-
Notifications
You must be signed in to change notification settings - Fork 45
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Users can mount blobs without having read access to the from
repository
#1286
Comments
lubosmj
added a commit
to lubosmj/pulp_container
that referenced
this issue
Jul 20, 2023
Before this commit, the registry checked one scope, ignoring other scopes that could relate to blob mounting operations. Due to that, users without sufficient permissions could mount blobs from other users unauthorized. closes pulp#1286
lubosmj
added a commit
to lubosmj/pulp_container
that referenced
this issue
Jul 21, 2023
Before this commit, the registry checked one scope, ignoring other scopes that could relate to blob mounting operations. Due to that, users without sufficient permissions could mount blobs from other users unauthorized. closes pulp#1286
lubosmj
added a commit
to lubosmj/pulp_container
that referenced
this issue
Jul 21, 2023
Before this commit, the registry checked one scope, ignoring other scopes that could relate to blob mounting operations. Due to that, users without sufficient permissions could mount blobs from other users unauthorized. closes pulp#1286
lubosmj
added a commit
to lubosmj/pulp_container
that referenced
this issue
Jul 21, 2023
Before this commit, the registry checked one scope, ignoring other scopes that could relate to blob mounting operations. Due to that, users without sufficient permissions could mount blobs from other users unauthorized. closes pulp#1286
lubosmj
added a commit
to lubosmj/pulp_container
that referenced
this issue
Jul 21, 2023
Before this commit, the registry checked one scope, ignoring other scopes that could relate to blob mounting operations. Due to that, users without sufficient permissions could mount blobs from other users unauthorized. closes pulp#1286
lubosmj
added a commit
that referenced
this issue
Jul 24, 2023
Before this commit, the registry checked one scope, ignoring other scopes that could relate to blob mounting operations. Due to that, users without sufficient permissions could mount blobs from other users unauthorized. closes #1286
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
We verify just the access to the created
to
repository (pulp_container/pulp_container/app/token_verification.py
Line 205 in 15aca2f
from
repository (pulp_container/pulp_container/app/registry_api.py
Line 578 in 15aca2f
The fix will need to be backported.
The text was updated successfully, but these errors were encountered: