VYPR

apk package

chainguard/configmap-reload-fips

pkg:apk/chainguard/configmap-reload-fips

Vulnerabilities (64)

  • CVE-2023-39326MedDec 6, 2023
    affected < 0.12.0-r2fixed 0.12.0-r2

    A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of d

  • CVE-2023-39325HigOct 11, 2023
    affected < 0.12.0-r2fixed 0.12.0-r2

    A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attack

  • CVE-2023-44487HigKEVOct 10, 2023
    affected < 0.12.0-r2fixed 0.12.0-r2

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-39323HigOct 5, 2023
    affected < 0.12.0-r2fixed 0.12.0-r2

    Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires

Page 4 of 4