VYPR

apk package

chainguard/vault-fips-1.17

pkg:apk/chainguard/vault-fips-1.17

Vulnerabilities (23)

  • CVE-2024-6468Jul 11, 2024
    affected < 1.17.2-r0fixed 1.17.2-r0

    Vault and Vault Enterprise did not properly handle requests originating from unauthorized IP addresses when the TCP listener option, proxy_protocol_behavior, was set to deny_unauthorized. When receiving a request from a source IP address that was not listed in proxy_protocol_auth

  • CVE-2024-24791HigJul 2, 2024
    affected < 1.17.1-r1fixed 1.17.1-r1

    The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the co

  • CVE-2024-28180Mar 9, 2024
    affected < 1.17.6-r0fixed 1.17.6-r0

    Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now ret

Page 2 of 2