VYPR

apk package

chainguard/bank-vaults-fips

pkg:apk/chainguard/bank-vaults-fips

Vulnerabilities (82)

  • CVE-2020-8911MedAug 11, 2020
    affected < 0fixed 0

    A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows an attacker who has write access to the target's S3 bucket a

  • CVE-2020-8559MedJul 22, 2020
    affected < 1.20.4-r24fixed 1.20.4-r24

    The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

Page 5 of 5