Get a Pentest and security assessment of your IT network.

News

CVE-2020-15157: Vulnerability in Containerd Can Leak Cloud Credentials

A new vulnerability was found in containerd, located in the container image-pulling process. The new vulnerability includes manipulation of the image manifest, allowing attackers to craft an image that can leak the hosts registry or cloud credentials when pulled from a registry. This leak occurs even before the image is running any code on your server. This vulnerability was discovered by Brad Geesaman who presented it in his “ContainerDrip” write-up. To remediate this vulnerability, you should ensure your systems are running the latest containerd 1.214, and containerx 1.3x was also tested and validated.”]

Source: https://blog.aquasec.com/cve-2020-15157-containerd-container-vulnerability

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

Linux bug leaves 1.4 billion Android users vulnerable to hijacking attacks