Type Confusion Affecting github.com/containers/image/v5/manifest package, versions <5.17.0


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMCONTAINERSIMAGEV5MANIFEST-1922834
  • published19 Nov 2021
  • disclosed18 Nov 2021
  • creditUnknown

Introduced: 18 Nov 2021

CVE-2021-41190  (opens in a new tab)
CWE-843  (opens in a new tab)

How to fix?

Upgrade github.com/containers/image/v5/manifest to version 5.17.0 or higher.

Overview

github.com/containers/image/v5/manifest is a package that works with containers' images.

Affected versions of this package are vulnerable to Type Confusion. Documents that contain both “manifests” and “layers” fields can be interpreted as either a manifest or an index in the absence of an accompanying Content-Type header. If a Content-Type header changes between two pulls of the same digest, a client may interpret the resulting content differently.

CVSS Scores

version 3.1