Authentication mechanism absence or evasion In github.com/distribution/distribution/v3
Description
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2//manifests/ endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 3.1.1 | ||
go | - | ||
debian 11 | - | ||
debian 13 | - | ||
debian 14 | - | ||
debian 12 | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1.