VYPR

apk package

wolfi/kots

pkg:apk/wolfi/kots

Vulnerabilities (166)

  • CVE-2022-39222CriOct 6, 2022
    affected < 0fixed 0

    Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clients accepting tokens issued by those Dex instances) are affected by this vulnerability if they are running a version prior to 2.35.

  • CVE-2020-27847CriMay 28, 2021
    affected < 0fixed 0

    A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system

  • CVE-2020-26290CriDec 28, 2020
    affected < 0fixed 0

    Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues with XML encoding in the under

  • CVE-2020-8912LowAug 11, 2020
    affected < 1.130.6-r0fixed 1.130.6-r0

    A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-

  • CVE-2020-8911MedAug 11, 2020
    affected < 1.130.6-r0fixed 1.130.6-r0

    A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows an attacker who has write access to the target's S3 bucket a

  • CVE-2020-8559MedJul 22, 2020
    affected < 1.124.8-r0fixed 1.124.8-r0

    The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

Page 9 of 9