rpm package
opensuse/trivy&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/trivy&distro=openSUSE%20Tumbleweed
Vulnerabilities (69)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-6257 | Hig | 8.4 | < 0.53.0-1.1 | 0.53.0-1.1 | Jun 25, 2024 | HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution. | |
| CVE-2024-35192 | Med | 5.5 | < 0.52.0-1.1 | 0.52.0-1.1 | May 20, 2024 | Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Clo | |
| CVE-2024-3817 | Cri | 9.8 | < 0.58.2-1.1 | 0.58.2-1.1 | Apr 17, 2024 | HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package. | |
| CVE-2023-42363 | Med | 5.5 | < 0.54.1-1.1 | 0.54.1-1.1 | Nov 27, 2023 | A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. | |
| CVE-2023-25165 | Med | 4.3 | < 0.37.3-1.1 | 0.37.3-1.1 | Feb 8, 2023 | Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a D | |
| CVE-2022-1996 | Cri | 9.1 | < 0.30.2-1.1 | 0.30.2-1.1 | Jun 8, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0. | |
| CVE-2022-28946 | Hig | 7.5 | < 0.28.0-1.1 | 0.28.0-1.1 | May 19, 2022 | An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. | |
| CVE-2022-23648 | Hig | 7.5 | < 0.26.0-1.1 | 0.26.0-1.1 | Mar 3, 2022 | containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could | |
| CVE-2021-32760 | Med | 5.0 | < 0.20.2-1.1 | 0.20.2-1.1 | Jul 19, 2021 | containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions |
- affected < 0.53.0-1.1fixed 0.53.0-1.1
HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
- affected < 0.52.0-1.1fixed 0.52.0-1.1
Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Clo
- affected < 0.58.2-1.1fixed 0.58.2-1.1
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.
- affected < 0.54.1-1.1fixed 0.54.1-1.1
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
- affected < 0.37.3-1.1fixed 0.37.3-1.1
Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a D
- affected < 0.30.2-1.1fixed 0.30.2-1.1
Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.
- affected < 0.28.0-1.1fixed 0.28.0-1.1
An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access.
- affected < 0.26.0-1.1fixed 0.26.0-1.1
containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could
- affected < 0.20.2-1.1fixed 0.20.2-1.1
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions
Page 4 of 4