VYPR

apk package

wolfi/loki-3.5-logcli

pkg:apk/wolfi/loki-3.5-logcli

Vulnerabilities (24)

  • CVE-2025-4673MedJun 11, 2025
    affected < 3.5.1-r1fixed 3.5.1-r1

    Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

  • CVE-2025-22874HigJun 11, 2025
    affected < 3.5.1-r1fixed 3.5.1-r1

    Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

  • CVE-2020-8912LowAug 11, 2020
    affected < 3.5.12-r9fixed 3.5.12-r9

    A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-

  • CVE-2020-8911MedAug 11, 2020
    affected < 3.5.12-r9fixed 3.5.12-r9

    A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows an attacker who has write access to the target's S3 bucket a

Page 2 of 2