Executive brief
A vulnerability in the BBOT security tool's Docker integration could allow an attacker to intercept sensitive login credentials. By sitting between the tool and a Docker registry, an attacker can redirect authentication requests to a server they control. This could lead to the theft of authentication tokens used to access private container images.
Technical details
The docker_pull module in BBOT (up to version 2.8.4) is vulnerable to a form of Server-Side Request Forgery (SSRF) and credential leakage. When connecting to a Docker registry, the module uses the 'realm' parameter from the WWW-Authenticate response header as the authentication endpoint without proper validation. A man-in-the-middle (MitM) attacker can modify this header to point to a malicious endpoint. If the tool then attempts to authenticate against this rogue endpoint, it may leak sensitive authentication tokens to the attacker. A fix has been identified in commit c2f4bc0.
Affected products
- Black Lantern Security BBOT 2.0.0 to 2.8.4
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory