VYPR

apk package

chainguard/gitlab-runner-fips

pkg:apk/chainguard/gitlab-runner-fips

Vulnerabilities (2)

  • CVE-2024-24791HigJul 2, 2024
    affected < 17.1.0-r2fixed 17.1.0-r2

    The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the co

  • CVE-2024-6104Jun 24, 2024
    affected < 17.1.0-r1fixed 17.1.0-r1

    go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.