The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/ratify-project/ratify/pkg/controllers
to version 1.2.3, 1.3.2 or higher.
Affected versions of this package are vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere due to the improper validation of target registry domains during the token exchange process. An attacker can extract and misuse authentication tokens by directing requests to a malicious registry.
Note:
This is only exploitable if a private Azure Container Registry is configured to be used with the Azure authentication providers.
This vulnerability can be mitigated by ensuring that only well-known Azure Container Registry endpoints are configured and used for authentication.