VYPR

apk package

chainguard/awx

pkg:apk/chainguard/awx

Vulnerabilities (144)

  • CVE-2024-33664MedApr 26, 2024
    affected < 24.6.1-r19fixed 24.6.1-r19

    python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

  • CVE-2024-33663MedApr 26, 2024
    affected < 24.6.1-r19fixed 24.6.1-r19

    python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.

  • CVE-2024-23342HigJan 23, 2024
    affected < 24.6.1-r33fixed 24.6.1-r33

    The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior

  • CVE-2023-45133CriOct 12, 2023
    affected < 24.6.1-r42fixed 24.6.1-r42

    Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when

Page 8 of 8