| - module: github.com/docker/distribution |
| - fixed: 2.8.0+incompatible |
| vulnerable_at: 2.7.1+incompatible |
| - package: github.com/docker/distribution |
| summary: Type confusion in github.com/docker/distribution |
| Systems that rely on digest equivalence for image attestations may be vulnerable |
| A maliciously crafted OCI Container Image can cause registry clients to parse |
| the same image in two different ways without modifying the image's digest, |
| invalidating the common pattern of relying on container image digests for |
| This problem has been addressed in newer versions by improving validation in |
| published: 2022-07-29T20:00:03Z |
| - fix: https://github.com/distribution/distribution/commit/b59a6f827947f9e0e67df0cfb571046de4733586 |