Skip to content

DeployKey exposure

High
PacoVK published GHSA-rj9m-qf65-f5gg Dec 31, 2024

Package

No package listed

Affected versions

0.9.0, 0.9.1

Patched versions

0.9.2

Description

Impact

Tapir versions 0.9.0 and 0.9.1 are facing critical issue with scope-able Deploykeys where attackers can guess the key to get write access to the registry.

Patches

User must upgrade to 0.9.2

Severity

High

CVE ID

CVE-2024-56802

Weaknesses

No CWEs

Credits