When the ACR admin account is enabled, a single username and password grant full pull and push to every repository, and the credential is readable from the management plane by anyone with the right. Even without it, AcrPull/AcrPush on the registry lets you read images (for baked-in secrets) and push tampered ones.
Grab the admin credential and log in#
az acr credential show -n <registry> # username + two passwords
az acr login -n <registry> # or docker login <registry>.azurecr.io
az acr repository list -n <registry>
docker pull <registry>.azurecr.io/<repo>:<tag>
Exploitation notes#
- Pull every image and grep layers for secrets, tokens, and connection strings; build artifacts leak these constantly.
az acr credential showworks for anyone withlistCredentialson the registry, so the admin account is a soft target even without Docker on the host.- Pushing a poisoned tag over an image that AKS or App Service pulls is covered under Tasks and image poisoning.
Tools#
- Azure CLI (
az acr credential show,az acr repository). - docker / crane / skopeo: pull, inspect, and push images.