VYPR

rpm package

suse/trivy&distro=SUSE Package Hub 15 SP5

pkg:rpm/suse/trivy&distro=SUSE%20Package%20Hub%2015%20SP5

Vulnerabilities (3)

  • CVE-2024-6257Jun 25, 2024
    affected < 0.54.1-bp155.2.3.1fixed 0.54.1-bp155.2.3.1

    HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

  • CVE-2024-35192MedMay 20, 2024
    affected < 0.54.1-bp155.2.3.1fixed 0.54.1-bp155.2.3.1

    Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Clo

  • CVE-2023-42363Nov 27, 2023
    affected < 0.54.1-bp155.2.3.1fixed 0.54.1-bp155.2.3.1

    A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.