Skip to content

H3-2021-0009

Unauthenticated Docker Registry API Access

Category SECURITY_MISCONFIGURATION
Base Score 5.5

Description

The Docker Registry API is accessible without authentication.

Impact

An attacker could access sensitive information stored in the registry such as manifests and configurations of each image stored in the catalog.

References