Skip to content

Docker Registry Unauthenticated Access Detection

docker-registry-unauthenticated is a high severity check in the devops category, written in shell. Its source is templates/devops/docker/docker-registry-unauthenticated.sh in cert-x-gen-templates.

Detects Docker Registry instances accessible without authentication

Field Value
Id docker-registry-unauthenticated
Severity high
Language shell
Category devops
Author CERT-X-GEN Security Team
Template version not recorded
Confidence 95
CVSS not recorded
Weakness CWE-306
Tags docker, registry, container, unauthenticated, devops
Target kind not recorded
Oracle not recorded

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info docker-registry-unauthenticated

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.