VYPR

rpm package

suse/golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise Server 12 SP4-ESPOS

pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-ESPOS

Vulnerabilities (4)

  • CVE-2022-46146Nov 29, 2022
    affected < 1.5.0-1.24.4fixed 1.5.0-1.24.4

    Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0.

  • CVE-2022-41715Oct 14, 2022
    affected < 1.5.0-1.24.4fixed 1.5.0-1.24.4

    Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively sm

  • CVE-2022-27664Sep 6, 2022
    affected < 1.5.0-1.24.4fixed 1.5.0-1.24.4

    In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.

  • CVE-2022-27191Mar 18, 2022
    affected < 1.5.0-1.24.4fixed 1.5.0-1.24.4

    The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.