VYPR

rpm package

suse/caddy&distro=SUSE Package Hub 15 SP5

pkg:rpm/suse/caddy&distro=SUSE%20Package%20Hub%2015%20SP5

Vulnerabilities (2)

  • CVE-2024-22189HigApr 4, 2024
    affected < 2.8.4-bp155.2.3.1fixed 2.8.4-bp155.2.3.1

    quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run out of memory sending a large number of `NEW_CONNECTION_ID` frames that retire old connection IDs. The receiver is supposed to respond to each retirement frame

  • CVE-2023-45142Oct 12, 2023
    affected < 2.8.4-bp155.2.3.1fixed 2.8.4-bp155.2.3.1

    OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests