create-only policy allows overwrite attempts of existing latest tag (update permission not required)
Upstream fixed versions: zot: v2.1.15
details
- Finding IDs
- F-ZOT-AUTHZ-001
- CVE
- CVE-2026-31801
- GHSA
- GHSA-85jx-fm8m-x8c6
- Status
- patched
- Fixed in
- zot: v2.1.15
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- create-only policy allows overwrite attempts of existing latest tag (update permission not required)
- Upstream CWE
- CWE-863
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream fixed versions
- zot: v2.1.15
- Upstream affected ranges
- zot: v1.3.0 through v2.1.14 (and `main` at commit `3c7d5a5f1d40eb996ba1d56f28be57a3b77510af`)
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-ZOT-AUTHZ-001: Access control. Create permission can be used to overwrite existing content. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-ZOT-AUTHZ-001
Security area (1seal assessment): Authorization. Create permission can be used to overwrite existing content. Reviewed 24 Sep 2026.