GHSA-h62f-wm92-2cmw

Source
https://github.com/advisories/GHSA-h62f-wm92-2cmw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h62f-wm92-2cmw/GHSA-h62f-wm92-2cmw.json
Aliases
Published
2022-05-13T01:16:08Z
Modified
2023-11-08T03:58:49.599563Z
Details

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

Specific Go Packages Affected

github.com/docker/distribution/registry/storage github.com/docker/distribution/registry/handlers

References

Affected packages

Go / github.com/docker/distribution

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
2.7.0-rc.0