Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to register a malicious container registry, or an existing container registry can be taken over, HTTP Headers (including registry authentication credentials or Portainer session tokens) may be leaked to that registry. This issue has been patched in STS version 2.31.0 and LTS version 2.27.7.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Jun 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to register a malicious container registry, or an existing container registry can be taken over, HTTP Headers (including registry authentication credentials or Portainer session tokens) may be leaked to that registry. This issue has been patched in STS version 2.31.0 and LTS version 2.27.7. | |
Title | Portainer HTTP Headers May Leak to Malicious Container Registries | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-17T21:27:38.542Z
Updated: 2025-06-18T13:41:17.580Z
Reserved: 2025-06-06T15:44:21.556Z
Link: CVE-2025-49593

Updated: 2025-06-18T13:41:12.676Z

Status : Awaiting Analysis
Published: 2025-06-17T22:15:49.700
Modified: 2025-06-18T13:46:52.973
Link: CVE-2025-49593

No data.