In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/oras-project/oras-go/v2/registry/remote/auth to version 2.6.1 or higher.
Affected versions of this package are vulnerable to Insufficiently Protected Credentials via the Authorization header being forwarded during HTTP redirects or blob upload Location responses across registry origins. An attacker can obtain registry credentials intended for one origin by causing a client to follow a redirect or upload location to a different HTTP origin.