rpm package
opensuse/trivy&distro=openSUSE Leap 15.5
pkg:rpm/opensuse/trivy&distro=openSUSE%20Leap%2015.5
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-6257 | — | < 0.54.1-bp155.2.3.1 | 0.54.1-bp155.2.3.1 | Jun 25, 2024 | HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution. | ||
| CVE-2024-35192 | Med | 5.5 | < 0.54.1-bp155.2.3.1 | 0.54.1-bp155.2.3.1 | May 20, 2024 | Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Clo | |
| CVE-2023-42363 | — | < 0.54.1-bp155.2.3.1 | 0.54.1-bp155.2.3.1 | Nov 27, 2023 | A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. |
- CVE-2024-6257Jun 25, 2024affected < 0.54.1-bp155.2.3.1fixed 0.54.1-bp155.2.3.1
HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
- affected < 0.54.1-bp155.2.3.1fixed 0.54.1-bp155.2.3.1
Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Clo
- CVE-2023-42363Nov 27, 2023affected < 0.54.1-bp155.2.3.1fixed 0.54.1-bp155.2.3.1
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.