VYPR

apk package

wolfi/linkerd2-proxy-identity

pkg:apk/wolfi/linkerd2-proxy-identity

Vulnerabilities (22)

  • CVE-2025-24898MedFeb 3, 2025
    affected < 25.1.2-r1fixed 25.1.2-r1

    rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_proto` can return a slice pointing into the `server` argument's buffer but with a lifetime bound to the `client` argument. In situations where the `sever` buffer's

  • CVE-2024-45337CriDec 12, 2024
    affected < 24.11.8-r1fixed 24.11.8-r1

    Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that

Page 2 of 2