High severity7.5NVD Advisory· Published Jul 20, 2022· Updated Jun 17, 2026
CVE-2022-1766
CVE-2022-1766
Description
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl version 0.1.4 should upgrade to anchorectl version 0.1.5 to resolve this issue.
Affected products
5cpe:2.3:a:anchore:anchorectl:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:anchore:anchorectl:*:*:*:*:*:*:*:*range: <0.1.5
- (no CPE)range: <=0.1.4
- Anchore Inc./Anchore Enterprisev5Range: unspecified
- Anchore Inc./AnchoreCTLv5Range: unspecified
Patches
Vulnerability mechanics
References
1- docs.anchore.com/current/docs/releasenotes/401/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.