What's Changed
Security Advisories 🔒
- (high): Path traversal vulnerability in distribution endpoints GHSA-qj39-pjf2-wmrc in
a82c5528f - (high): A system robot with user:update makes itself a system administrator GHSA-w5fq-xrhj-j7g2 in
8896be0ae - (high): Robot "cover all projects" scope collapses into a global wildcard, conferring the deliberately-ungrantable robot:update — enabling cross-project robot takeover with owner lockout GHSA-xq2m-cj8w-56v5 in
7331b58d5 - (high): External auth-proxy identity named admin inherits Registry system-administrator authorization GHSA-xvh7-74g6-29xw in
13e5a1b97 - (medium): Immutable tag rule matcher only evaluates first repository/tag selector, allowing multi-selector rules to be bypassed GHSA-27f2-qg57-2gwg in
08c58f3c7 - (medium): SSRF in webhook delivery allows ProjectAdmin to reach internal services and cloud metadata endpoints GHSA-2phj-cp9f-qq6w in
fb476e10c - (medium): Scanner bearer authorization request disables TLS verification and reads the full response body GHSA-884q-mjcg-86x4 in
eb1a6fb64 - (medium): Webhook error responses can cause unbounded decompression in Jobservice GHSA-jw3v-7jvc-pfmx in
fb476e10c - (medium): scanner_registration.access_cred is missing filter:"false", giving a project admin a blind oracle over the scanner credential GHSA-vwvv-675v-p6rr in
d2e2312f5 - (medium): Registry chunk upload reuses unvalidated Location headers GHSA-wjpm-hv5w-gxr6 in
401e73429 - (medium): Vulnerability & Content-Trust pull policies bypassable via attacker-controlled
User-Agentheader GHSA-wrw5-gmvj-gf23 in9d255ebe1 - (medium): SSRF and credential disclosure via attacker-controlled pagination Link header in the registry replication client GHSA-xgp2-5vxg-rgh2 in
a01e0c6c5 - (low): Security middleware continues after AuthMode lookup failure GHSA-3x7c-wf86-mjx6 in
bfd319a92
Other Changes
Full Changelog: v2.13.5...v2.13.6