VYPR

rpm package

almalinux/podman-gvproxy

pkg:rpm/almalinux/podman-gvproxy

Vulnerabilities (109)

  • CVE-2021-4024MedDec 23, 2021
    affected < 2:4.2.0-3.el9fixed 2:4.2.0-3.el9

    A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is op

  • CVE-2021-33198HigAug 2, 2021
    affected < 4:4.9.4-18.module_el8.10.0+3926+f12484f5fixed 4:4.9.4-18.module_el8.10.0+3926+f12484f5

    In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

  • CVE-2021-33197MedAug 2, 2021
    affected < 2:4.2.0-3.el9fixed 2:4.2.0-3.el9

    In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers.

  • CVE-2021-34558MedJul 15, 2021
    affected < 2:4.2.0-3.el9fixed 2:4.2.0-3.el9

    The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.

  • CVE-2021-20291MedApr 1, 2021
    affected < 2:4.2.0-3.el9fixed 2:4.2.0-3.el9

    A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation wh

  • CVE-2021-20199MedFeb 2, 2021
    affected < 2:4.2.0-3.el9fixed 2:4.2.0-3.el9

    Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podma

  • CVE-2020-28852HigJan 2, 2021
    affected < 2:4.2.0-3.el9fixed 2:4.2.0-3.el9

    In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

  • CVE-2020-28851HigJan 2, 2021
    affected < 2:4.2.0-3.el9fixed 2:4.2.0-3.el9

    In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

  • CVE-2019-19921HigFeb 12, 2020
    affected < 2:4.0.2-24.module_el8.9.0+3627+db8ec155fixed 2:4.0.2-24.module_el8.9.0+3627+db8ec155

    runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vul

Page 6 of 6