An ECR repository policy is a resource policy that can grant other principals, including whole external accounts, the right to pull or push. A policy that allows ecr:* or names a broad principal lets an attacker in one account read images from, or push images into, a repository in another, turning a loose policy into cross-account data access or a supply-chain write.
Reading and abusing the policy#
aws ecr get-repository-policy --repository-name <r> --query policyText --output text
# If pull is allowed cross-account: authenticate to the owning registry and pull
aws ecr get-login-password --region <region> | docker login --username AWS \
--password-stdin <owner-acct>.dkr.ecr.<region>.amazonaws.com
docker pull <owner-acct>.dkr.ecr.<region>.amazonaws.com/<r>:<tag>
If push is allowed, the repository is an image poisoning target.
Exploitation notes#
- A
Principalof*or another account root on a pull action exposes every image in the repository cross-account. - Push rights cross-account are the dangerous case: they let you plant a tag that the owner's deploy pipeline will run.
- Combine with enumeration to find which repositories the policies actually expose, then target the ones feeding privileged workloads.
Tools#
- AWS CLI (
get-repository-policy,ecr get-login-password): read the policy, authenticate. - docker / crane: pull or push across the boundary.