rcowsill.github.io

github.com/rcowsill

Security - docker-library/official-images

CI/CD vulnerability report and fixes

The docker-library/official-images repository is the ‘Primary source of truth for the Docker “Official Images” program’. This program is a curated set of Docker repositories hosted on Docker Hub.

In late 2021 I found a vulnerability in one of the GitHub actions workflows used in the official-images repo. Exploiting it would have allowed an attacker to gain content: write permission, with which they could directly commit changes to the repo. That access could then have been used to stage a supply chain attack.

For full details, see my original report sent to the official-images maintainers (reproduced here with their kind permission).

My sincere thanks to the official-images maintainers for their rapid response and willingness to collaborate on fixing the issue.

Disclosure Timeline: