VYPR
Vendor

Anchore

Products
10
CVEs
12
Across products
15
Status
Private

Products

10

Recent CVEs

12
  • CVE-2022-1766HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl…

  • CVE-2026-25076HigMar 13, 2026
    risk 0.47cvss 7.3epss 0.00

    Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenticated attacker that is able to access the GraphQL API could execute arbitrary SQL instructions resulting in modifications to the data contained in the Anchore…

  • CVE-2025-65965HigNov 25, 2025
    risk 0.46cvss epss 0.00

    Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found in Grype, affecting versions 0.68.0 through 0.104.0. If registry credentials are defined and the output of grype is written using the --file or --output…

  • CVE-2018-1999033MedAug 1, 2018
    risk 0.42cvss 6.5epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system access to the Jenkins master to obtain the password stored…

  • CVE-2023-24827MedFeb 7, 2023
    risk 0.35cvss 6.5epss 0.01

    syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. A password disclosure flaw was found in Syft versions v0.69.0 and v0.69.1. This flaw leaks the password stored in the SYFT_ATTEST_PASSWORD environment…

  • CVE-2026-31961MedMar 11, 2026
    risk 0.29cvss 5.5epss 0.00

    Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unbounded memory allocation vulnerability when parsing Mach-O binaries. Exploitation requires that Quill processes an attacker-supplied Mach-O binary, which is…

  • CVE-2026-33481MedMar 26, 2026
    risk 0.27cvss 5.3epss 0.00

    Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not properly cleanup temporary storage if the temporary storage was exhausted during a scan. When scanning archives…

  • CVE-2026-31960MedMar 11, 2026
    risk 0.27cvss 5.3epss 0.00

    Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies during the Apple notarization process. Exploitation requires the ability to modify API responses from Apple's notarization…

  • CVE-2026-31959MedMar 11, 2026
    risk 0.27cvss 5.3epss 0.00

    Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Server-Side Request Forgery (SSRF) vulnerability when attempting to fetch the Apple notarization submission logs. Exploitation requires the ability to modify API…

  • CVE-2024-24579MedJan 31, 2024
    risk 0.27cvss 5.3epss 0.00

    stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1, it is possible to craft an OCI tar archive that, when stereoscope attempts to unarchive the contents, will result in writing to paths outside of the unarchive…

  • CVE-2026-63727HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions…

  • CVE-2020-11075HigMay 27, 2020
    risk 0.00cvss 7.7epss 0.02

    In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer service during an image analysis process. The image analysis operation can only be executed by an…