VYPR

Packer

by Hashicorp

CVEs (2)

  • CVE-2018-15869MedAug 25, 2018
    risk 0.28cvss 5.3epss 0.02

    An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious…

  • CVE-2022-42717HigOct 11, 2022
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers…