VYPR

rpm package

opensuse/trivy&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/trivy&distro=openSUSE%20Tumbleweed

Vulnerabilities (69)

  • CVE-2024-6257HigJun 25, 2024
    affected < 0.53.0-1.1fixed 0.53.0-1.1

    HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

  • CVE-2024-35192MedMay 20, 2024
    affected < 0.52.0-1.1fixed 0.52.0-1.1

    Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Clo

  • CVE-2024-3817CriApr 17, 2024
    affected < 0.58.2-1.1fixed 0.58.2-1.1

    HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.

  • CVE-2023-42363MedNov 27, 2023
    affected < 0.54.1-1.1fixed 0.54.1-1.1

    A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.

  • CVE-2023-25165MedFeb 8, 2023
    affected < 0.37.3-1.1fixed 0.37.3-1.1

    Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a D

  • CVE-2022-1996CriJun 8, 2022
    affected < 0.30.2-1.1fixed 0.30.2-1.1

    Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

  • CVE-2022-28946HigMay 19, 2022
    affected < 0.28.0-1.1fixed 0.28.0-1.1

    An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access.

  • CVE-2022-23648HigMar 3, 2022
    affected < 0.26.0-1.1fixed 0.26.0-1.1

    containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could

  • CVE-2021-32760MedJul 19, 2021
    affected < 0.20.2-1.1fixed 0.20.2-1.1

    containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions

Page 4 of 4