VYPR

apk package

chainguard/opensearch-dashboards-3-fips-dashboards-reporting

pkg:apk/chainguard/opensearch-dashboards-3-fips-dashboards-reporting

Vulnerabilities (46)

  • CVE-2025-58754HigSep 12, 2025
    affected < 3.2.0-r0fixed 3.2.0-r0

    Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire

  • CVE-2025-57810HigAug 26, 2025
    affected < 3.4.0-r0fixed 3.4.0-r0

    jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provid

  • CVE-2025-9288CriAug 20, 2025
    affected < 3.1.0-r4fixed 3.1.0-r4

    Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.

  • CVE-2025-9287CriAug 20, 2025
    affected < 3.1.0-r4fixed 3.1.0-r4

    Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.

  • CVE-2025-7783CriJul 18, 2025
    affected < 3.1.0-r2fixed 3.1.0-r2

    Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.

  • CVE-2024-1899MedFeb 26, 2024
    affected < 3.8.0-r0fixed 3.8.0-r0

    An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions.

Page 3 of 3