PT-2026-99453 · Contrast · Contrast
CVSS v3.1
8.2
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Contrast versions 1.14.0 through 1.23.0
Description
Runtime policies are generated that fail to detect all container image substitutions. This occurs because an
allow storage rule accepts storage entries using the image guest pull driver without verifying the image digest. An attacker with access to the Kata agent API can substitute a container image with an exploit payload, provided the substituted image satisfies the remaining policy rules, which undermines the integrity guarantees of the confidential container.Recommendations
Update Contrast to version 1.23.1.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contrast