VYPR

apk package

chainguard/fulcio-fips

pkg:apk/chainguard/fulcio-fips

Vulnerabilities (104)

  • CVE-2023-48795MedDec 18, 2023
    affected < 1.4.3-r2fixed 1.4.3-r2

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end

  • CVE-2023-45285HigDec 6, 2023
    affected < 1.4.3-r1fixed 1.4.3-r1

    Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not

  • CVE-2023-39326MedDec 6, 2023
    affected < 1.4.3-r1fixed 1.4.3-r1

    A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of d

  • CVE-2020-8559MedJul 22, 2020
    affected < 1.6.6-r6fixed 1.6.6-r6

    The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

Page 6 of 6