VYPR

apk package

chainguard/kibana-8.17-iamguarded

pkg:apk/chainguard/kibana-8.17-iamguarded

Vulnerabilities (102)

  • CVE-2025-59343HigSep 24, 2025
    affected < 8.17.10-r1fixed 8.17.10-r1

    tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A worka

  • CVE-2025-58754HigSep 12, 2025
    affected < 8.17.10-r10fixed 8.17.10-r10

    Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire

Page 6 of 6