
Cloud Vulnerability DB
A community-led vulnerabilities database
Trivy, a security scanner, was found to contain a vulnerability (CVE-2024-35192) prior to version 0.51.2. The vulnerability could allow a malicious actor to trigger Trivy to scan container images from a crafted malicious registry, potentially leading to the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR). The vulnerability was discovered and disclosed on May 20, 2024 (GitHub Advisory).
The vulnerability is rated as Moderate with a CVSS v3.1 base score of 5.5 (MEDIUM). The CVSS vector string is CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N, indicating Local attack vector, High attack complexity, No privileges required, Required user interaction, Changed scope, and High confidentiality impact with No impact on integrity and availability (GitHub Advisory).
If exploited, the vulnerability allows attackers to obtain tokens that can be used to push/pull images from registries to which the identity/user running Trivy has access. The impact is particularly significant when Trivy is executed with environment variables containing static AWS credentials, within a Pod running on an EKS cluster with IRSA annotations, or similar configurations for GCP and Azure (GitHub Advisory).
The vulnerability only applies when scanning container images directly from a registry. Systems are not affected if the default credential provider chain is unable to obtain valid credentials, or if using Docker, containerd, or other runtime to pull images locally for scanning (GitHub Advisory).
The vulnerability has been fixed in Trivy version 0.51.2. For users of earlier versions, it is recommended to only scan images from trusted registries. Users can enforce this behavior by using the --image-src flag to select trusted sources. Additionally, using Docker, containerd, or other runtime to pull images locally before scanning with Trivy provides protection against this vulnerability (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."