Project

Profile

Help

Issue #8303

push of an image that contains foreign layers should not succeed

Added by ipanova@redhat.com about 2 months ago. Updated about 1 month ago.

Status:
NEW
Priority:
Normal
Assignee:
-
Sprint/Milestone:
-
Start date:
Due date:
Estimated time:
Severity:
2. Medium
Platform Release:
OS:
Triaged:
Yes
Groomed:
No
Sprint Candidate:
No
Tags:
Sprint:
Quarter:

Description

https://github.com/pulp/pulp_container/blob/2.3/pulp_container/app/registry_api.py#L459

Our upload logic does not seem to check on the type of the blob that is being uploaded. Foreign layers should be rejected. We should check on the content_type provided in the request.

We should audit manifests too.

https://github.com/pulp/pulp_container/blob/2.3/pulp_container/app/registry_api.py#L576

History

#1 Updated by ipanova@redhat.com about 1 month ago

  • Triaged changed from No to Yes

Please register to edit this issue

Also available in: Atom PDF