VYPR

apk package

chainguard/opa-fips-envoy

pkg:apk/chainguard/opa-fips-envoy

Vulnerabilities (63)

  • CVE-2024-45339HigJan 28, 2025
    affected < 1.0.0-r0fixed 1.0.0-r0

    When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and

  • CVE-2024-45336MedJan 28, 2025
    affected < 1.0.0-r1fixed 1.0.0-r1

    The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain re

  • CVE-2024-45338MedDec 18, 2024
    affected < 0.70.0_rc1-r1fixed 0.70.0_rc1-r1

    An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

Page 4 of 4