VYPR

apk package

wolfi/k3s-multicall

pkg:apk/wolfi/k3s-multicall

Vulnerabilities (84)

  • CVE-2023-45142HigOct 12, 2023
    affected < 1.28.2-r2fixed 1.28.2-r2

    OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests

  • CVE-2023-39325HigOct 11, 2023
    affected < 1.28.2-r1fixed 1.28.2-r1

    A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attack

  • CVE-2023-32187HigSep 18, 2023
    affected < 1.27.5-r0fixed 1.27.5-r0

    An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers' apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects k3s: from v1.24.0 before v1.24.17+k3s1, from v1.25.0 before v1.25.13+k3s

  • CVE-2023-3978MedAug 2, 2023
    affected < 1.28.2-r1fixed 1.28.2-r1

    Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

Page 5 of 5