VYPR

apk package

chainguard/k3d-tools

pkg:apk/chainguard/k3d-tools

Vulnerabilities (145)

  • CVE-2023-2121MedJun 9, 2023
    affected < 5.6.0-r11fixed 5.6.0-r11

    Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.

  • CVE-2023-1297MedJun 2, 2023
    affected < 5.6.0-r11fixed 5.6.0-r11

    Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3

  • CVE-2023-25000MedMar 30, 2023
    affected < 5.6.0-r11fixed 5.6.0-r11

    HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the sea

  • CVE-2023-0665MedMar 30, 2023
    affected < 5.6.0-r11fixed 5.6.0-r11

    HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key material, trust chains or certificate issuance

  • CVE-2023-0620MedMar 30, 2023
    affected < 5.6.0-r11fixed 5.6.0-r11

    HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed

  • CVE-2023-24999MedMar 11, 2023
    affected < 5.6.0-r11fixed 5.6.0-r11

    HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.1

  • CVE-2022-41723HigFeb 28, 2023
    affected < 5.6.0-r11fixed 5.6.0-r11

    A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

  • CVE-2022-3064HigDec 27, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.

  • CVE-2022-2582MedDec 27, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks this metadata field, but older SDK versions still send it.

  • CVE-2021-4235MedDec 27, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

  • CVE-2021-38561HigDec 26, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.

  • CVE-2022-32149HigOct 14, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.

  • CVE-2022-41316MedOct 12, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.

  • CVE-2022-40716MedSep 23, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and 1.13.2."

  • CVE-2022-27664HigSep 6, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.

  • CVE-2021-43565HigSep 6, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.

  • CVE-2022-29526MedJun 23, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

  • CVE-2022-29153HigApr 19, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.

  • CVE-2022-27191HigMar 18, 2022
    affected < 5.6.0-r11fixed 5.6.0-r11

    The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

  • CVE-2021-41802LowOct 8, 2021
    affected < 5.6.0-r11fixed 5.6.0-r11

    HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.

Page 6 of 8