devcontainers / devcontainers/cli

Dependency confusion attack from looking for manifest in docker.io first

オープン
#811 コメント 2 件 リアクション 0 件 担当者 1 名 @chrmarti が担当を希望しています GitHub で見る
info-needed
主要言語
TypeScript
スター
3k
フォーク
457
平均マージ
13時間 17分
マージ済み PR(30日)
6

説明

[This block of code](https://github.com/devcontainers/cli/blob/c1c8b08263c6dca7cd79c97a2d0bc581fcef4f6c/src/spec-node/utils.ts#L309-L313) assumes that any image name with only one slash in it cannot possibly be a fully qualified image name, and therefore prepends `docker.io/` to the name.

Thus, if I specify a Dockerfile with
```
FROM artefact.example.com/my_image:1.2.3
```
then this CLI first looks for a manifest at `docker.io/artefact.example.com/my_image:1.2.3`.

This concerns me. It feels like an invitation to a dependency confusion attack. Someone could create an "artefact.example.com" organization on docker.io, publish a malicious image named "my_image:1.2.3", and this CLI would pull that instead of what I specified.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。