Vulnerability Bulletins

Reported ECR Public Gallery Issue


System information

   
Affected software AmazonWS

Description

Initial Publication Date: 12/13/2022 9:00AM EST On November 14, 2022, a security researcher reported an issue in Amazon Elastic Container Registry (ECR) Public Gallery, a public website for finding and sharing public container images. The researcher identified an ECR API action that, if called, could have enabled modification or removal of images available on ECR Public Gallery. As of November 15, 2022, the identified issue was remediated. We have conducted exhaustive analysis of all logs, we

More info:

https://aws.amazon.com/security/security-bulletins/AWS-2022-010/

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2022-12-14
Ministerio de Defensa
CNI
CCN
CCN-CERT