VYPR

rpm package

suse/skopeo&distro=SUSE Linux Micro 6.0

pkg:rpm/suse/skopeo&distro=SUSE%20Linux%20Micro%206.0

Vulnerabilities (7)

  • CVE-2025-22870MedMar 12, 2025
    affected < 1.14.4-3.1fixed 1.14.4-3.1

    Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

  • CVE-2025-27144MedFeb 24, 2025
    affected < 1.14.4-3.1fixed 1.14.4-3.1

    Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when par

  • CVE-2024-9676Oct 15, 2024
    affected < 1.14.4-2.1fixed 1.14.4-2.1

    A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned

  • CVE-2024-6104Jun 24, 2024
    affected < 1.14.4-3.1fixed 1.14.4-3.1

    go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

  • CVE-2024-3727HigMay 14, 2024
    affected < 1.14.4-1.1fixed 1.14.4-1.1

    A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

  • CVE-2023-45288HigApr 4, 2024
    affected < 1.14.4-3.1fixed 1.14.4-3.1

    An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed Ma

  • CVE-2024-28180Mar 9, 2024
    affected < 1.14.4-1.1fixed 1.14.4-1.1

    Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now ret