VYPR

apk package

chainguard/conductor

pkg:apk/chainguard/conductor

Vulnerabilities (46)

  • CVE-2025-37727MedOct 10, 2025
    affected < 3.31.0-r4fixed 3.31.0-r4

    Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

  • CVE-2025-41249HigSep 16, 2025
    affected < 3.31.0-r4fixed 3.31.0-r4

    The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application m

  • CVE-2025-41242MedAug 18, 2025
    affected < 3.31.0-r4fixed 3.31.0-r4

    Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following are true: * the application is deployed as a WAR or with an embedded Servlet co

  • CVE-2025-22227MedJul 16, 2025
    affected < 3.31.0-r3fixed 3.31.0-r3

    In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.

  • CVE-2024-52980MedApr 8, 2025
    affected < 3.31.0-r4fixed 3.31.0-r4

    A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privil

  • CVE-2020-36843MedMar 13, 2025
    affected < 3.31.0-r4fixed 3.31.0-r4

    The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to create new valid signatures different fr

Page 3 of 3