VYPR

apk package

chainguard/eks-distro-fips-1.31

pkg:apk/chainguard/eks-distro-fips-1.31

Vulnerabilities (23)

  • CVE-2024-53259MedDec 2, 2024
    affected < 1.31.9-r0fixed 1.31.9-r0

    quic-go is an implementation of the QUIC protocol in Go. An off-path attacker can inject an ICMP Packet Too Large packet. Since affected quic-go versions used IP_PMTUDISC_DO, the kernel would then return a "message too large" error on sendmsg, i.e. when quic-go attempts to send a

  • CVE-2024-51744LowNov 4, 2024
    affected < 1.31.6-r1fixed 1.31.6-r1

    golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors r

  • CVE-2024-45310Sep 3, 2024
    affected < 1.31.33-r0fixed 1.31.33-r0

    runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between

Page 2 of 2