apk package
chainguard/grafana-fips-10.3-oci-compat
pkg:apk/chainguard/grafana-fips-10.3-oci-compat
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-6104 | Med | 6.0 | < 10.3.6-r3 | 10.3.6-r3 | Jun 24, 2024 | go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7. | |
| CVE-2024-35255 | Med | 5.5 | < 10.3.6-r2 | 10.3.6-r2 | Jun 11, 2024 | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability |
- affected < 10.3.6-r3fixed 10.3.6-r3
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.
- affected < 10.3.6-r2fixed 10.3.6-r2
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability