VYPR

apk package

wolfi/clickhouse-operator-metrics-exporter-compat

pkg:apk/wolfi/clickhouse-operator-metrics-exporter-compat

Vulnerabilities (4)

  • CVE-2025-47910MedSep 22, 2025
    affected < 0.25.3-r2fixed 0.25.3-r2

    When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended sec

  • CVE-2025-4673MedJun 11, 2025
    affected < 0.25.0-r1fixed 0.25.0-r1

    Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

  • CVE-2025-22874HigJun 11, 2025
    affected < 0.25.0-r1fixed 0.25.0-r1

    Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

  • CVE-2025-22872MedApr 16, 2025
    affected < 0.24.5-r1fixed 0.24.5-r1

    The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can resul