← Späť na vyhľadávanie CVE

CVE-2026-10517

Clair

Popis

Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is implemented entirely in github.com/quay/clair; no PSK-related code exists anywhere in claircore-s codebase or git history. The unauthenticated indexer API is Clair-s documented, intentional design, authentication is an opt-in deployment choice, not a code defect. No fix commit was found in claircore between the version recorded as the affected boundary (1.5.52) and the following release (1.5.53); intervening commits are unrelated dependency and feature changes, so the -fixed in 1.5.52- status is inaccurate.

CVSS 5.8EPSS 0.292%Riziko 0.6
Zobraziť zdroj
Zverejnené
2026-06-01 09:16:16
Dotknuté verzie
unknown
Typ
Core software
Posledná úprava
2026-07-27 09:16:37
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N