VYPR

rpm package

suse/amazon-ssm-agent&distro=SUSE Linux Enterprise Module for Public Cloud 15 SP3

pkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP3

Vulnerabilities (4)

  • CVE-2025-47913Nov 13, 2025
    affected < 3.3.1611.0-150000.5.26.1fixed 3.3.1611.0-150000.5.26.1

    SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.

  • CVE-2025-22870MedMar 12, 2025
    affected < 3.3.1611.0-150000.5.23.1fixed 3.3.1611.0-150000.5.23.1

    Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

  • CVE-2025-21613Jan 6, 2025
    affected < 3.3.1611.0-150000.5.20.1fixed 3.3.1611.0-150000.5.20.1

    go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flag

  • CVE-2022-29527Apr 20, 2022
    affected < 3.1.1260.0-150000.5.9.2fixed 3.1.1260.0-150000.5.9.2

    Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.