A new vulnerability was found in containerd, located in the container image-pulling process. The new vulnerability includes manipulation of the image manifest, allowing attackers to craft an image that can leak the hosts registry or cloud credentials when pulled from a registry. This leak occurs even before the image is running any code on your server. This vulnerability was discovered by Brad Geesaman who presented it in his “ContainerDrip” write-up. To remediate this vulnerability, you should ensure your systems are running the latest containerd 1.214, and containerx 1.3x was also tested and validated.”]
Source: https://blog.aquasec.com/cve-2020-15157-containerd-container-vulnerability

