github / advisory-database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Creative Commons Attribution 4.0 International
1.72k stars 323 forks source link

[GHSA-6wvf-f2vw-3425] github.com/containers/image allows unexpected authenticated registry accesses #4477

Closed RTann closed 4 months ago

RTann commented 4 months ago

Updates

Comments For some products, updating to v5.29.3 is easier than v5.30.1. However, if they do that, many vuln scanners will still claim they are vulnerable as v5.29.3 < v5.30.1. Adding this make it clear v5.29.3 is also safe. See https://github.com/containers/image/releases/tag/v5.29.3 for proof.

advisory-database[bot] commented 4 months ago

Hi @RTann! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!