apk package
wolfi/kpt
pkg:apk/wolfi/kpt
Vulnerabilities (82)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-3978 | Med | 6.1 | < 1.0.0_beta46-r0 | 1.0.0_beta46-r0 | Aug 2, 2023 | Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack. | |
| CVE-2023-2253 | Med | 6.5 | < 1.0.0_beta31-r5 | 1.0.0_beta31-r5 | Jun 6, 2023 | A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the all |
- affected < 1.0.0_beta46-r0fixed 1.0.0_beta46-r0
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
- affected < 1.0.0_beta31-r5fixed 1.0.0_beta31-r5
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the all
Page 5 of 5