Unauthenticated registry access

Self-hosted registries frequently ship with no authentication, or with read or even write open to anonymous clients. Anonymous pull leaks every image; anonymous push is a supply-chain foothold, letting an attacker overwrite an existing tag with a malicious image.

bash
REG=https://registry.example.com
curl -s $REG/v2/                                    # 200 with no auth = open
curl -s $REG/v2/_catalog                            # anonymous inventory

# Anonymous push: overwrite a tag that deployments pull
crane copy backdoored:latest $REG/<repo>:<tag>

Exploitation notes#

  • A 200 on /v2/ with no Www-Authenticate challenge signals an open registry.
  • Overwriting a mutable tag (latest, an environment tag) is the highest-impact action: anything that pulls it runs your image.
  • Where only pull is open, pivot to Secrets in image layers across every repository.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more