VYPR

Stereoscope

by Anchore

Source repositories

CVEs (1)

  • CVE-2024-24579MedJan 31, 2024
    risk 0.27cvss 5.3epss 0.00

    stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1, it is possible to craft an OCI tar archive that, when stereoscope attempts to unarchive the contents, will result in writing to paths outside of the unarchive…