VYPR

apk package

wolfi/kind

pkg:apk/wolfi/kind

Vulnerabilities (71)

  • CVE-2023-44487HigKEVOct 10, 2023
    affected < 0.21.0-r0fixed 0.21.0-r0

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-39323HigOct 5, 2023
    affected < 0.21.0-r0fixed 0.21.0-r0

    Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires

  • CVE-2023-39319MedSep 8, 2023
    affected < 0.21.0-r0fixed 0.21.0-r0

    The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be

  • CVE-2023-39318MedSep 8, 2023
    affected < 0.21.0-r0fixed 0.21.0-r0

    The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in contexts. This may cause the template parser to improperly interpret the contents of contexts, causing actions to be improperly escaped. This may

  • CVE-2023-29409MedAug 2, 2023
    affected < 0.21.0-r0fixed 0.21.0-r0

    Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are curr

  • CVE-2023-29406MedJul 11, 2023
    affected < 0.21.0-r0fixed 0.21.0-r0

    The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.

  • CVE-2023-29405CriJun 8, 2023
    affected < 0.21.0-r0fixed 0.21.0-r0

    The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. F

  • CVE-2023-29404CriJun 8, 2023
    affected < 0.21.0-r0fixed 0.21.0-r0

    The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. T

  • CVE-2023-29403HigJun 8, 2023
    affected < 0.21.0-r0fixed 0.21.0-r0

    On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is execute

  • CVE-2023-29402CriJun 8, 2023
    affected < 0.21.0-r0fixed 0.21.0-r0

    The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules wh

  • CVE-2022-29526MedJun 23, 2022
    affected < 0.22.0-r1fixed 0.22.0-r1

    Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Page 4 of 4