VYPR

apk package

chainguard/kubeflow-centraldashboard

pkg:apk/chainguard/kubeflow-centraldashboard

Vulnerabilities (87)

  • CVE-2024-39338HigAug 12, 2024
    affected < 1.9.0-r1fixed 1.9.0-r1

    axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

  • CVE-2024-37890HigJun 17, 2024
    affected < 1.8.0-r5fixed 1.8.0-r5

    ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in [email protected] (e55e510) and backported to [email protected] (22c2876), [email protected] (e

  • CVE-2024-37168MedJun 10, 2024
    affected < 1.8.0-r5fixed 1.8.0-r5

    @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to versions 1.10.9, 1.9.15, and 1.8.22, there are two separate code paths in which memory can be allocated per message in excess of the `grpc.max_receive_message_length` chann

  • CVE-2024-29041MedMar 25, 2024
    affected < 1.8.0-r3fixed 1.8.0-r3

    Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a redirect using a user-provided URL Expres

  • CVE-2024-28849MedMar 14, 2024
    affected < 1.8.0-r3fixed 1.8.0-r3

    follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which

  • CVE-2023-26159HigJan 2, 2024
    affected < 1.8.0-r1fixed 1.8.0-r1

    Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this

  • CVE-2019-10790HigFeb 17, 2020
    affected < 1.10.0-r19fixed 1.10.0-r19

    taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. taffy sets an internal index for each data item in its DB. Howev

Page 5 of 5