Advisories
Open SourceExploitedCISA KEV listedHIGH2023-10-31
Red Hat Security Advisory: OpenShift Container Platform 4.14.0 security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| afterburn |
affected |
Red Hat:openshift:4.14::el9 |
afterburn |
— |
| afterburn-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
afterburn-debuginfo |
— |
| afterburn-dracut |
affected |
Red Hat:openshift:4.14::el9 |
afterburn-dracut |
— |
| bpftool |
affected |
Red Hat:openshift:4.14::el9 |
bpftool |
— |
| bpftool-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
bpftool-debuginfo |
— |
| buildah |
affected |
Red Hat:openshift:4.14::el8 |
buildah |
— |
| buildah |
affected |
Red Hat:openshift:4.14::el9 |
buildah |
— |
| buildah-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
buildah-debuginfo |
— |
| buildah-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
buildah-debuginfo |
— |
| buildah-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
buildah-debugsource |
— |
| buildah-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
buildah-debugsource |
— |
| buildah-tests |
affected |
Red Hat:openshift:4.14::el8 |
buildah-tests |
— |
| buildah-tests |
affected |
Red Hat:openshift:4.14::el9 |
buildah-tests |
— |
| buildah-tests-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
buildah-tests-debuginfo |
— |
| buildah-tests-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
buildah-tests-debuginfo |
— |
| butane |
affected |
Red Hat:openshift:4.14::el8 |
butane |
— |
| butane-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
butane-debuginfo |
— |
| butane-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
butane-debugsource |
— |
| butane-redistributable |
affected |
Red Hat:openshift:4.14::el8 |
butane-redistributable |
— |
| catch |
affected |
Red Hat:openshift:4.14::el9 |
catch |
— |
| catch-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
catch-debuginfo |
— |
| catch-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
catch-debugsource |
— |
| catch-devel |
affected |
Red Hat:openshift:4.14::el9 |
catch-devel |
— |
| conmon |
affected |
Red Hat:openshift:4.14::el8 |
conmon |
— |
| conmon |
affected |
Red Hat:openshift:4.14::el9 |
conmon |
— |
| conmon-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
conmon-debuginfo |
— |
| conmon-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
conmon-debuginfo |
— |
| conmon-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
conmon-debugsource |
— |
| conmon-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
conmon-debugsource |
— |
| containernetworking-plugins |
affected |
Red Hat:openshift:4.14::el8 |
containernetworking-plugins |
— |
| containernetworking-plugins-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
containernetworking-plugins-debuginfo |
— |
| containernetworking-plugins-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
containernetworking-plugins-debugsource |
— |
| containers-common |
affected |
Red Hat:openshift:4.14::el8 |
containers-common |
— |
| container-selinux |
affected |
Red Hat:openshift:4.14::el8 |
container-selinux |
— |
| container-selinux |
affected |
Red Hat:openshift:4.14::el9 |
container-selinux |
— |
| coreos-installer |
affected |
Red Hat:openshift:4.14::el9 |
coreos-installer |
— |
| coreos-installer |
affected |
Red Hat:openshift:4.14::el8 |
coreos-installer |
— |
| coreos-installer-bootinfra |
affected |
Red Hat:openshift:4.14::el8 |
coreos-installer-bootinfra |
— |
| coreos-installer-bootinfra |
affected |
Red Hat:openshift:4.14::el9 |
coreos-installer-bootinfra |
— |
| coreos-installer-bootinfra-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
coreos-installer-bootinfra-debuginfo |
— |
| coreos-installer-bootinfra-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
coreos-installer-bootinfra-debuginfo |
— |
| coreos-installer-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
coreos-installer-debuginfo |
— |
| coreos-installer-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
coreos-installer-debuginfo |
— |
| coreos-installer-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
coreos-installer-debugsource |
— |
| coreos-installer-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
coreos-installer-debugsource |
— |
| coreos-installer-dracut |
affected |
Red Hat:openshift:4.14::el9 |
coreos-installer-dracut |
— |
| coreos-installer-dracut |
affected |
Red Hat:openshift:4.14::el8 |
coreos-installer-dracut |
— |
| cri-o |
affected |
Red Hat:openshift:4.14::el8 |
cri-o |
— |
| cri-o |
affected |
Red Hat:openshift:4.14::el9 |
cri-o |
— |
| cri-o-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
cri-o-debuginfo |
— |
| cri-o-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
cri-o-debuginfo |
— |
| cri-o-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
cri-o-debugsource |
— |
| cri-o-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
cri-o-debugsource |
— |
| cri-tools |
affected |
Red Hat:openshift:4.14::el9 |
cri-tools |
— |
| cri-tools |
affected |
Red Hat:openshift:4.14::el8 |
cri-tools |
— |
| cri-tools-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
cri-tools-debuginfo |
— |
| cri-tools-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
cri-tools-debuginfo |
— |
| cri-tools-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
cri-tools-debugsource |
— |
| cri-tools-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
cri-tools-debugsource |
— |
| crun |
affected |
Red Hat:openshift:4.14::el9 |
crun |
— |
| crun |
affected |
Red Hat:openshift:4.14::el8 |
crun |
— |
| crun-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
crun-debuginfo |
— |
| crun-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
crun-debuginfo |
— |
| crun-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
crun-debugsource |
— |
| crun-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
crun-debugsource |
— |
| crun-wasm |
affected |
Red Hat:openshift:4.14::el8 |
crun-wasm |
— |
| crun-wasm |
affected |
Red Hat:openshift:4.14::el9 |
crun-wasm |
— |
| crun-wasm-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
crun-wasm-debuginfo |
— |
| crun-wasm-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
crun-wasm-debugsource |
— |
| fmt |
affected |
Red Hat:openshift:4.14::el9 |
fmt |
— |
| fmt-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
fmt-debuginfo |
— |
| fmt-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
fmt-debugsource |
— |
| fmt-devel |
affected |
Red Hat:openshift:4.14::el9 |
fmt-devel |
— |
| gmock |
affected |
Red Hat:openshift:4.14::el9 |
gmock |
— |
| gmock-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
gmock-debuginfo |
— |
| gmock-devel |
affected |
Red Hat:openshift:4.14::el9 |
gmock-devel |
— |
| golang-github-prometheus-promu |
affected |
Red Hat:openshift:4.14::el8 |
golang-github-prometheus-promu |
— |
| google-benchmark |
affected |
Red Hat:openshift:4.14::el9 |
google-benchmark |
— |
| google-benchmark-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
google-benchmark-debuginfo |
— |
| google-benchmark-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
google-benchmark-debugsource |
— |
| google-benchmark-devel |
affected |
Red Hat:openshift:4.14::el9 |
google-benchmark-devel |
— |
| google-benchmark-doc |
affected |
Red Hat:openshift:4.14::el9 |
google-benchmark-doc |
— |
| gtest |
affected |
Red Hat:openshift:4.14::el9 |
gtest |
— |
| gtest-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
gtest-debuginfo |
— |
| gtest-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
gtest-debugsource |
— |
| gtest-devel |
affected |
Red Hat:openshift:4.14::el9 |
gtest-devel |
— |
| haproxy |
affected |
Red Hat:openshift:4.14::el8 |
haproxy |
— |
| haproxy26 |
affected |
Red Hat:openshift:4.14::el8 |
haproxy26 |
— |
| haproxy26-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
haproxy26-debuginfo |
— |
| haproxy-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
haproxy-debugsource |
— |
| ignition |
affected |
Red Hat:openshift:4.14::el9 |
ignition |
— |
| ignition-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
ignition-debuginfo |
— |
| ignition-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
ignition-debugsource |
— |
| ignition-validate |
affected |
Red Hat:openshift:4.14::el9 |
ignition-validate |
— |
| ignition-validate-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
ignition-validate-debuginfo |
— |
| kata-containers |
affected |
Red Hat:openshift:4.14::el9 |
kata-containers |
— |
| kernel |
affected |
Red Hat:openshift:4.14::el9 |
kernel |
— |
| kernel-64k |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k |
— |
| kernel-64k-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-core |
— |
| kernel-64k-debug |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debug |
— |
| kernel-64k-debug-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debug-core |
— |
| kernel-64k-debug-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debug-debuginfo |
— |
| kernel-64k-debug-devel |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debug-devel |
— |
| kernel-64k-debug-devel-matched |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debug-devel-matched |
— |
| kernel-64k-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debuginfo |
— |
| kernel-64k-debug-modules |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debug-modules |
— |
| kernel-64k-debug-modules-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debug-modules-core |
— |
| kernel-64k-debug-modules-extra |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debug-modules-extra |
— |
| kernel-64k-debug-modules-internal |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debug-modules-internal |
— |
| kernel-64k-debug-modules-partner |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-debug-modules-partner |
— |
| kernel-64k-devel |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-devel |
— |
| kernel-64k-devel-matched |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-devel-matched |
— |
| kernel-64k-modules |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-modules |
— |
| kernel-64k-modules-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-modules-core |
— |
| kernel-64k-modules-extra |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-modules-extra |
— |
| kernel-64k-modules-internal |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-modules-internal |
— |
| kernel-64k-modules-partner |
affected |
Red Hat:openshift:4.14::el9 |
kernel-64k-modules-partner |
— |
| kernel-abi-stablelists |
affected |
Red Hat:openshift:4.14::el9 |
kernel-abi-stablelists |
— |
| kernel-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-core |
— |
| kernel-debug |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug |
— |
| kernel-debug-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug-core |
— |
| kernel-debug-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug-debuginfo |
— |
| kernel-debug-devel |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug-devel |
— |
| kernel-debug-devel-matched |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug-devel-matched |
— |
| kernel-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debuginfo |
— |
| kernel-debuginfo-common-aarch64 |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debuginfo-common-aarch64 |
— |
| kernel-debuginfo-common-ppc64le |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debuginfo-common-ppc64le |
— |
| kernel-debuginfo-common-s390x |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debuginfo-common-s390x |
— |
| kernel-debuginfo-common-x86_64 |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debuginfo-common-x86_64 |
— |
| kernel-debug-modules |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug-modules |
— |
| kernel-debug-modules-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug-modules-core |
— |
| kernel-debug-modules-extra |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug-modules-extra |
— |
| kernel-debug-modules-internal |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug-modules-internal |
— |
| kernel-debug-modules-partner |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug-modules-partner |
— |
| kernel-debug-uki-virt |
affected |
Red Hat:openshift:4.14::el9 |
kernel-debug-uki-virt |
— |
| kernel-devel |
affected |
Red Hat:openshift:4.14::el9 |
kernel-devel |
— |
| kernel-devel-matched |
affected |
Red Hat:openshift:4.14::el9 |
kernel-devel-matched |
— |
| kernel-doc |
affected |
Red Hat:openshift:4.14::el9 |
kernel-doc |
— |
| kernel-ipaclones-internal |
affected |
Red Hat:openshift:4.14::el9 |
kernel-ipaclones-internal |
— |
| kernel-modules |
affected |
Red Hat:openshift:4.14::el9 |
kernel-modules |
— |
| kernel-modules-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-modules-core |
— |
| kernel-modules-extra |
affected |
Red Hat:openshift:4.14::el9 |
kernel-modules-extra |
— |
| kernel-modules-internal |
affected |
Red Hat:openshift:4.14::el9 |
kernel-modules-internal |
— |
| kernel-modules-partner |
affected |
Red Hat:openshift:4.14::el9 |
kernel-modules-partner |
— |
| kernel-rt |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt |
— |
| kernel-rt-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-core |
— |
| kernel-rt-debug |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug |
— |
| kernel-rt-debug-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug-core |
— |
| kernel-rt-debug-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug-debuginfo |
— |
| kernel-rt-debug-devel |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug-devel |
— |
| kernel-rt-debug-devel-matched |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug-devel-matched |
— |
| kernel-rt-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debuginfo |
— |
| kernel-rt-debuginfo-common-x86_64 |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debuginfo-common-x86_64 |
— |
| kernel-rt-debug-kvm |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug-kvm |
— |
| kernel-rt-debug-modules |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug-modules |
— |
| kernel-rt-debug-modules-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug-modules-core |
— |
| kernel-rt-debug-modules-extra |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug-modules-extra |
— |
| kernel-rt-debug-modules-internal |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug-modules-internal |
— |
| kernel-rt-debug-modules-partner |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-debug-modules-partner |
— |
| kernel-rt-devel |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-devel |
— |
| kernel-rt-devel-matched |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-devel-matched |
— |
| kernel-rt-kvm |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-kvm |
— |
| kernel-rt-modules |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-modules |
— |
| kernel-rt-modules-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-modules-core |
— |
| kernel-rt-modules-extra |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-modules-extra |
— |
| kernel-rt-modules-internal |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-modules-internal |
— |
| kernel-rt-modules-partner |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-modules-partner |
— |
| kernel-rt-selftests-internal |
affected |
Red Hat:openshift:4.14::el9 |
kernel-rt-selftests-internal |
— |
| kernel-selftests-internal |
affected |
Red Hat:openshift:4.14::el9 |
kernel-selftests-internal |
— |
| kernel-tools |
affected |
Red Hat:openshift:4.14::el9 |
kernel-tools |
— |
| kernel-tools-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
kernel-tools-debuginfo |
— |
| kernel-tools-libs |
affected |
Red Hat:openshift:4.14::el9 |
kernel-tools-libs |
— |
| kernel-tools-libs-devel |
affected |
Red Hat:openshift:4.14::el9 |
kernel-tools-libs-devel |
— |
| kernel-uki-virt |
affected |
Red Hat:openshift:4.14::el9 |
kernel-uki-virt |
— |
| kernel-zfcpdump |
affected |
Red Hat:openshift:4.14::el9 |
kernel-zfcpdump |
— |
| kernel-zfcpdump-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-zfcpdump-core |
— |
| kernel-zfcpdump-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
kernel-zfcpdump-debuginfo |
— |
| kernel-zfcpdump-devel |
affected |
Red Hat:openshift:4.14::el9 |
kernel-zfcpdump-devel |
— |
| kernel-zfcpdump-devel-matched |
affected |
Red Hat:openshift:4.14::el9 |
kernel-zfcpdump-devel-matched |
— |
| kernel-zfcpdump-modules |
affected |
Red Hat:openshift:4.14::el9 |
kernel-zfcpdump-modules |
— |
| kernel-zfcpdump-modules-core |
affected |
Red Hat:openshift:4.14::el9 |
kernel-zfcpdump-modules-core |
— |
| kernel-zfcpdump-modules-extra |
affected |
Red Hat:openshift:4.14::el9 |
kernel-zfcpdump-modules-extra |
— |
| kernel-zfcpdump-modules-internal |
affected |
Red Hat:openshift:4.14::el9 |
kernel-zfcpdump-modules-internal |
— |
| kernel-zfcpdump-modules-partner |
affected |
Red Hat:openshift:4.14::el9 |
kernel-zfcpdump-modules-partner |
— |
| nmstate |
affected |
Red Hat:openshift:4.14::el8 |
nmstate |
— |
| nmstate-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
nmstate-debuginfo |
— |
| nmstate-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
nmstate-debugsource |
— |
| nmstate-devel |
affected |
Red Hat:openshift:4.14::el8 |
nmstate-devel |
— |
| nmstate-libs |
affected |
Red Hat:openshift:4.14::el8 |
nmstate-libs |
— |
| nmstate-libs-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
nmstate-libs-debuginfo |
— |
| nmstate-static |
affected |
Red Hat:openshift:4.14::el8 |
nmstate-static |
— |
| openshift |
affected |
Red Hat:openshift:4.14::el8 |
openshift |
— |
| openshift |
affected |
Red Hat:openshift:4.14::el9 |
openshift |
— |
| openshift4-aws-iso |
affected |
Red Hat:openshift:4.14::el8 |
openshift4-aws-iso |
— |
| openshift-ansible |
affected |
Red Hat:openshift:4.14::el8 |
openshift-ansible |
— |
| openshift-ansible |
affected |
Red Hat:openshift:4.14::el9 |
openshift-ansible |
— |
| openshift-ansible-test |
affected |
Red Hat:openshift:4.14::el9 |
openshift-ansible-test |
— |
| openshift-ansible-test |
affected |
Red Hat:openshift:4.14::el8 |
openshift-ansible-test |
— |
| openshift-clients |
affected |
Red Hat:openshift:4.14::el9 |
openshift-clients |
— |
| openshift-clients |
affected |
Red Hat:openshift:4.14::el8 |
openshift-clients |
— |
| openshift-clients-redistributable |
affected |
Red Hat:openshift:4.14::el9 |
openshift-clients-redistributable |
— |
| openshift-clients-redistributable |
affected |
Red Hat:openshift:4.14::el8 |
openshift-clients-redistributable |
— |
| openshift-hyperkube |
affected |
Red Hat:openshift:4.14::el9 |
openshift-hyperkube |
— |
| openshift-hyperkube |
affected |
Red Hat:openshift:4.14::el8 |
openshift-hyperkube |
— |
| openshift-kuryr |
affected |
Red Hat:openshift:4.14::el8 |
openshift-kuryr |
— |
| openshift-kuryr-cni |
affected |
Red Hat:openshift:4.14::el8 |
openshift-kuryr-cni |
— |
| openshift-kuryr-common |
affected |
Red Hat:openshift:4.14::el8 |
openshift-kuryr-common |
— |
| openshift-kuryr-controller |
affected |
Red Hat:openshift:4.14::el8 |
openshift-kuryr-controller |
— |
| openshift-prometheus-promu |
affected |
Red Hat:openshift:4.14::el8 |
openshift-prometheus-promu |
— |
| openstack-ironic |
affected |
Red Hat:openshift_ironic:4.14::el9 |
openstack-ironic |
— |
| openstack-ironic-api |
affected |
Red Hat:openshift_ironic:4.14::el9 |
openstack-ironic-api |
— |
| openstack-ironic-common |
affected |
Red Hat:openshift_ironic:4.14::el9 |
openstack-ironic-common |
— |
| openstack-ironic-conductor |
affected |
Red Hat:openshift_ironic:4.14::el9 |
openstack-ironic-conductor |
— |
| openstack-ironic-dnsmasq-tftp-server |
affected |
Red Hat:openshift_ironic:4.14::el9 |
openstack-ironic-dnsmasq-tftp-server |
— |
| openstack-ironic-inspector |
affected |
Red Hat:openshift_ironic:4.14::el9 |
openstack-ironic-inspector |
— |
| openstack-ironic-inspector-api |
affected |
Red Hat:openshift_ironic:4.14::el9 |
openstack-ironic-inspector-api |
— |
| openstack-ironic-inspector-conductor |
affected |
Red Hat:openshift_ironic:4.14::el9 |
openstack-ironic-inspector-conductor |
— |
| openstack-ironic-inspector-dnsmasq |
affected |
Red Hat:openshift_ironic:4.14::el9 |
openstack-ironic-inspector-dnsmasq |
— |
| openstack-ironic-python-agent |
affected |
Red Hat:openshift_ironic:4.14::el9 |
openstack-ironic-python-agent |
— |
| ovn23.09 |
affected |
Red Hat:openshift:4.14::el9 |
ovn23.09 |
— |
| ovn23.09-central |
affected |
Red Hat:openshift:4.14::el9 |
ovn23.09-central |
— |
| ovn23.09-central-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
ovn23.09-central-debuginfo |
— |
| ovn23.09-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
ovn23.09-debuginfo |
— |
| ovn23.09-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
ovn23.09-debugsource |
— |
| ovn23.09-host |
affected |
Red Hat:openshift:4.14::el9 |
ovn23.09-host |
— |
| ovn23.09-host-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
ovn23.09-host-debuginfo |
— |
| ovn23.09-vtep |
affected |
Red Hat:openshift:4.14::el9 |
ovn23.09-vtep |
— |
| ovn23.09-vtep-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
ovn23.09-vtep-debuginfo |
— |
| perf |
affected |
Red Hat:openshift:4.14::el9 |
perf |
— |
| perf-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
perf-debuginfo |
— |
| podman |
affected |
Red Hat:openshift:4.14::el8 |
podman |
— |
| podman |
affected |
Red Hat:openshift:4.14::el9 |
podman |
— |
| podman-catatonit |
affected |
Red Hat:openshift:4.14::el8 |
podman-catatonit |
— |
| podman-catatonit-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
podman-catatonit-debuginfo |
— |
| podman-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
podman-debuginfo |
— |
| podman-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
podman-debuginfo |
— |
| podman-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
podman-debugsource |
— |
| podman-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
podman-debugsource |
— |
| podman-docker |
affected |
Red Hat:openshift:4.14::el9 |
podman-docker |
— |
| podman-docker |
affected |
Red Hat:openshift:4.14::el8 |
podman-docker |
— |
| podman-gvproxy |
affected |
Red Hat:openshift:4.14::el9 |
podman-gvproxy |
— |
| podman-gvproxy |
affected |
Red Hat:openshift:4.14::el8 |
podman-gvproxy |
— |
| podman-gvproxy-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
podman-gvproxy-debuginfo |
— |
| podman-gvproxy-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
podman-gvproxy-debuginfo |
— |
| podman-plugins |
affected |
Red Hat:openshift:4.14::el9 |
podman-plugins |
— |
| podman-plugins |
affected |
Red Hat:openshift:4.14::el8 |
podman-plugins |
— |
| podman-plugins-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
podman-plugins-debuginfo |
— |
| podman-plugins-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
podman-plugins-debuginfo |
— |
| podman-remote |
affected |
Red Hat:openshift:4.14::el9 |
podman-remote |
— |
| podman-remote |
affected |
Red Hat:openshift:4.14::el8 |
podman-remote |
— |
| podman-remote-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
podman-remote-debuginfo |
— |
| podman-remote-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
podman-remote-debuginfo |
— |
| podman-tests |
affected |
Red Hat:openshift:4.14::el9 |
podman-tests |
— |
| podman-tests |
affected |
Red Hat:openshift:4.14::el8 |
podman-tests |
— |
| python3-automaton |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-automaton |
— |
| python3-cinderclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-cinderclient |
— |
| python3-cliff |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-cliff |
— |
| python3-cliff-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-cliff-tests |
— |
| python3-debtcollector |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-debtcollector |
— |
| python3-decorator |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-decorator |
— |
| python3-dracclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-dracclient |
— |
| python3-fixtures |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-fixtures |
— |
| python3-futurist |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-futurist |
— |
| python3-glanceclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-glanceclient |
— |
| python3-hardware |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-hardware |
— |
| python3-hardware-detect |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-hardware-detect |
— |
| python3-ironic-inspector-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-ironic-inspector-tests |
— |
| python3-ironic-lib |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-ironic-lib |
— |
| python3-ironic-prometheus-exporter |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-ironic-prometheus-exporter |
— |
| python3-ironic-python-agent |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-ironic-python-agent |
— |
| python3-ironic-python-agent-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-ironic-python-agent-tests |
— |
| python3-ironic-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-ironic-tests |
— |
| python3-keystoneauth1 |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-keystoneauth1 |
— |
| python3-keystoneclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-keystoneclient |
— |
| python3-keystoneclient-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-keystoneclient-tests |
— |
| python3-keystonemiddleware |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-keystonemiddleware |
— |
| python3-kuryr-kubernetes |
affected |
Red Hat:openshift:4.14::el8 |
python3-kuryr-kubernetes |
— |
| python3-libnmstate |
affected |
Red Hat:openshift:4.14::el8 |
python3-libnmstate |
— |
| python3-openstacksdk |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-openstacksdk |
— |
| python3-openstacksdk-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-openstacksdk-tests |
— |
| python3-osc-lib |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-osc-lib |
— |
| python3-osc-lib-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-osc-lib-tests |
— |
| python3-oslo-cache |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-cache |
— |
| python3-oslo-cache-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-cache-tests |
— |
| python3-oslo-concurrency |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-concurrency |
— |
| python3-oslo-concurrency-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-concurrency-tests |
— |
| python3-oslo-config |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-config |
— |
| python3-oslo-context |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-context |
— |
| python3-oslo-context-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-context-tests |
— |
| python3-oslo-db |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-db |
— |
| python3-oslo-db-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-db-tests |
— |
| python3-oslo-i18n |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-i18n |
— |
| python3-oslo-log |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-log |
— |
| python3-oslo-log-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-log-tests |
— |
| python3-oslo-messaging |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-messaging |
— |
| python3-oslo-messaging-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-messaging-tests |
— |
| python3-oslo-middleware |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-middleware |
— |
| python3-oslo-middleware-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-middleware-tests |
— |
| python3-oslo-policy |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-policy |
— |
| python3-oslo-policy-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-policy-tests |
— |
| python3-oslo-rootwrap |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-rootwrap |
— |
| python3-oslo-rootwrap-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-rootwrap-tests |
— |
| python3-oslo-serialization |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-serialization |
— |
| python3-oslo-serialization-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-serialization-tests |
— |
| python3-oslo-service |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-service |
— |
| python3-oslo-service-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-service-tests |
— |
| python3-oslo-upgradecheck |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-upgradecheck |
— |
| python3-oslo-utils |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-utils |
— |
| python3-oslo-utils-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-utils-tests |
— |
| python3-oslo-versionedobjects |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-versionedobjects |
— |
| python3-oslo-versionedobjects-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-oslo-versionedobjects-tests |
— |
| python3-osprofiler |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-osprofiler |
— |
| python3-os-service-types |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-os-service-types |
— |
| python3-os-traits |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-os-traits |
— |
| python3-os-traits-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-os-traits-tests |
— |
| python3-pbr |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-pbr |
— |
| python3-perf |
affected |
Red Hat:openshift:4.14::el9 |
python3-perf |
— |
| python3-perf-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
python3-perf-debuginfo |
— |
| python3-proliantutils |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-proliantutils |
— |
| python3-pycadf |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-pycadf |
— |
| python3-requestsexceptions |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-requestsexceptions |
— |
| python3-scciclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-scciclient |
— |
| python3-stevedore |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-stevedore |
— |
| python3-sushy |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-sushy |
— |
| python3-sushy-oem-idrac |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-sushy-oem-idrac |
— |
| python3-sushy-oem-idrac-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-sushy-oem-idrac-tests |
— |
| python3-sushy-tests |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-sushy-tests |
— |
| python3-swiftclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-swiftclient |
— |
| python3-tenacity |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-tenacity |
— |
| python3-tooz |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-tooz |
— |
| python3-wrapt |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-wrapt |
— |
| python3-wrapt-debuginfo |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python3-wrapt-debuginfo |
— |
| python-automaton |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-automaton |
— |
| python-cinderclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-cinderclient |
— |
| python-cliff |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-cliff |
— |
| python-debtcollector |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-debtcollector |
— |
| python-decorator |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-decorator |
— |
| python-dracclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-dracclient |
— |
| python-fixtures |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-fixtures |
— |
| python-futurist |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-futurist |
— |
| python-glanceclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-glanceclient |
— |
| python-hardware |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-hardware |
— |
| python-ironic-lib |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-ironic-lib |
— |
| python-ironic-prometheus-exporter |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-ironic-prometheus-exporter |
— |
| python-keystoneauth1 |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-keystoneauth1 |
— |
| python-keystoneclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-keystoneclient |
— |
| python-keystonemiddleware |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-keystonemiddleware |
— |
| python-openstacksdk |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-openstacksdk |
— |
| python-osc-lib |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-osc-lib |
— |
| python-oslo-cache |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-cache |
— |
| python-oslo-cache-lang |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-cache-lang |
— |
| python-oslo-concurrency |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-concurrency |
— |
| python-oslo-concurrency-lang |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-concurrency-lang |
— |
| python-oslo-config |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-config |
— |
| python-oslo-context |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-context |
— |
| python-oslo-db |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-db |
— |
| python-oslo-db-lang |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-db-lang |
— |
| python-oslo-i18n |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-i18n |
— |
| python-oslo-i18n-lang |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-i18n-lang |
— |
| python-oslo-log |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-log |
— |
| python-oslo-log-lang |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-log-lang |
— |
| python-oslo-messaging |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-messaging |
— |
| python-oslo-middleware |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-middleware |
— |
| python-oslo-middleware-lang |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-middleware-lang |
— |
| python-oslo-policy |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-policy |
— |
| python-oslo-policy-lang |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-policy-lang |
— |
| python-oslo-rootwrap |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-rootwrap |
— |
| python-oslo-serialization |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-serialization |
— |
| python-oslo-service |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-service |
— |
| python-oslo-upgradecheck |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-upgradecheck |
— |
| python-oslo-utils |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-utils |
— |
| python-oslo-utils-lang |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-utils-lang |
— |
| python-oslo-versionedobjects |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-versionedobjects |
— |
| python-oslo-versionedobjects-lang |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-oslo-versionedobjects-lang |
— |
| python-osprofiler |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-osprofiler |
— |
| python-os-service-types |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-os-service-types |
— |
| python-os-traits |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-os-traits |
— |
| python-pbr |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-pbr |
— |
| python-proliantutils |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-proliantutils |
— |
| python-pycadf |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-pycadf |
— |
| python-pycadf-common |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-pycadf-common |
— |
| python-requestsexceptions |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-requestsexceptions |
— |
| python-scciclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-scciclient |
— |
| python-stevedore |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-stevedore |
— |
| python-sushy |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-sushy |
— |
| python-sushy-oem-idrac |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-sushy-oem-idrac |
— |
| python-swiftclient |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-swiftclient |
— |
| python-tenacity |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-tenacity |
— |
| python-tooz |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-tooz |
— |
| python-wrapt |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-wrapt |
— |
| python-wrapt-debugsource |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-wrapt-debugsource |
— |
| python-wrapt-doc |
affected |
Red Hat:openshift_ironic:4.14::el9 |
python-wrapt-doc |
— |
| rtla |
affected |
Red Hat:openshift:4.14::el9 |
rtla |
— |
| runc |
affected |
Red Hat:openshift:4.14::el9 |
runc |
— |
| runc |
affected |
Red Hat:openshift:4.14::el8 |
runc |
— |
| runc-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
runc-debuginfo |
— |
| runc-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
runc-debuginfo |
— |
| runc-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
runc-debugsource |
— |
| runc-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
runc-debugsource |
— |
| rust-afterburn |
affected |
Red Hat:openshift:4.14::el9 |
rust-afterburn |
— |
| rust-afterburn-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
rust-afterburn-debugsource |
— |
| skopeo |
affected |
Red Hat:openshift:4.14::el8 |
skopeo |
— |
| skopeo |
affected |
Red Hat:openshift:4.14::el9 |
skopeo |
— |
| skopeo-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
skopeo-debuginfo |
— |
| skopeo-debuginfo |
affected |
Red Hat:openshift:4.14::el8 |
skopeo-debuginfo |
— |
| skopeo-debugsource |
affected |
Red Hat:openshift:4.14::el8 |
skopeo-debugsource |
— |
| skopeo-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
skopeo-debugsource |
— |
| skopeo-tests |
affected |
Red Hat:openshift:4.14::el8 |
skopeo-tests |
— |
| skopeo-tests |
affected |
Red Hat:openshift:4.14::el9 |
skopeo-tests |
— |
| spdlog |
affected |
Red Hat:openshift:4.14::el9 |
spdlog |
— |
| spdlog-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
spdlog-debuginfo |
— |
| spdlog-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
spdlog-debugsource |
— |
| spdlog-devel |
affected |
Red Hat:openshift:4.14::el9 |
spdlog-devel |
— |
| toolbox |
affected |
Red Hat:openshift:4.14::el9 |
toolbox |
— |
| wasmedge |
affected |
Red Hat:openshift:4.14::el9 |
wasmedge |
— |
| wasmedge-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
wasmedge-debuginfo |
— |
| wasmedge-debugsource |
affected |
Red Hat:openshift:4.14::el9 |
wasmedge-debugsource |
— |
| wasmedge-devel |
affected |
Red Hat:openshift:4.14::el9 |
wasmedge-devel |
— |
| wasmedge-rt |
affected |
Red Hat:openshift:4.14::el9 |
wasmedge-rt |
— |
| wasmedge-rt-debuginfo |
affected |
Red Hat:openshift:4.14::el9 |
wasmedge-rt-debuginfo |
— |
Open SourceExploitedCISA KEV listedNONE2023-10-24
Important: go-toolset:rhel8 security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| delve |
affected |
Rocky Linux:8 |
delve |
— |
| golang |
affected |
Rocky Linux:8 |
golang |
— |
| go-toolset |
affected |
Rocky Linux:8 |
go-toolset |
— |
Open SourceExploitedCISA KEV listedHIGH2023-10-20
Red Hat Security Advisory: Red Hat OpenStack Platform 16.2.5 (collectd-libpod-stats, etcd) security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| etcd |
affected |
Red Hat:openstack:16.2::el8 |
etcd |
— |
| etcd-debuginfo |
affected |
Red Hat:openstack:16.2::el8 |
etcd-debuginfo |
— |
| etcd-debugsource |
affected |
Red Hat:openstack:16.2::el8 |
etcd-debugsource |
— |
| python3-octavia-tests-tempest |
affected |
Red Hat:openstack:16.2::el8 |
python3-octavia-tests-tempest |
— |
| python3-octavia-tests-tempest-golang |
affected |
Red Hat:openstack:16.2::el8 |
python3-octavia-tests-tempest-golang |
— |
| python3-octavia-tests-tempest-golang-debuginfo |
affected |
Red Hat:openstack:16.2::el8 |
python3-octavia-tests-tempest-golang-debuginfo |
— |
| python-octavia-tests-tempest |
affected |
Red Hat:openstack:16.2::el8 |
python-octavia-tests-tempest |
— |
| python-octavia-tests-tempest-debugsource |
affected |
Red Hat:openstack:16.2::el8 |
python-octavia-tests-tempest-debugsource |
— |
Open SourceExploitedCISA KEV listedHIGH2023-10-20
Red Hat Security Advisory: Red Hat OpenStack Platform 16.1.9 (collectd-libpod-stats, etcd) security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| collectd-libpod-stats |
affected |
Red Hat:openstack:16.1::el8 |
collectd-libpod-stats |
— |
| etcd |
affected |
Red Hat:openstack:16.1::el8 |
etcd |
— |
| etcd-debuginfo |
affected |
Red Hat:openstack:16.1::el8 |
etcd-debuginfo |
— |
| etcd-debugsource |
affected |
Red Hat:openstack:16.1::el8 |
etcd-debugsource |
— |
| python3-octavia-tests-tempest |
affected |
Red Hat:openstack:16.1::el8 |
python3-octavia-tests-tempest |
— |
| python3-octavia-tests-tempest-golang |
affected |
Red Hat:openstack:16.1::el8 |
python3-octavia-tests-tempest-golang |
— |
| python3-octavia-tests-tempest-golang-debuginfo |
affected |
Red Hat:openstack:16.1::el8 |
python3-octavia-tests-tempest-golang-debuginfo |
— |
| python-octavia-tests-tempest |
affected |
Red Hat:openstack:16.1::el8 |
python-octavia-tests-tempest |
— |
| python-octavia-tests-tempest-debugsource |
affected |
Red Hat:openstack:16.1::el8 |
python-octavia-tests-tempest-debugsource |
— |
Open SourceExploitedCISA KEV listedHIGH2023-10-20
Red Hat Security Advisory: Red Hat OpenStack Platform 17.1.1 security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| collectd-libpod-stats |
affected |
Red Hat:openstack:17.1::el9 |
collectd-libpod-stats |
— |
| etcd |
affected |
Red Hat:openstack:17.1::el9 |
etcd |
— |
| etcd-debuginfo |
affected |
Red Hat:openstack:17.1::el9 |
etcd-debuginfo |
— |
| etcd-debugsource |
affected |
Red Hat:openstack:17.1::el9 |
etcd-debugsource |
— |
| python3-octavia-tests-tempest |
affected |
Red Hat:openstack:17.1::el9 |
python3-octavia-tests-tempest |
— |
| python3-octavia-tests-tempest-golang |
affected |
Red Hat:openstack:17.1::el9 |
python3-octavia-tests-tempest-golang |
— |
| python3-octavia-tests-tempest-golang-debuginfo |
affected |
Red Hat:openstack:17.1::el9 |
python3-octavia-tests-tempest-golang-debuginfo |
— |
| python-octavia-tests-tempest |
affected |
Red Hat:openstack:17.1::el9 |
python-octavia-tests-tempest |
— |
| python-octavia-tests-tempest-debugsource |
affected |
Red Hat:openstack:17.1::el9 |
python-octavia-tests-tempest-debugsource |
— |
Open SourceExploitedCISA KEV listedHIGH2023-10-16
Red Hat Security Advisory: go-toolset and golang security and bug fix update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Red Hat:enterprise_linux:9::appstream |
golang |
— |
| golang-bin |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-bin |
— |
| golang-docs |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-docs |
— |
| golang-misc |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-misc |
— |
| golang-race |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-race |
— |
| golang-src |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-src |
— |
| golang-tests |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-tests |
— |
Open SourceExploitedCISA KEV listedHIGH2023-10-16
Red Hat Security Advisory: go-toolset:rhel8 security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| delve |
affected |
Red Hat:enterprise_linux:8::appstream |
delve |
— |
| delve-debuginfo |
affected |
Red Hat:enterprise_linux:8::appstream |
delve-debuginfo |
— |
| delve-debugsource |
affected |
Red Hat:enterprise_linux:8::appstream |
delve-debugsource |
— |
| golang |
affected |
Red Hat:enterprise_linux:8::appstream |
golang |
— |
| golang-bin |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-bin |
— |
| golang-docs |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-docs |
— |
| golang-misc |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-misc |
— |
| golang-race |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-race |
— |
| golang-src |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-src |
— |
| golang-tests |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-tests |
— |
| go-toolset |
affected |
Red Hat:enterprise_linux:8::appstream |
go-toolset |
— |
Open SourceExploitedCISA KEV listedHIGH2023-10-16
Red Hat Security Advisory: go-toolset-1.19 and go-toolset-1.19-golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go-toolset-1.19 |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19 |
— |
| go-toolset-1.19-build |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-build |
— |
| go-toolset-1.19-golang |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang |
— |
| go-toolset-1.19-golang-bin |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-bin |
— |
| go-toolset-1.19-golang-docs |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-docs |
— |
| go-toolset-1.19-golang-misc |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-misc |
— |
| go-toolset-1.19-golang-race |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-race |
— |
| go-toolset-1.19-golang-src |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-src |
— |
| go-toolset-1.19-golang-tests |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-tests |
— |
| go-toolset-1.19-runtime |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-runtime |
— |
| go-toolset-1.19-scldevel |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-scldevel |
— |
Open SourceExploitedCISA KEV listedNONE2023-10-16
Important: go-toolset:rhel8 security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| delve |
affected |
AlmaLinux:8 |
delve |
— |
| golang |
affected |
AlmaLinux:8 |
golang |
— |
| golang-bin |
affected |
AlmaLinux:8 |
golang-bin |
— |
| golang-docs |
affected |
AlmaLinux:8 |
golang-docs |
— |
| golang-misc |
affected |
AlmaLinux:8 |
golang-misc |
— |
| golang-race |
affected |
AlmaLinux:8 |
golang-race |
— |
| golang-src |
affected |
AlmaLinux:8 |
golang-src |
— |
| golang-tests |
affected |
AlmaLinux:8 |
golang-tests |
— |
| go-toolset |
affected |
AlmaLinux:8 |
go-toolset |
— |
Open SourceExploitedCISA KEV listedNONE2023-10-16
Important: go-toolset and golang security and bug fix update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
AlmaLinux:9 |
golang |
— |
| golang-bin |
affected |
AlmaLinux:9 |
golang-bin |
— |
| golang-docs |
affected |
AlmaLinux:9 |
golang-docs |
— |
| golang-misc |
affected |
AlmaLinux:9 |
golang-misc |
— |
| golang-race |
affected |
AlmaLinux:9 |
golang-race |
— |
| golang-src |
affected |
AlmaLinux:9 |
golang-src |
— |
| golang-tests |
affected |
AlmaLinux:9 |
golang-tests |
— |
| go-toolset |
affected |
AlmaLinux:9 |
go-toolset |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-11
HTTP/2 rapid reset can cause excessive work in net/http
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aactl |
affected |
chainguard |
aactl |
— |
| aactl |
affected |
wolfi |
aactl |
— |
| amass |
affected |
chainguard |
amass |
— |
| amass |
affected |
wolfi |
amass |
— |
| apko |
affected |
chainguard |
apko |
— |
| apko |
affected |
wolfi |
apko |
— |
| atlantis |
affected |
wolfi |
atlantis |
— |
| atlantis |
affected |
chainguard |
atlantis |
— |
| atlantis-fips |
affected |
chainguard |
atlantis-fips |
— |
| aws-ebs-csi-driver |
affected |
chainguard |
aws-ebs-csi-driver |
— |
| aws-efs-csi-driver |
affected |
wolfi |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver |
affected |
chainguard |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver-fips |
affected |
chainguard |
aws-efs-csi-driver-fips |
— |
| aws-load-balancer-controller |
affected |
wolfi |
aws-load-balancer-controller |
— |
| aws-load-balancer-controller |
affected |
chainguard |
aws-load-balancer-controller |
— |
| aws-load-balancer-controller-fips |
affected |
chainguard |
aws-load-balancer-controller-fips |
— |
| azure-aad-pod-identity-mic |
affected |
chainguard |
azure-aad-pod-identity-mic |
— |
| bank-vaults |
affected |
chainguard |
bank-vaults |
— |
| bank-vaults |
affected |
wolfi |
bank-vaults |
— |
| bank-vaults-fips |
affected |
chainguard |
bank-vaults-fips |
— |
| bom |
affected |
chainguard |
bom |
— |
| bom |
affected |
wolfi |
bom |
— |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| caddy |
affected |
chainguard |
caddy |
— |
| caddy |
affected |
wolfi |
caddy |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| configmap-reload-fips |
affected |
chainguard |
configmap-reload-fips |
— |
| configmap-reload-fips-0.11 |
affected |
chainguard |
configmap-reload-fips-0.11 |
— |
| cosign |
affected |
wolfi |
cosign |
— |
| cosign |
affected |
chainguard |
cosign |
— |
| crossplane-provider-aws |
affected |
chainguard |
crossplane-provider-aws |
— |
| crossplane-provider-aws |
affected |
wolfi |
crossplane-provider-aws |
— |
| crossplane-provider-azure |
affected |
chainguard |
crossplane-provider-azure |
— |
| crossplane-provider-azure |
affected |
wolfi |
crossplane-provider-azure |
— |
| cue |
affected |
wolfi |
cue |
— |
| cue |
affected |
chainguard |
cue |
— |
| dex |
affected |
chainguard |
dex |
— |
| dex |
affected |
wolfi |
dex |
— |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| dgraph |
affected |
chainguard |
dgraph |
— |
| dgraph |
affected |
wolfi |
dgraph |
— |
| dive |
affected |
chainguard |
dive |
— |
| dive |
affected |
wolfi |
dive |
— |
| dynamic-localpv-provisioner |
affected |
wolfi |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner |
affected |
chainguard |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| falcoctl |
affected |
chainguard |
falcoctl |
— |
| falcoctl |
affected |
wolfi |
falcoctl |
— |
| falcoctl-fips |
affected |
chainguard |
falcoctl-fips |
— |
| falcoctl-fips-0.4 |
affected |
chainguard |
falcoctl-fips-0.4 |
— |
| flux |
affected |
chainguard |
flux |
— |
| flux |
affected |
wolfi |
flux |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-image-automation-controller |
affected |
wolfi |
flux-image-automation-controller |
— |
| flux-image-automation-controller |
affected |
chainguard |
flux-image-automation-controller |
— |
| flux-image-reflector-controller |
affected |
chainguard |
flux-image-reflector-controller |
— |
| flux-image-reflector-controller |
affected |
wolfi |
flux-image-reflector-controller |
— |
| flux-kustomize-controller |
affected |
chainguard |
flux-kustomize-controller |
— |
| flux-kustomize-controller |
affected |
wolfi |
flux-kustomize-controller |
— |
| flux-notification-controller |
affected |
chainguard |
flux-notification-controller |
— |
| flux-notification-controller |
affected |
wolfi |
flux-notification-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| frp |
affected |
chainguard |
frp |
— |
| frp |
affected |
wolfi |
frp |
— |
| fuse-overlayfs-snapshotter |
affected |
wolfi |
fuse-overlayfs-snapshotter |
— |
| fuse-overlayfs-snapshotter |
affected |
chainguard |
fuse-overlayfs-snapshotter |
— |
| git-lfs |
affected |
wolfi |
git-lfs |
— |
| git-lfs |
affected |
chainguard |
git-lfs |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gke-gcloud-auth-plugin |
affected |
chainguard |
gke-gcloud-auth-plugin |
— |
| gke-gcloud-auth-plugin |
affected |
wolfi |
gke-gcloud-auth-plugin |
— |
| go-1.20 |
affected |
chainguard |
go-1.20 |
— |
| go-1.20 |
affected |
wolfi |
go-1.20 |
— |
| go-1.21 |
affected |
chainguard |
go-1.21 |
— |
| go-1.21 |
affected |
wolfi |
go-1.21 |
— |
| gobuster |
affected |
chainguard |
gobuster |
— |
| gobuster |
affected |
wolfi |
gobuster |
— |
| gomplate |
affected |
wolfi |
gomplate |
— |
| gomplate |
affected |
chainguard |
gomplate |
— |
| grpcurl |
affected |
wolfi |
grpcurl |
— |
| grpcurl |
affected |
chainguard |
grpcurl |
— |
| haproxy-ingress |
affected |
chainguard |
haproxy-ingress |
— |
| haproxy-ingress |
affected |
wolfi |
haproxy-ingress |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm-3 |
affected |
wolfi |
helm-3 |
— |
| helm-3 |
affected |
chainguard |
helm-3 |
— |
| helm-4 |
affected |
chainguard |
helm-4 |
— |
| helm-4 |
affected |
wolfi |
helm-4 |
— |
| hey |
affected |
wolfi |
hey |
— |
| hey |
affected |
chainguard |
hey |
— |
| hugo |
affected |
chainguard |
hugo |
— |
| hugo |
affected |
wolfi |
hugo |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k8sgpt-operator |
affected |
wolfi |
k8sgpt-operator |
— |
| k8sgpt-operator |
affected |
chainguard |
k8sgpt-operator |
— |
| kaf |
affected |
wolfi |
kaf |
— |
| kaf |
affected |
chainguard |
kaf |
— |
| kiam |
affected |
chainguard |
kiam |
— |
| kind |
affected |
chainguard |
kind |
— |
| kind |
affected |
wolfi |
kind |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kpt |
affected |
wolfi |
kpt |
— |
| kpt |
affected |
chainguard |
kpt |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kube-fluentd-operator |
affected |
wolfi |
kube-fluentd-operator |
— |
| kube-fluentd-operator |
affected |
chainguard |
kube-fluentd-operator |
— |
| kube-logging-logging-operator-3.17 |
affected |
chainguard |
kube-logging-logging-operator-3.17 |
— |
| kube-logging-logging-operator-4.1 |
affected |
chainguard |
kube-logging-logging-operator-4.1 |
— |
| kube-logging-operator |
affected |
wolfi |
kube-logging-operator |
— |
| kube-logging-operator |
affected |
chainguard |
kube-logging-operator |
— |
| kube-oidc-proxy |
affected |
chainguard |
kube-oidc-proxy |
— |
| kubernetes-csi-external-provisioner |
affected |
wolfi |
kubernetes-csi-external-provisioner |
— |
| kubernetes-csi-external-provisioner |
affected |
chainguard |
kubernetes-csi-external-provisioner |
— |
| kubernetes-csi-external-resizer |
affected |
chainguard |
kubernetes-csi-external-resizer |
— |
| kubernetes-csi-external-resizer |
affected |
wolfi |
kubernetes-csi-external-resizer |
— |
| kubernetes-csi-livenessprobe |
affected |
chainguard |
kubernetes-csi-livenessprobe |
— |
| kubernetes-csi-livenessprobe |
affected |
wolfi |
kubernetes-csi-livenessprobe |
— |
| kubernetes-csi-livenessprobe-2.10 |
affected |
chainguard |
kubernetes-csi-livenessprobe-2.10 |
— |
| kubernetes-csi-livenessprobe-fips |
affected |
chainguard |
kubernetes-csi-livenessprobe-fips |
— |
| kubernetes-dashboard |
affected |
wolfi |
kubernetes-dashboard |
— |
| kubernetes-dashboard |
affected |
chainguard |
kubernetes-dashboard |
— |
| kubernetes-dashboard-metrics-scraper |
affected |
wolfi |
kubernetes-dashboard-metrics-scraper |
— |
| kubernetes-dashboard-metrics-scraper |
affected |
chainguard |
kubernetes-dashboard-metrics-scraper |
— |
| kubernetes-dns-node-cache |
affected |
wolfi |
kubernetes-dns-node-cache |
— |
| kubernetes-dns-node-cache |
affected |
chainguard |
kubernetes-dns-node-cache |
— |
| kubernetes-ingress-defaultbackend |
affected |
chainguard |
kubernetes-ingress-defaultbackend |
— |
| kubernetes-ingress-defaultbackend |
affected |
wolfi |
kubernetes-ingress-defaultbackend |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kube-state-metrics |
affected |
wolfi |
kube-state-metrics |
— |
| kube-state-metrics |
affected |
chainguard |
kube-state-metrics |
— |
| kube-state-metrics-2.6 |
affected |
chainguard |
kube-state-metrics-2.6 |
— |
| kube-state-metrics-fips |
affected |
chainguard |
kube-state-metrics-fips |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubewatch |
affected |
chainguard |
kubewatch |
— |
| kubewatch |
affected |
wolfi |
kubewatch |
— |
| mc |
affected |
chainguard |
mc |
— |
| mc |
affected |
wolfi |
mc |
— |
| memcached-exporter |
affected |
wolfi |
memcached-exporter |
— |
| memcached-exporter |
affected |
chainguard |
memcached-exporter |
— |
| metacontroller |
affected |
wolfi |
metacontroller |
— |
| metacontroller |
affected |
chainguard |
metacontroller |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| metrics-server-fips |
affected |
chainguard |
metrics-server-fips |
— |
| minio |
affected |
chainguard |
minio |
— |
| minio |
affected |
wolfi |
minio |
— |
| nats |
affected |
wolfi |
nats |
— |
| nats |
affected |
chainguard |
nats |
— |
| newrelic-infrastructure-agent |
affected |
wolfi |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent |
affected |
chainguard |
newrelic-infrastructure-agent |
— |
| nfs-subdir-external-provisioner |
affected |
wolfi |
nfs-subdir-external-provisioner |
— |
| nfs-subdir-external-provisioner |
affected |
chainguard |
nfs-subdir-external-provisioner |
— |
| nfs-subdir-external-provisioner-fips |
affected |
chainguard |
nfs-subdir-external-provisioner-fips |
— |
| node-problem-detector-0.8 |
affected |
chainguard |
node-problem-detector-0.8 |
— |
| nodetaint |
affected |
chainguard |
nodetaint |
— |
| nodetaint |
affected |
wolfi |
nodetaint |
— |
| nri-prometheus |
affected |
wolfi |
nri-prometheus |
— |
| nri-prometheus |
affected |
chainguard |
nri-prometheus |
— |
| oauth2-proxy |
affected |
chainguard |
oauth2-proxy |
— |
| oauth2-proxy |
affected |
wolfi |
oauth2-proxy |
— |
| ollama |
affected |
chainguard |
ollama |
— |
| ollama |
affected |
wolfi |
ollama |
— |
| prometheus-adapter |
affected |
wolfi |
prometheus-adapter |
— |
| prometheus-adapter |
affected |
chainguard |
prometheus-adapter |
— |
| prometheus-adapter-0.10 |
affected |
chainguard |
prometheus-adapter-0.10 |
— |
| prometheus-adapter-fips |
affected |
chainguard |
prometheus-adapter-fips |
— |
| prometheus-adapter-fips-0.10 |
affected |
chainguard |
prometheus-adapter-fips-0.10 |
— |
| prometheus-alertmanager |
affected |
chainguard |
prometheus-alertmanager |
— |
| prometheus-alertmanager |
affected |
wolfi |
prometheus-alertmanager |
— |
| prometheus-bind-exporter |
affected |
chainguard |
prometheus-bind-exporter |
— |
| prometheus-blackbox-exporter |
affected |
chainguard |
prometheus-blackbox-exporter |
— |
| prometheus-elasticsearch-exporter |
affected |
chainguard |
prometheus-elasticsearch-exporter |
— |
| prometheus-elasticsearch-exporter-fips |
affected |
chainguard |
prometheus-elasticsearch-exporter-fips |
— |
| prometheus-mongodb-exporter |
affected |
chainguard |
prometheus-mongodb-exporter |
— |
| prometheus-mongodb-exporter-fips |
affected |
chainguard |
prometheus-mongodb-exporter-fips |
— |
| prometheus-mongodb-exporter-fips-0.37 |
affected |
chainguard |
prometheus-mongodb-exporter-fips-0.37 |
— |
| prometheus-mysqld-exporter |
affected |
chainguard |
prometheus-mysqld-exporter |
— |
| prometheus-node-exporter |
affected |
chainguard |
prometheus-node-exporter |
— |
| prometheus-node-exporter-1.5 |
affected |
chainguard |
prometheus-node-exporter-1.5 |
— |
| prometheus-node-exporter-fips |
affected |
chainguard |
prometheus-node-exporter-fips |
— |
| prometheus-operator |
affected |
wolfi |
prometheus-operator |
— |
| prometheus-operator |
affected |
chainguard |
prometheus-operator |
— |
| prometheus-postgres-exporter |
affected |
chainguard |
prometheus-postgres-exporter |
— |
| prometheus-postgres-exporter-0.10 |
affected |
chainguard |
prometheus-postgres-exporter-0.10 |
— |
| prometheus-postgres-exporter-fips |
affected |
chainguard |
prometheus-postgres-exporter-fips |
— |
| prometheus-pushgateway |
affected |
wolfi |
prometheus-pushgateway |
— |
| prometheus-pushgateway |
affected |
chainguard |
prometheus-pushgateway |
— |
| prometheus-pushgateway-fips |
affected |
chainguard |
prometheus-pushgateway-fips |
— |
| prometheus-pushgateway-fips-1.4 |
affected |
chainguard |
prometheus-pushgateway-fips-1.4 |
— |
| prometheus-stackdriver-exporter |
affected |
chainguard |
prometheus-stackdriver-exporter |
— |
| prometheus-statsd-exporter |
affected |
chainguard |
prometheus-statsd-exporter |
— |
| prometheus-statsd-exporter-fips |
affected |
chainguard |
prometheus-statsd-exporter-fips |
— |
| pulumi |
affected |
wolfi |
pulumi |
— |
| pulumi |
affected |
chainguard |
pulumi |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| pulumi-language-dotnet |
affected |
wolfi |
pulumi-language-dotnet |
— |
| pulumi-language-dotnet |
affected |
chainguard |
pulumi-language-dotnet |
— |
| pulumi-language-java |
affected |
chainguard |
pulumi-language-java |
— |
| pulumi-language-java |
affected |
wolfi |
pulumi-language-java |
— |
| pulumi-language-yaml |
affected |
chainguard |
pulumi-language-yaml |
— |
| pulumi-language-yaml |
affected |
wolfi |
pulumi-language-yaml |
— |
| rqlite |
affected |
wolfi |
rqlite |
— |
| rqlite |
affected |
chainguard |
rqlite |
— |
| runc |
affected |
chainguard |
runc |
— |
| runc |
affected |
wolfi |
runc |
— |
| secrets-store-csi-driver |
affected |
chainguard |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver |
affected |
wolfi |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver-provider-gcp |
affected |
wolfi |
secrets-store-csi-driver-provider-gcp |
— |
| secrets-store-csi-driver-provider-gcp |
affected |
chainguard |
secrets-store-csi-driver-provider-gcp |
— |
| sigstore-scaffolding |
affected |
chainguard |
sigstore-scaffolding |
— |
| sigstore-scaffolding |
affected |
wolfi |
sigstore-scaffolding |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| smarter-device-manager-fips |
affected |
chainguard |
smarter-device-manager-fips |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
| src |
affected |
chainguard |
src |
— |
| src |
affected |
wolfi |
src |
— |
| stakater-reloader |
affected |
chainguard |
stakater-reloader |
— |
| stakater-reloader |
affected |
wolfi |
stakater-reloader |
— |
| stakater-reloader-0.0.119 |
affected |
chainguard |
stakater-reloader-0.0.119 |
— |
| stakater-reloader-0.0.128 |
affected |
chainguard |
stakater-reloader-0.0.128 |
— |
| stdlib |
affected |
Go |
stdlib |
— |
| tekton-chains |
affected |
wolfi |
tekton-chains |
— |
| tekton-chains |
affected |
chainguard |
tekton-chains |
— |
| terraform |
affected |
wolfi |
terraform |
— |
| terraform |
affected |
chainguard |
terraform |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| thanos-operator |
affected |
wolfi |
thanos-operator |
— |
| thanos-operator |
affected |
chainguard |
thanos-operator |
— |
| timoni |
affected |
chainguard |
timoni |
— |
| timoni |
affected |
wolfi |
timoni |
— |
| tkn |
affected |
wolfi |
tkn |
— |
| tkn |
affected |
chainguard |
tkn |
— |
| trillian |
affected |
wolfi |
trillian |
— |
| trillian |
affected |
chainguard |
trillian |
— |
| trust-manager |
affected |
wolfi |
trust-manager |
— |
| trust-manager |
affected |
chainguard |
trust-manager |
— |
| up |
affected |
chainguard |
up |
— |
| up |
affected |
wolfi |
up |
— |
| vault-csi-provider |
affected |
chainguard |
vault-csi-provider |
— |
| vault-k8s |
affected |
wolfi |
vault-k8s |
— |
| vault-k8s |
affected |
chainguard |
vault-k8s |
— |
| vault-k8s-fips |
affected |
chainguard |
vault-k8s-fips |
— |
| vertical-pod-autoscaler |
affected |
wolfi |
vertical-pod-autoscaler |
— |
| vertical-pod-autoscaler |
affected |
chainguard |
vertical-pod-autoscaler |
— |
| volume-modifier-for-k8s-fips |
affected |
chainguard |
volume-modifier-for-k8s-fips |
— |
| wavefront-collector-for-kubernetes-1.12 |
affected |
chainguard |
wavefront-collector-for-kubernetes-1.12 |
— |
| wavefront-collector-for-kubernetes-1.13 |
affected |
chainguard |
wavefront-collector-for-kubernetes-1.13 |
— |
| weaviate |
affected |
wolfi |
weaviate |
— |
| weaviate |
affected |
chainguard |
weaviate |
— |
| wireguard-go |
affected |
wolfi |
wireguard-go |
— |
| wireguard-go |
affected |
chainguard |
wireguard-go |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
| yq |
affected |
wolfi |
yq |
— |
| yq |
affected |
chainguard |
yq |
— |
| zot |
affected |
chainguard |
zot |
— |
| zot |
affected |
wolfi |
zot |
— |
GoogleExploitedCISA KEV listedHIGH2023-10-10
io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset Attack
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| io.netty:netty-codec-http2 |
affected |
Maven |
io.netty:netty-codec-http2 |
— |
Open SourceExploitedCISA KEV listedHIGH2023-10-10
io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset Attack
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cloudwatch-exporter |
affected |
wolfi |
cloudwatch-exporter |
— |
| cloudwatch-exporter |
affected |
chainguard |
cloudwatch-exporter |
— |
| docker-selenium-jre-bcfips |
affected |
chainguard |
docker-selenium-jre-bcfips |
— |
| elasticsearch-8 |
affected |
chainguard |
elasticsearch-8 |
— |
| grpc-java-fips-1.56.0 |
affected |
chainguard |
grpc-java-fips-1.56.0 |
— |
| io.netty:netty-codec-http2 |
affected |
Maven |
io.netty:netty-codec-http2 |
— |
| spark-3.5.0-compat |
affected |
chainguard |
spark-3.5.0-compat |
— |
| stargate |
affected |
chainguard |
stargate |
— |
| trino |
affected |
wolfi |
trino |
— |
| trino |
affected |
chainguard |
trino |
— |
| wavefront-proxy |
affected |
wolfi |
wavefront-proxy |
— |
| wavefront-proxy |
affected |
chainguard |
wavefront-proxy |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
HTTP/2 Stream Cancellation Attack
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apple/swift-nio-http2 |
affected |
github.com |
github.com/apple/swift-nio-http2 |
— |
| com.typesafe.akka:akka-http-core |
affected |
Maven |
com.typesafe.akka:akka-http-core |
— |
| com.typesafe.akka:akka-http-core_2.11 |
affected |
Maven |
com.typesafe.akka:akka-http-core_2.11 |
— |
| com.typesafe.akka:akka-http-core_2.12 |
affected |
Maven |
com.typesafe.akka:akka-http-core_2.12 |
— |
| com.typesafe.akka:akka-http-core_2.13 |
affected |
Maven |
com.typesafe.akka:akka-http-core_2.13 |
— |
| org.apache.tomcat.embed:tomcat-embed-core |
affected |
Maven |
org.apache.tomcat.embed:tomcat-embed-core |
— |
| org.apache.tomcat:tomcat-coyote |
affected |
Maven |
org.apache.tomcat:tomcat-coyote |
— |
| org.eclipse.jetty.http2:http2-common |
affected |
Maven |
org.eclipse.jetty.http2:http2-common |
— |
| org.eclipse.jetty.http2:http2-server |
affected |
Maven |
org.eclipse.jetty.http2:http2-server |
— |
| org.eclipse.jetty.http2:jetty-http2-common |
affected |
Maven |
org.eclipse.jetty.http2:jetty-http2-common |
— |
| org.eclipse.jetty.http2:jetty-http2-server |
affected |
Maven |
org.eclipse.jetty.http2:jetty-http2-server |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
HTTP/2 Stream Cancellation Attack
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aactl |
affected |
wolfi |
aactl |
— |
| aactl |
affected |
chainguard |
aactl |
— |
| amass |
affected |
chainguard |
amass |
— |
| amass |
affected |
wolfi |
amass |
— |
| apple/swift-nio-http2 |
affected |
github.com |
github.com/apple/swift-nio-http2 |
— |
| argo-cd-2.7 |
affected |
chainguard |
argo-cd-2.7 |
— |
| argo-cd-2.7 |
affected |
wolfi |
argo-cd-2.7 |
— |
| atlantis |
affected |
chainguard |
atlantis |
— |
| atlantis |
affected |
wolfi |
atlantis |
— |
| atlantis-fips |
affected |
chainguard |
atlantis-fips |
— |
| aws-efs-csi-driver |
affected |
chainguard |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver |
affected |
wolfi |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver-fips |
affected |
chainguard |
aws-efs-csi-driver-fips |
— |
| aws-efs-csi-driver-fips-1.6 |
affected |
chainguard |
aws-efs-csi-driver-fips-1.6 |
— |
| aws-load-balancer-controller-2.4.5 |
affected |
chainguard |
aws-load-balancer-controller-2.4.5 |
— |
| bank-vaults-fips |
affected |
chainguard |
bank-vaults-fips |
— |
| bom |
affected |
wolfi |
bom |
— |
| bom |
affected |
chainguard |
bom |
— |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| calico |
affected |
chainguard |
calico |
— |
| calico |
affected |
wolfi |
calico |
— |
| calico-fips |
affected |
chainguard |
calico-fips |
— |
| calico-fips-3.25 |
affected |
chainguard |
calico-fips-3.25 |
— |
| certificate-transparency |
affected |
wolfi |
certificate-transparency |
— |
| certificate-transparency |
affected |
chainguard |
certificate-transparency |
— |
| cert-manager-1.13 |
affected |
chainguard |
cert-manager-1.13 |
— |
| cert-manager-1.13 |
affected |
wolfi |
cert-manager-1.13 |
— |
| cilium-envoy |
affected |
wolfi |
cilium-envoy |
— |
| cilium-envoy |
affected |
chainguard |
cilium-envoy |
— |
| cluster-autoscaler-1.25 |
affected |
chainguard |
cluster-autoscaler-1.25 |
— |
| cluster-autoscaler-1.25 |
affected |
wolfi |
cluster-autoscaler-1.25 |
— |
| cluster-autoscaler-fips-1.25 |
affected |
chainguard |
cluster-autoscaler-fips-1.25 |
— |
| com.typesafe.akka:akka-http-core |
affected |
Maven |
com.typesafe.akka:akka-http-core |
— |
| com.typesafe.akka:akka-http-core_2.11 |
affected |
Maven |
com.typesafe.akka:akka-http-core_2.11 |
— |
| com.typesafe.akka:akka-http-core_2.12 |
affected |
Maven |
com.typesafe.akka:akka-http-core_2.12 |
— |
| com.typesafe.akka:akka-http-core_2.13 |
affected |
Maven |
com.typesafe.akka:akka-http-core_2.13 |
— |
| configmap-reload-fips |
affected |
chainguard |
configmap-reload-fips |
— |
| configmap-reload-fips-0.11 |
affected |
chainguard |
configmap-reload-fips-0.11 |
— |
| conftest |
affected |
wolfi |
conftest |
— |
| conftest |
affected |
chainguard |
conftest |
— |
| coredns |
affected |
chainguard |
coredns |
— |
| coredns |
affected |
wolfi |
coredns |
— |
| cortex |
affected |
wolfi |
cortex |
— |
| cortex |
affected |
chainguard |
cortex |
— |
| cosign |
affected |
wolfi |
cosign |
— |
| cosign |
affected |
chainguard |
cosign |
— |
| cue |
affected |
wolfi |
cue |
— |
| cue |
affected |
chainguard |
cue |
— |
| dex |
affected |
wolfi |
dex |
— |
| dex |
affected |
chainguard |
dex |
— |
| dgraph |
affected |
wolfi |
dgraph |
— |
| dgraph |
affected |
chainguard |
dgraph |
— |
| dotnet-6 |
affected |
chainguard |
dotnet-6 |
— |
| dotnet-6 |
affected |
wolfi |
dotnet-6 |
— |
| dotnet-7 |
affected |
chainguard |
dotnet-7 |
— |
| dotnet-7 |
affected |
wolfi |
dotnet-7 |
— |
| dynamic-localpv-provisioner |
affected |
chainguard |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner |
affected |
wolfi |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| envoy-ratelimit |
affected |
wolfi |
envoy-ratelimit |
— |
| envoy-ratelimit |
affected |
chainguard |
envoy-ratelimit |
— |
| external-dns |
affected |
wolfi |
external-dns |
— |
| external-dns |
affected |
chainguard |
external-dns |
— |
| external-dns-fips |
affected |
chainguard |
external-dns-fips |
— |
| external-secrets-0.7 |
affected |
chainguard |
external-secrets-0.7 |
— |
| falco |
affected |
wolfi |
falco |
— |
| falco |
affected |
chainguard |
falco |
— |
| falcoctl-fips |
affected |
chainguard |
falcoctl-fips |
— |
| falcoctl-fips-0.4 |
affected |
chainguard |
falcoctl-fips-0.4 |
— |
| flux-0 |
affected |
chainguard |
flux-0 |
— |
| flux-0.37 |
affected |
chainguard |
flux-0.37 |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-helm-controller-0 |
affected |
chainguard |
flux-helm-controller-0 |
— |
| flux-helm-controller-0.37 |
affected |
chainguard |
flux-helm-controller-0.37 |
— |
| flux-image-reflector-controller-0 |
affected |
chainguard |
flux-image-reflector-controller-0 |
— |
| flux-kustomize-controller |
affected |
chainguard |
flux-kustomize-controller |
— |
| flux-kustomize-controller |
affected |
wolfi |
flux-kustomize-controller |
— |
| flux-kustomize-controller-0 |
affected |
chainguard |
flux-kustomize-controller-0 |
— |
| flux-kustomize-controller-0.37 |
affected |
chainguard |
flux-kustomize-controller-0.37 |
— |
| flux-notification-controller |
affected |
wolfi |
flux-notification-controller |
— |
| flux-notification-controller |
affected |
chainguard |
flux-notification-controller |
— |
| flux-notification-controller-0 |
affected |
chainguard |
flux-notification-controller-0 |
— |
| flux-notification-controller-0.37 |
affected |
chainguard |
flux-notification-controller-0.37 |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| flux-source-controller-0 |
affected |
chainguard |
flux-source-controller-0 |
— |
| flux-source-controller-0.37 |
affected |
chainguard |
flux-source-controller-0.37 |
— |
| frp |
affected |
chainguard |
frp |
— |
| frp |
affected |
wolfi |
frp |
— |
| fuse-overlayfs-snapshotter |
affected |
wolfi |
fuse-overlayfs-snapshotter |
— |
| fuse-overlayfs-snapshotter |
affected |
chainguard |
fuse-overlayfs-snapshotter |
— |
| gatekeeper-3.12 |
affected |
wolfi |
gatekeeper-3.12 |
— |
| gatekeeper-3.12 |
affected |
chainguard |
gatekeeper-3.12 |
— |
| gatekeeper-3.14 |
affected |
chainguard |
gatekeeper-3.14 |
— |
| gatekeeper-3.14 |
affected |
wolfi |
gatekeeper-3.14 |
— |
| gatekeeper-fips-3.14 |
affected |
chainguard |
gatekeeper-fips-3.14 |
— |
| gitlab-pages |
affected |
wolfi |
gitlab-pages |
— |
| gitlab-pages |
affected |
chainguard |
gitlab-pages |
— |
| gitlab-runner |
affected |
wolfi |
gitlab-runner |
— |
| gitlab-runner |
affected |
chainguard |
gitlab-runner |
— |
| git-lfs |
affected |
wolfi |
git-lfs |
— |
| git-lfs |
affected |
chainguard |
git-lfs |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gke-gcloud-auth-plugin |
affected |
chainguard |
gke-gcloud-auth-plugin |
— |
| gke-gcloud-auth-plugin |
affected |
wolfi |
gke-gcloud-auth-plugin |
— |
| gobuster |
affected |
chainguard |
gobuster |
— |
| gobuster |
affected |
wolfi |
gobuster |
— |
| gomplate |
affected |
chainguard |
gomplate |
— |
| gomplate |
affected |
wolfi |
gomplate |
— |
| goreleaser-1.18 |
affected |
wolfi |
goreleaser-1.18 |
— |
| goreleaser-1.18 |
affected |
chainguard |
goreleaser-1.18 |
— |
| grafana-7 |
affected |
chainguard |
grafana-7 |
— |
| grafana-9.3 |
affected |
chainguard |
grafana-9.3 |
— |
| grpcurl |
affected |
wolfi |
grpcurl |
— |
| grpcurl |
affected |
chainguard |
grpcurl |
— |
| grype |
affected |
chainguard |
grype |
— |
| grype |
affected |
wolfi |
grype |
— |
| haproxy-ingress |
affected |
wolfi |
haproxy-ingress |
— |
| haproxy-ingress |
affected |
chainguard |
haproxy-ingress |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm-3 |
affected |
chainguard |
helm-3 |
— |
| helm-3 |
affected |
wolfi |
helm-3 |
— |
| helm-4 |
affected |
wolfi |
helm-4 |
— |
| helm-4 |
affected |
chainguard |
helm-4 |
— |
| hey |
affected |
chainguard |
hey |
— |
| hey |
affected |
wolfi |
hey |
— |
| hugo |
affected |
chainguard |
hugo |
— |
| hugo |
affected |
wolfi |
hugo |
— |
| influxd |
affected |
chainguard |
influxd |
— |
| influxd |
affected |
wolfi |
influxd |
— |
| ingress-nginx-controller |
affected |
chainguard |
ingress-nginx-controller |
— |
| ingress-nginx-controller |
affected |
wolfi |
ingress-nginx-controller |
— |
| ingress-nginx-controller-fips |
affected |
chainguard |
ingress-nginx-controller-fips |
— |
| ipfs |
affected |
chainguard |
ipfs |
— |
| ipfs |
affected |
wolfi |
ipfs |
— |
| ip-masq-agent |
affected |
wolfi |
ip-masq-agent |
— |
| ip-masq-agent |
affected |
chainguard |
ip-masq-agent |
— |
| istio-envoy-1.18 |
affected |
wolfi |
istio-envoy-1.18 |
— |
| istio-envoy-1.18 |
affected |
chainguard |
istio-envoy-1.18 |
— |
| istio-envoy-1.19 |
affected |
wolfi |
istio-envoy-1.19 |
— |
| istio-envoy-1.19 |
affected |
chainguard |
istio-envoy-1.19 |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| kaf |
affected |
chainguard |
kaf |
— |
| kaf |
affected |
wolfi |
kaf |
— |
| karpenter-0.23 |
affected |
chainguard |
karpenter-0.23 |
— |
| keda |
affected |
chainguard |
keda |
— |
| keda |
affected |
wolfi |
keda |
— |
| keda-2.10 |
affected |
chainguard |
keda-2.10 |
— |
| keda-2.10 |
affected |
wolfi |
keda-2.10 |
— |
| keda-2.11 |
affected |
chainguard |
keda-2.11 |
— |
| keda-2.11 |
affected |
wolfi |
keda-2.11 |
— |
| kiam |
affected |
chainguard |
kiam |
— |
| kind |
affected |
chainguard |
kind |
— |
| kind |
affected |
wolfi |
kind |
— |
| ko |
affected |
wolfi |
ko |
— |
| ko |
affected |
chainguard |
ko |
— |
| kots |
affected |
wolfi |
kots |
— |
| kots |
affected |
chainguard |
kots |
— |
| kpt |
affected |
chainguard |
kpt |
— |
| kpt |
affected |
wolfi |
kpt |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kube-oidc-proxy |
affected |
chainguard |
kube-oidc-proxy |
— |
| kubernetes-csi-external-attacher-4.3 |
affected |
chainguard |
kubernetes-csi-external-attacher-4.3 |
— |
| kubernetes-csi-external-attacher-4.3 |
affected |
wolfi |
kubernetes-csi-external-attacher-4.3 |
— |
| kubernetes-csi-external-attacher-fips-4.3 |
affected |
chainguard |
kubernetes-csi-external-attacher-fips-4.3 |
— |
| kubernetes-csi-external-resizer-fips-1.8 |
affected |
chainguard |
kubernetes-csi-external-resizer-fips-1.8 |
— |
| kubernetes-csi-external-snapshotter-6.0 |
affected |
chainguard |
kubernetes-csi-external-snapshotter-6.0 |
— |
| kubernetes-csi-livenessprobe |
affected |
wolfi |
kubernetes-csi-livenessprobe |
— |
| kubernetes-csi-livenessprobe |
affected |
chainguard |
kubernetes-csi-livenessprobe |
— |
| kubernetes-csi-livenessprobe-2.10 |
affected |
chainguard |
kubernetes-csi-livenessprobe-2.10 |
— |
| kubernetes-csi-livenessprobe-fips |
affected |
chainguard |
kubernetes-csi-livenessprobe-fips |
— |
| kubernetes-csi-livenessprobe-fips-2.10 |
affected |
chainguard |
kubernetes-csi-livenessprobe-fips-2.10 |
— |
| kubernetes-csi-node-driver-registrar-2.9 |
affected |
wolfi |
kubernetes-csi-node-driver-registrar-2.9 |
— |
| kubernetes-csi-node-driver-registrar-2.9 |
affected |
chainguard |
kubernetes-csi-node-driver-registrar-2.9 |
— |
| kubernetes-csi-node-driver-registrar-fips-2.8 |
affected |
chainguard |
kubernetes-csi-node-driver-registrar-fips-2.8 |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kube-state-metrics-2.6 |
affected |
chainguard |
kube-state-metrics-2.6 |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubewatch |
affected |
wolfi |
kubewatch |
— |
| kubewatch |
affected |
chainguard |
kubewatch |
— |
| kyverno |
affected |
chainguard |
kyverno |
— |
| kyverno |
affected |
wolfi |
kyverno |
— |
| kyverno-policy-reporter-2.11 |
affected |
chainguard |
kyverno-policy-reporter-2.11 |
— |
| kyverno-policy-reporter-kyverno-plugin-1.5 |
affected |
chainguard |
kyverno-policy-reporter-kyverno-plugin-1.5 |
— |
| kyverno-policy-reporter-ui-1.7 |
affected |
chainguard |
kyverno-policy-reporter-ui-1.7 |
— |
| mc |
affected |
wolfi |
mc |
— |
| mc |
affected |
chainguard |
mc |
— |
| memcached-exporter |
affected |
chainguard |
memcached-exporter |
— |
| memcached-exporter |
affected |
wolfi |
memcached-exporter |
— |
| metacontroller |
affected |
wolfi |
metacontroller |
— |
| metacontroller |
affected |
chainguard |
metacontroller |
— |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| metrics-server-fips |
affected |
chainguard |
metrics-server-fips |
— |
| minio |
affected |
chainguard |
minio |
— |
| minio |
affected |
wolfi |
minio |
— |
| nats |
affected |
chainguard |
nats |
— |
| nats |
affected |
wolfi |
nats |
— |
| neuvector-agent |
affected |
chainguard |
neuvector-agent |
— |
| neuvector-agent |
affected |
wolfi |
neuvector-agent |
— |
| newrelic-infrastructure-agent |
affected |
chainguard |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent |
affected |
wolfi |
newrelic-infrastructure-agent |
— |
| nfs-subdir-external-provisioner-fips |
affected |
chainguard |
nfs-subdir-external-provisioner-fips |
— |
| nghttp2 |
affected |
wolfi |
nghttp2 |
— |
| nghttp2 |
affected |
chainguard |
nghttp2 |
— |
| nginx-mainline |
affected |
chainguard |
nginx-mainline |
— |
| nginx-mainline |
affected |
wolfi |
nginx-mainline |
— |
| nginx-stable |
affected |
chainguard |
nginx-stable |
— |
| nginx-stable |
affected |
wolfi |
nginx-stable |
— |
| nodejs-16 |
affected |
wolfi |
nodejs-16 |
— |
| nodejs-16 |
affected |
chainguard |
nodejs-16 |
— |
| nodejs-18 |
affected |
wolfi |
nodejs-18 |
— |
| nodejs-18 |
affected |
chainguard |
nodejs-18 |
— |
| nodejs-19 |
affected |
wolfi |
nodejs-19 |
— |
| nodejs-19 |
affected |
chainguard |
nodejs-19 |
— |
| nodejs-20 |
affected |
wolfi |
nodejs-20 |
— |
| nodejs-20 |
affected |
chainguard |
nodejs-20 |
— |
| node-problem-detector-0.8 |
affected |
wolfi |
node-problem-detector-0.8 |
— |
| node-problem-detector-0.8 |
affected |
chainguard |
node-problem-detector-0.8 |
— |
| nodetaint |
affected |
wolfi |
nodetaint |
— |
| nodetaint |
affected |
chainguard |
nodetaint |
— |
| nri-prometheus |
affected |
wolfi |
nri-prometheus |
— |
| nri-prometheus |
affected |
chainguard |
nri-prometheus |
— |
| oauth2-proxy |
affected |
chainguard |
oauth2-proxy |
— |
| oauth2-proxy |
affected |
wolfi |
oauth2-proxy |
— |
| ollama |
affected |
chainguard |
ollama |
— |
| ollama |
affected |
wolfi |
ollama |
— |
| opentofu |
affected |
chainguard |
opentofu |
— |
| opentofu |
affected |
wolfi |
opentofu |
— |
| org.apache.tomcat.embed:tomcat-embed-core |
affected |
Maven |
org.apache.tomcat.embed:tomcat-embed-core |
— |
| org.apache.tomcat:tomcat-coyote |
affected |
Maven |
org.apache.tomcat:tomcat-coyote |
— |
| org.eclipse.jetty.http2:http2-common |
affected |
Maven |
org.eclipse.jetty.http2:http2-common |
— |
| org.eclipse.jetty.http2:http2-server |
affected |
Maven |
org.eclipse.jetty.http2:http2-server |
— |
| org.eclipse.jetty.http2:jetty-http2-common |
affected |
Maven |
org.eclipse.jetty.http2:jetty-http2-common |
— |
| org.eclipse.jetty.http2:jetty-http2-server |
affected |
Maven |
org.eclipse.jetty.http2:jetty-http2-server |
— |
| prometheus |
affected |
chainguard |
prometheus |
— |
| prometheus |
affected |
wolfi |
prometheus |
— |
| prometheus-2.38 |
affected |
chainguard |
prometheus-2.38 |
— |
| prometheus-adapter |
affected |
wolfi |
prometheus-adapter |
— |
| prometheus-adapter |
affected |
chainguard |
prometheus-adapter |
— |
| prometheus-adapter-0.10 |
affected |
chainguard |
prometheus-adapter-0.10 |
— |
| prometheus-adapter-fips-0.10 |
affected |
chainguard |
prometheus-adapter-fips-0.10 |
— |
| prometheus-bind-exporter |
affected |
wolfi |
prometheus-bind-exporter |
— |
| prometheus-bind-exporter |
affected |
chainguard |
prometheus-bind-exporter |
— |
| prometheus-blackbox-exporter |
affected |
wolfi |
prometheus-blackbox-exporter |
— |
| prometheus-blackbox-exporter |
affected |
chainguard |
prometheus-blackbox-exporter |
— |
| prometheus-elasticsearch-exporter |
affected |
wolfi |
prometheus-elasticsearch-exporter |
— |
| prometheus-elasticsearch-exporter |
affected |
chainguard |
prometheus-elasticsearch-exporter |
— |
| prometheus-postgres-exporter-0.10 |
affected |
chainguard |
prometheus-postgres-exporter-0.10 |
— |
| prometheus-redis-exporter-fips-1.44 |
affected |
chainguard |
prometheus-redis-exporter-fips-1.44 |
— |
| prometheus-stackdriver-exporter |
affected |
chainguard |
prometheus-stackdriver-exporter |
— |
| prometheus-stackdriver-exporter |
affected |
wolfi |
prometheus-stackdriver-exporter |
— |
| pulumi |
affected |
chainguard |
pulumi |
— |
| pulumi |
affected |
wolfi |
pulumi |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| pulumi-language-dotnet |
affected |
wolfi |
pulumi-language-dotnet |
— |
| pulumi-language-dotnet |
affected |
chainguard |
pulumi-language-dotnet |
— |
| pulumi-language-java |
affected |
wolfi |
pulumi-language-java |
— |
| pulumi-language-java |
affected |
chainguard |
pulumi-language-java |
— |
| pulumi-language-yaml |
affected |
chainguard |
pulumi-language-yaml |
— |
| pulumi-language-yaml |
affected |
wolfi |
pulumi-language-yaml |
— |
| rqlite |
affected |
wolfi |
rqlite |
— |
| rqlite |
affected |
chainguard |
rqlite |
— |
| scorecard |
affected |
wolfi |
scorecard |
— |
| scorecard |
affected |
chainguard |
scorecard |
— |
| secrets-store-csi-driver |
affected |
chainguard |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver |
affected |
wolfi |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver-provider-gcp |
affected |
chainguard |
secrets-store-csi-driver-provider-gcp |
— |
| secrets-store-csi-driver-provider-gcp |
affected |
wolfi |
secrets-store-csi-driver-provider-gcp |
— |
| sigstore-scaffolding |
affected |
chainguard |
sigstore-scaffolding |
— |
| sigstore-scaffolding |
affected |
wolfi |
sigstore-scaffolding |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| smarter-device-manager-fips |
affected |
chainguard |
smarter-device-manager-fips |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
| src |
affected |
wolfi |
src |
— |
| src |
affected |
chainguard |
src |
— |
| stakater-reloader |
affected |
wolfi |
stakater-reloader |
— |
| stakater-reloader |
affected |
chainguard |
stakater-reloader |
— |
| stakater-reloader-0.0.119 |
affected |
chainguard |
stakater-reloader-0.0.119 |
— |
| stakater-reloader-0.0.128 |
affected |
chainguard |
stakater-reloader-0.0.128 |
— |
| tctl |
affected |
chainguard |
tctl |
— |
| tctl |
affected |
wolfi |
tctl |
— |
| telegraf-1.26 |
affected |
chainguard |
telegraf-1.26 |
— |
| telegraf-1.26 |
affected |
wolfi |
telegraf-1.26 |
— |
| telegraf-1.27 |
affected |
wolfi |
telegraf-1.27 |
— |
| telegraf-1.27 |
affected |
chainguard |
telegraf-1.27 |
— |
| terraform |
affected |
wolfi |
terraform |
— |
| terraform |
affected |
chainguard |
terraform |
— |
| terraform-provider-aws |
affected |
wolfi |
terraform-provider-aws |
— |
| terraform-provider-aws |
affected |
chainguard |
terraform-provider-aws |
— |
| terraform-provider-azurerm |
affected |
chainguard |
terraform-provider-azurerm |
— |
| terraform-provider-azurerm |
affected |
wolfi |
terraform-provider-azurerm |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| thanos-0.31 |
affected |
chainguard |
thanos-0.31 |
— |
| thanos-0.31 |
affected |
wolfi |
thanos-0.31 |
— |
| thanos-0.32 |
affected |
chainguard |
thanos-0.32 |
— |
| thanos-0.32 |
affected |
wolfi |
thanos-0.32 |
— |
| timestamp-authority-fips |
affected |
chainguard |
timestamp-authority-fips |
— |
| tomcat-10 |
affected |
wolfi |
tomcat-10 |
— |
| tomcat-10 |
affected |
chainguard |
tomcat-10 |
— |
| tomcat-8 |
affected |
chainguard |
tomcat-8 |
— |
| tomcat-8 |
affected |
wolfi |
tomcat-8 |
— |
| tomcat-9 |
affected |
chainguard |
tomcat-9 |
— |
| tomcat-9 |
affected |
wolfi |
tomcat-9 |
— |
| traefik |
affected |
wolfi |
traefik |
— |
| traefik |
affected |
chainguard |
traefik |
— |
| up |
affected |
chainguard |
up |
— |
| up |
affected |
wolfi |
up |
— |
| vault-csi-provider |
affected |
chainguard |
vault-csi-provider |
— |
| vault-csi-provider |
affected |
wolfi |
vault-csi-provider |
— |
| vault-k8s-fips |
affected |
chainguard |
vault-k8s-fips |
— |
| volume-modifier-for-k8s-fips |
affected |
chainguard |
volume-modifier-for-k8s-fips |
— |
| weaviate |
affected |
wolfi |
weaviate |
— |
| weaviate |
affected |
chainguard |
weaviate |
— |
| wireguard-go |
affected |
wolfi |
wireguard-go |
— |
| wireguard-go |
affected |
chainguard |
wireguard-go |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
CVE-2023-44487 affecting package application-gateway-kubernetes-ingress for versions less than 1.4.0-15
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| application-gateway-kubernetes-ingress |
affected |
Azure Linux:2 |
application-gateway-kubernetes-ingress |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
CVE-2023-44487 affecting package golang for versions less than 1.20.10
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
CVE-2023-44487 affecting package grpc for versions less than 1.42.0-7
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Azure Linux:2 |
grpc |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
CVE-2023-44487 affecting package kubernetes for versions less than 1.28.3-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Azure Linux:2 |
kubernetes |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
CVE-2023-44487 affecting package application-gateway-kubernetes-ingress for versions less than 1.4.0-15
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| application-gateway-kubernetes-ingress |
affected |
Azure Linux:3 |
application-gateway-kubernetes-ingress |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
CVE-2023-44487 affecting package grpc for versions less than 1.42.0-7
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Azure Linux:3 |
grpc |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
CVE-2023-44487 affecting package kubernetes for versions less than 1.28.3-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Azure Linux:3 |
kubernetes |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
CVE-2023-44487 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
CVE-2023-44487 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
DEBIAN-CVE-2023-44487
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dnsdist |
affected |
Debian:11 |
dnsdist |
— |
| dnsdist |
affected |
Debian:12 |
dnsdist |
— |
| dnsdist |
affected |
Debian:13 |
dnsdist |
— |
| dnsdist |
affected |
Debian:14 |
dnsdist |
— |
| grpc |
affected |
Debian:11 |
grpc |
— |
| grpc |
affected |
Debian:12 |
grpc |
— |
| grpc |
affected |
Debian:13 |
grpc |
— |
| grpc |
affected |
Debian:14 |
grpc |
— |
| h2o |
affected |
Debian:11 |
h2o |
— |
| h2o |
affected |
Debian:12 |
h2o |
— |
| haproxy |
affected |
Debian:11 |
haproxy |
— |
| haproxy |
affected |
Debian:12 |
haproxy |
— |
| haproxy |
affected |
Debian:13 |
haproxy |
— |
| haproxy |
affected |
Debian:14 |
haproxy |
— |
| jetty9 |
affected |
Debian:11 |
jetty9 |
— |
| jetty9 |
affected |
Debian:12 |
jetty9 |
— |
| jetty9 |
affected |
Debian:13 |
jetty9 |
— |
| jetty9 |
affected |
Debian:14 |
jetty9 |
— |
| netty |
affected |
Debian:11 |
netty |
— |
| netty |
affected |
Debian:12 |
netty |
— |
| netty |
affected |
Debian:13 |
netty |
— |
| netty |
affected |
Debian:14 |
netty |
— |
| nghttp2 |
affected |
Debian:11 |
nghttp2 |
— |
| nghttp2 |
affected |
Debian:12 |
nghttp2 |
— |
| nghttp2 |
affected |
Debian:13 |
nghttp2 |
— |
| nghttp2 |
affected |
Debian:14 |
nghttp2 |
— |
| nginx |
affected |
Debian:12 |
nginx |
— |
| nginx |
affected |
Debian:13 |
nginx |
— |
| nginx |
affected |
Debian:14 |
nginx |
— |
| nginx |
affected |
Debian:11 |
nginx |
— |
| tomcat10 |
affected |
Debian:13 |
tomcat10 |
— |
| tomcat10 |
affected |
Debian:14 |
tomcat10 |
— |
| tomcat10 |
affected |
Debian:12 |
tomcat10 |
— |
| tomcat9 |
affected |
Debian:12 |
tomcat9 |
— |
| tomcat9 |
affected |
Debian:13 |
tomcat9 |
— |
| tomcat9 |
affected |
Debian:14 |
tomcat9 |
— |
| tomcat9 |
affected |
Debian:11 |
tomcat9 |
— |
| trafficserver |
affected |
Debian:12 |
trafficserver |
— |
| trafficserver |
affected |
Debian:11 |
trafficserver |
— |
| varnish |
affected |
Debian:11 |
varnish |
— |
| varnish |
affected |
Debian:12 |
varnish |
— |
| varnish |
affected |
Debian:13 |
varnish |
— |
| varnish |
affected |
Debian:14 |
varnish |
— |
Open SourceExploitedCISA KEV listedHIGH2023-10-10
BELL-CVE-2023-44487
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
BellSoft Hardened Containers:23 |
go |
— |
| go |
affected |
BellSoft Hardened Containers:stream |
go |
— |
| go |
affected |
Alpaquita:23 |
go |
— |
| go |
affected |
Alpaquita:stream |
go |
— |
| grpc |
affected |
Alpaquita:23 |
grpc |
— |
| grpc |
affected |
Alpaquita:stream |
grpc |
— |
| nghttp2 |
affected |
Alpaquita:stream |
nghttp2 |
— |
| nghttp2 |
affected |
Alpaquita:23 |
nghttp2 |
— |
| nghttp2 |
affected |
BellSoft Hardened Containers:23 |
nghttp2 |
— |
| nghttp2 |
affected |
BellSoft Hardened Containers:stream |
nghttp2 |
— |
| nginx |
affected |
Alpaquita:stream |
nginx |
— |
| nginx |
affected |
Alpaquita:23 |
nginx |
— |
Open SourceExploitedCISA KEV listedMEDIUM2023-10-10
HTTP/2 Stream Cancellation Attack
CVEs:CVE-2023-44487
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apple/swift-nio-http2 |
affected |
github.com |
github.com/apple/swift-nio-http2 |
— |
| com.typesafe.akka:akka-http-core |
affected |
Maven |
com.typesafe.akka:akka-http-core |
— |
| com.typesafe.akka:akka-http-core_2.11 |
affected |
Maven |
com.typesafe.akka:akka-http-core_2.11 |
— |
| com.typesafe.akka:akka-http-core_2.12 |
affected |
Maven |
com.typesafe.akka:akka-http-core_2.12 |
— |
| com.typesafe.akka:akka-http-core_2.13 |
affected |
Maven |
com.typesafe.akka:akka-http-core_2.13 |
— |
| org.apache.tomcat.embed:tomcat-embed-core |
affected |
Maven |
org.apache.tomcat.embed:tomcat-embed-core |
— |
| org.apache.tomcat:tomcat-coyote |
affected |
Maven |
org.apache.tomcat:tomcat-coyote |
— |
| org.eclipse.jetty.http2:http2-common |
affected |
Maven |
org.eclipse.jetty.http2:http2-common |
— |
| org.eclipse.jetty.http2:http2-server |
affected |
Maven |
org.eclipse.jetty.http2:http2-server |
— |
| org.eclipse.jetty.http2:jetty-http2-common |
affected |
Maven |
org.eclipse.jetty.http2:jetty-http2-common |
— |
| org.eclipse.jetty.http2:jetty-http2-server |
affected |
Maven |
org.eclipse.jetty.http2:jetty-http2-server |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-10-10
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVEs:CVE-2023-44487
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| 3scale_api_management_platform |
affected |
redhat |
— |
— |
| advanced_cluster_management_for_kubernetes |
affected |
redhat |
— |
— |
| advanced_cluster_security |
affected |
redhat |
— |
— |
| ansible_automation_platform |
affected |
redhat |
— |
— |
| apisix |
affected |
apache |
— |
— |
| armeria |
affected |
linecorp |
— |
— |
| asp.net_core |
affected |
microsoft |
— |
— |
| astra_control_center |
affected |
netapp |
— |
— |
| azure_kubernetes_service |
affected |
microsoft |
— |
— |
| big-ip_access_policy_manager |
affected |
f5 |
— |
— |
| big-ip_advanced_firewall_manager |
affected |
f5 |
— |
— |
| big-ip_advanced_web_application_firewall |
affected |
f5 |
— |
— |
| big-ip_analytics |
affected |
f5 |
— |
— |
| big-ip_application_acceleration_manager |
affected |
f5 |
— |
— |
| big-ip_application_security_manager |
affected |
f5 |
— |
— |
| big-ip_application_visibility_and_reporting |
affected |
f5 |
— |
— |
| big-ip_carrier-grade_nat |
affected |
f5 |
— |
— |
| big-ip_ddos_hybrid_defender |
affected |
f5 |
— |
— |
| big-ip_domain_name_system |
affected |
f5 |
— |
— |
| big-ip_fraud_protection_service |
affected |
f5 |
— |
— |
| big-ip_global_traffic_manager |
affected |
f5 |
— |
— |
| big-ip_link_controller |
affected |
f5 |
— |
— |
| big-ip_local_traffic_manager |
affected |
f5 |
— |
— |
| big-ip_next |
affected |
f5 |
— |
— |
| big-ip_next_service_proxy_for_kubernetes |
affected |
f5 |
— |
— |
| big-ip_policy_enforcement_manager |
affected |
f5 |
— |
— |
| big-ip_ssl_orchestrator |
affected |
f5 |
— |
— |
| big-ip_webaccelerator |
affected |
f5 |
— |
— |
| big-ip_websafe |
affected |
f5 |
— |
— |
| build_of_optaplanner |
affected |
redhat |
— |
— |
| build_of_quarkus |
affected |
redhat |
— |
— |
| business_process_automation |
affected |
cisco |
— |
— |
| caddy |
affected |
caddyserver |
— |
— |
| cbl-mariner |
affected |
microsoft |
— |
— |
| ceph_storage |
affected |
redhat |
— |
— |
| certification_for_red_hat_enterprise_linux |
affected |
redhat |
— |
— |
| cert-manager_operator_for_red_hat_openshift |
affected |
redhat |
— |
— |
| connected_mobile_experiences |
affected |
cisco |
— |
— |
| contour |
affected |
projectcontour |
— |
— |
| cost_management |
affected |
redhat |
— |
— |
| crosswork_data_gateway |
affected |
cisco |
— |
— |
| crosswork_situation_manager |
affected |
cisco |
— |
— |
| crosswork_zero_touch_provisioning |
affected |
cisco |
— |
— |
| cryostat |
affected |
redhat |
— |
— |
| data_center_network_manager |
affected |
cisco |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| decision_manager |
affected |
redhat |
— |
— |
| enterprise_chat_and_email |
affected |
cisco |
— |
— |
| enterprise_linux |
affected |
redhat |
— |
— |
| envoy |
affected |
envoyproxy |
— |
— |
| expressway |
affected |
cisco |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| fence_agents_remediation_operator |
affected |
redhat |
— |
— |
| firepower_threat_defense |
affected |
cisco |
— |
— |
| fog_director |
affected |
cisco |
— |
— |
| go |
affected |
golang |
— |
— |
| grpc |
affected |
grpc |
— |
— |
| h2o |
affected |
dena |
— |
— |
| http |
affected |
ietf |
— |
— |
| http2 |
affected |
kazu-yamamoto |
— |
— |
| http2 |
affected |
golang |
— |
— |
| http_server |
affected |
akka |
— |
— |
| integration_camel_for_spring_boot |
affected |
redhat |
— |
— |
| integration_camel_k |
affected |
redhat |
— |
— |
| integration_service_registry |
affected |
redhat |
— |
— |
| ios_xe |
affected |
cisco |
— |
— |
| ios_xr |
affected |
cisco |
— |
— |
| iot_field_network_director |
affected |
cisco |
— |
— |
| istio |
affected |
istio |
— |
— |
| jboss_a-mq |
affected |
redhat |
— |
— |
| jboss_a-mq_streams |
affected |
redhat |
— |
— |
| jboss_core_services |
affected |
redhat |
— |
— |
| jboss_data_grid |
affected |
redhat |
— |
— |
| jboss_enterprise_application_platform |
affected |
redhat |
— |
— |
| jboss_fuse |
affected |
redhat |
— |
— |
| jenkins |
affected |
jenkins |
— |
— |
| jetty |
affected |
eclipse |
— |
— |
| kong_gateway |
affected |
konghq |
— |
— |
| linkerd |
affected |
linkerd |
— |
— |
| logging_subsystem_for_red_hat_openshift |
affected |
redhat |
— |
— |
| machine_deletion_remediation_operator |
affected |
redhat |
— |
— |
| migration_toolkit_for_applications |
affected |
redhat |
— |
— |
| migration_toolkit_for_containers |
affected |
redhat |
— |
— |
| migration_toolkit_for_virtualization |
affected |
redhat |
— |
— |
| .net |
affected |
microsoft |
— |
— |
| netty |
affected |
netty |
— |
— |
| networking |
affected |
golang |
— |
— |
| network_observability_operator |
affected |
redhat |
— |
— |
| nghttp2 |
affected |
nghttp2 |
— |
— |
| nginx |
affected |
f5 |
— |
— |
| nginx_ingress_controller |
affected |
f5 |
— |
— |
| nginx_plus |
affected |
f5 |
— |
— |
| node_healthcheck_operator |
affected |
redhat |
— |
— |
| node.js |
affected |
nodejs |
— |
— |
| node_maintenance_operator |
affected |
redhat |
— |
— |
| nx-os |
affected |
cisco |
— |
— |
| oncommand_insight |
affected |
netapp |
— |
— |
| openresty |
affected |
openresty |
— |
— |
| opensearch_data_prepper |
affected |
amazon |
— |
— |
| openshift |
affected |
redhat |
— |
— |
| openshift_api_for_data_protection |
affected |
redhat |
— |
— |
| openshift_container_platform |
affected |
redhat |
— |
— |
| openshift_container_platform_assisted_installer |
affected |
redhat |
— |
— |
| openshift_data_science |
affected |
redhat |
— |
— |
| openshift_developer_tools_and_services |
affected |
redhat |
— |
— |
| openshift_dev_spaces |
affected |
redhat |
— |
— |
| openshift_distributed_tracing |
affected |
redhat |
— |
— |
| openshift_gitops |
affected |
redhat |
— |
— |
| openshift_pipelines |
affected |
redhat |
— |
— |
| openshift_sandboxed_containers |
affected |
redhat |
— |
— |
| openshift_secondary_scheduler_operator |
affected |
redhat |
— |
— |
| openshift_serverless |
affected |
redhat |
— |
— |
| openshift_service_mesh |
affected |
redhat |
— |
— |
| openshift_virtualization |
affected |
redhat |
— |
— |
| openstack_platform |
affected |
redhat |
— |
— |
| prime_access_registrar |
affected |
cisco |
— |
— |
| prime_cable_provisioning |
affected |
cisco |
— |
— |
| prime_infrastructure |
affected |
cisco |
— |
— |
| prime_network_registrar |
affected |
cisco |
— |
— |
| process_automation |
affected |
redhat |
— |
— |
| proxygen |
affected |
facebook |
— |
— |
| quay |
affected |
redhat |
— |
— |
| ruggedcom_ape1808_firmware |
affected |
siemens |
— |
— |
| run_once_duration_override_operator |
affected |
redhat |
— |
— |
| satellite |
affected |
redhat |
— |
— |
| secure_dynamic_attributes_connector |
affected |
cisco |
— |
— |
| secure_firewall_threat_defense |
affected |
cisco |
— |
— |
| secure_malware_analytics |
affected |
cisco |
— |
— |
| secure_web_appliance_firmware |
affected |
cisco |
— |
— |
| self_node_remediation_operator |
affected |
redhat |
— |
— |
| service_interconnect |
affected |
redhat |
— |
— |
| service_telemetry_framework |
affected |
redhat |
— |
— |
| simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware |
affected |
siemens |
— |
— |
| simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware |
affected |
siemens |
— |
— |
| sinec_ins |
affected |
siemens |
— |
— |
| sinec_nms |
affected |
siemens |
— |
— |
| single_sign-on |
affected |
redhat |
— |
— |
| siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware |
affected |
siemens |
— |
— |
| solr |
affected |
apache |
— |
— |
| st7_scadaconnect |
affected |
siemens |
— |
— |
| support_for_spring_boot |
affected |
redhat |
— |
— |
| swiftnio_http\/2 |
affected |
apple |
— |
— |
| telepresence_video_communication_server |
affected |
cisco |
— |
— |
| tomcat |
affected |
apache |
— |
— |
| traefik |
affected |
traefik |
— |
— |
| traffic_server |
affected |
apache |
— |
— |
| ultra_cloud_core_-_policy_control_function |
affected |
cisco |
— |
— |
| ultra_cloud_core_-_serving_gateway_function |
affected |
cisco |
— |
— |
| ultra_cloud_core_-_session_management_function |
affected |
cisco |
— |
— |
| unified_attendant_console_advanced |
affected |
cisco |
— |
— |
| unified_contact_center_domain_manager |
affected |
cisco |
— |
— |
| unified_contact_center_enterprise |
affected |
cisco |
— |
— |
| unified_contact_center_enterprise_-_live_data_server |
affected |
cisco |
— |
— |
| unified_contact_center_management_portal |
affected |
cisco |
— |
— |
| varnish_cache |
affected |
varnish_cache_project |
— |
— |
| visual_studio_2022 |
affected |
microsoft |
— |
— |
| web_terminal |
affected |
redhat |
— |
— |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_10_21h2 |
affected |
microsoft |
— |
— |
| windows_10_22h2 |
affected |
microsoft |
— |
— |
| windows_11_21h2 |
affected |
microsoft |
— |
— |
| windows_11_22h2 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
| windows_server_2022 |
affected |
microsoft |
— |
— |
GoogleExploitedCISA KEV listed2023-10-10
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVEs:CVE-2023-44487
Open SourceExploitedCISA KEV listedCRITICAL2023-10-03
Updated chromium-browser-stable package fixes bugs and vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:9 |
chromium-browser-stable |
— |
GoogleExploitedCISA KEV listedCRITICAL2023-10-04
CVEs:CVE-2023-22515
GoogleExploitedCISA KEV listedCRITICAL2023-10-04
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Conflu...
CVEs:CVE-2023-22515
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| confluence_data_center |
affected |
atlassian |
— |
— |
| confluence_server |
affected |
atlassian |
— |
— |
Project ZeroExploitedCISA KEV listed2023-10-04
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.
Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this
CVEs:CVE-2023-22515
GoogleExploitedCISA KEV listedMEDIUM2023-10-01
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
CVEs:CVE-2023-4211
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| 5th_gen_gpu_architecture_kernel_driver |
affected |
arm |
— |
— |
| bifrost_gpu_kernel_driver |
affected |
arm |
— |
— |
| midgard_gpu_kernel_driver |
affected |
arm |
— |
— |
| valhall_gpu_kernel_driver |
affected |
arm |
— |
— |
GoogleExploitedCISA KEV listedMEDIUM2023-10-01
CVEs:CVE-2023-4211
Project ZeroExploitedCISA KEV listed2023-10-01
Mali GPU Kernel Driver Allows Improper GPU Memory Processing Operations
CVEs:CVE-2023-4211
GoogleExploitedCISA KEV listed2023-10-01
ASB-A-294605494
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleExploitedCISA KEV listedHIGH2023-10-04
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of...
CVEs:CVE-2023-42824
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
GoogleExploitedCISA KEV listedHIGH2023-10-04
CVEs:CVE-2023-42824
Project ZeroExploitedCISA KEV listed2023-10-04
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6.
CVEs:CVE-2023-42824
Open SourceActive exploitation (sightings)HIGH2023-10-25
Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
k8s.io |
k8s.io/ingress-nginx |
— |
Open SourceActive exploitation (sightings)HIGH2023-10-25
Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
k8s.io |
k8s.io/ingress-nginx |
— |
| ingress-nginx-controller |
affected |
wolfi |
ingress-nginx-controller |
— |
| ingress-nginx-controller |
affected |
chainguard |
ingress-nginx-controller |
— |
| ingress-nginx-controller-1.13 |
affected |
chainguard |
ingress-nginx-controller-1.13 |
— |
| ingress-nginx-controller-1.14 |
affected |
wolfi |
ingress-nginx-controller-1.14 |
— |
| ingress-nginx-controller-1.14 |
affected |
chainguard |
ingress-nginx-controller-1.14 |
— |
| ingress-nginx-controller-1.15 |
affected |
wolfi |
ingress-nginx-controller-1.15 |
— |
| ingress-nginx-controller-1.15 |
affected |
chainguard |
ingress-nginx-controller-1.15 |
— |
| ingress-nginx-controller-1.9 |
affected |
chainguard |
ingress-nginx-controller-1.9 |
— |
| ingress-nginx-controller-fips |
affected |
chainguard |
ingress-nginx-controller-fips |
— |
| ingress-nginx-controller-fips-1.13 |
affected |
chainguard |
ingress-nginx-controller-fips-1.13 |
— |
| ingress-nginx-controller-fips-1.14 |
affected |
chainguard |
ingress-nginx-controller-fips-1.14 |
— |
| ingress-nginx-controller-fips-1.15 |
affected |
chainguard |
ingress-nginx-controller-fips-1.15 |
— |
| ingress-nginx-controller-fips-1.9 |
affected |
chainguard |
ingress-nginx-controller-fips-1.9 |
— |
GoogleActive exploitation (sightings)HIGH2023-10-25
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
CVEs:CVE-2023-5044
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
kubernetes |
— |
— |
GoogleActive exploitation (sightings)2023-10-25
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
CVEs:CVE-2023-5044
Open SourceActive exploitation (sightings)HIGH2023-10-25
Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
CVEs:CVE-2023-5044
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
k8s.io |
k8s.io/ingress-nginx |
— |
GoogleActive exploitation (sightings)HIGH2023-10-31
Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5482
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-31
CVEs:CVE-2023-5482
GoogleActive exploitation (sightings)2023-10-31
Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5482
Open SourceActive exploitation (sightings)HIGH2023-10-25
Ingress nginx annotation injection causes arbitrary command execution
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
k8s.io |
k8s.io/ingress-nginx |
— |
Open SourceActive exploitation (sightings)HIGH2023-10-25
Ingress nginx annotation injection causes arbitrary command execution
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
k8s.io |
k8s.io/ingress-nginx |
— |
| ingress-nginx-controller |
affected |
chainguard |
ingress-nginx-controller |
— |
| ingress-nginx-controller |
affected |
wolfi |
ingress-nginx-controller |
— |
| ingress-nginx-controller-1.9 |
affected |
chainguard |
ingress-nginx-controller-1.9 |
— |
| ingress-nginx-controller-fips |
affected |
chainguard |
ingress-nginx-controller-fips |
— |
| ingress-nginx-controller-fips-1.9 |
affected |
chainguard |
ingress-nginx-controller-fips-1.9 |
— |
GoogleActive exploitation (sightings)2023-10-25
Ingress nginx annotation injection causes arbitrary command execution.
CVEs:CVE-2023-5043
Open SourceActive exploitation (sightings)HIGH2023-10-25
Ingress nginx annotation injection causes arbitrary command execution
CVEs:CVE-2023-5043
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
k8s.io |
k8s.io/ingress-nginx |
— |
GoogleActive exploitation (sightings)CRITICAL2023-10-25
Ingress nginx annotation injection causes arbitrary command execution.
CVEs:CVE-2023-5043
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
kubernetes |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-10-05
DEBIAN-CVE-2023-5346
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)2023-10-05
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourceActive exploitation (sightings)2023-10-04
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2023-10-03
CVEs:CVE-2023-5346
GoogleActive exploitation (sightings)HIGH2023-10-03
Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5346
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)2023-10-03
Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5346
Open SourceActive exploitation (sightings)CRITICAL2023-10-19
Updated chromium-browser-stable packages fix bugs and vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:9 |
chromium-browser-stable |
— |
Open SourceActive exploitation (sightings)CRITICAL2023-10-13
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
Open SourceActive exploitation (sightings)2023-10-12
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2023-10-11
DEBIAN-CVE-2023-5218
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2023-10-10
Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVEs:CVE-2023-5218
GoogleActive exploitation (sightings)HIGH2023-10-10
CVEs:CVE-2023-5218
GoogleActive exploitation (sightings)CRITICAL2023-10-10
Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVEs:CVE-2023-5218
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)CRITICAL2023-10-31
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially execute arbitrary code via a malicious file. (Chromium security severity: Medium)
CVEs:CVE-2023-5857
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-31
CVEs:CVE-2023-5857
GoogleActive exploitation (sightings)CRITICAL2023-10-31
Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5849
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-31
CVEs:CVE-2023-5849
Open SourceActive exploitation (sightings)MEDIUM2023-10-11
DEBIAN-CVE-2023-5484
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2023-10-10
Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-5484
GoogleActive exploitation (sightings)MEDIUM2023-10-10
CVEs:CVE-2023-5484
GoogleActive exploitation (sightings)MEDIUM2023-10-10
Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-5484
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)2023-10-31
Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
CVEs:CVE-2023-5854
GoogleActive exploitation (sightings)HIGH2023-10-31
CVEs:CVE-2023-5854
GoogleActive exploitation (sightings)CRITICAL2023-10-31
Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
CVEs:CVE-2023-5854
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-31
CVEs:CVE-2023-5480
GoogleActive exploitation (sightings)CRITICAL2023-10-31
Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)
CVEs:CVE-2023-5480
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)2023-10-31
Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)
CVEs:CVE-2023-5480
GoogleActive exploitation (sightings)HIGH2023-10-31
CVEs:CVE-2023-5852
GoogleActive exploitation (sightings)CRITICAL2023-10-31
Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
CVEs:CVE-2023-5852
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-31
CVEs:CVE-2023-5855
GoogleActive exploitation (sightings)CRITICAL2023-10-31
Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
CVEs:CVE-2023-5855
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)2023-10-31
Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
CVEs:CVE-2023-5855
GoogleActive exploitation (sightings)MEDIUM2023-10-31
CVEs:CVE-2023-5850
GoogleActive exploitation (sightings)2023-10-31
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
CVEs:CVE-2023-5850
GoogleActive exploitation (sightings)MEDIUM2023-10-31
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
CVEs:CVE-2023-5850
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2023-10-11
DEBIAN-CVE-2023-5476
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2023-10-10
Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-5476
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-10
CVEs:CVE-2023-5476
GoogleActive exploitation (sightings)MEDIUM2023-10-13
CVEs:CVE-2023-36559
Open SourceActive exploitation (sightings)MEDIUM2023-10-10
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2023-36559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-10-11
DEBIAN-CVE-2023-5485
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-10
CVEs:CVE-2023-5485
GoogleActive exploitation (sightings)MEDIUM2023-10-10
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-5485
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-31
CVEs:CVE-2023-5859
GoogleActive exploitation (sightings)MEDIUM2023-10-31
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-5859
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-10
CVEs:CVE-2023-40534
Open SourceActive exploitation (sightings)HIGH2023-10-10
When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate...
CVEs:CVE-2023-40534
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| big-ip_access_policy_manager |
affected |
f5 |
— |
— |
| big-ip_advanced_firewall_manager |
affected |
f5 |
— |
— |
| big-ip_advanced_web_application_firewall |
affected |
f5 |
— |
— |
| big-ip_analytics |
affected |
f5 |
— |
— |
| big-ip_application_acceleration_manager |
affected |
f5 |
— |
— |
| big-ip_application_security_manager |
affected |
f5 |
— |
— |
| big-ip_application_visibility_and_reporting |
affected |
f5 |
— |
— |
| big-ip_carrier-grade_nat |
affected |
f5 |
— |
— |
| big-ip_ddos_hybrid_defender |
affected |
f5 |
— |
— |
| big-ip_domain_name_system |
affected |
f5 |
— |
— |
| big-ip_edge_gateway |
affected |
f5 |
— |
— |
| big-ip_fraud_protection_service |
affected |
f5 |
— |
— |
| big-ip_global_traffic_manager |
affected |
f5 |
— |
— |
| big-ip_link_controller |
affected |
f5 |
— |
— |
| big-ip_local_traffic_manager |
affected |
f5 |
— |
— |
| big-ip_next_service_proxy_for_kubernetes |
affected |
f5 |
— |
— |
| big-ip_policy_enforcement_manager |
affected |
f5 |
— |
— |
| big-ip_ssl_orchestrator |
affected |
f5 |
— |
— |
| big-ip_webaccelerator |
affected |
f5 |
— |
— |
| big-ip_websafe |
affected |
f5 |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21391
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21391
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21339
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21339
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-10
CVEs:CVE-2023-45226
Open SourceActive exploitation (sightings)CRITICAL2023-10-10
The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those cont...
CVEs:CVE-2023-45226
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| big-ip_next_service_proxy_for_kubernetes |
affected |
f5 |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-10-30
In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21353
GoogleActive exploitation (sightings)HIGH2023-10-26
CVEs:CVE-2023-46094
GoogleActive exploitation (sightings)CRITICAL2023-10-26
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin <= 6.5.3 versions.
CVEs:CVE-2023-46094
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_analytics_integration_for_woocommerce |
affected |
conversios |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-06
CVEs:CVE-2023-27448
GoogleActive exploitation (sightings)HIGH2023-10-06
Cross-Site Request Forgery (CSRF) vulnerability in MakeStories Team MakeStories (for Google Web Stories) plugin <= 2.8.0 versions.
CVEs:CVE-2023-27448
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| makestories_\(for_google_web_stories\) |
affected |
makestories |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-18
CVEs:CVE-2023-3254
GoogleActive exploitation (sightings)MEDIUM2023-10-18
The Widgets for Google Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.9. This is due to missing or incorrect nonce validation within setup_no_reg_header.php. This makes it possible for unau...
CVEs:CVE-2023-3254
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| widgets_for_google_reviews |
affected |
trustedindex |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21395
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21395
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Bluetooth, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege when connecting to a Bluetooth device with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2023-21392
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21392
Open SourceActive exploitation (sightings)HIGH2023-10-30
In RemoteSpeechRecognitionService of RemoteSpeechRecognitionService.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution ...
CVEs:CVE-2023-21342
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21342
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21356
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21356
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21315
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21315
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-45780
Open SourceActive exploitation (sightings)HIGH2023-10-30
In multiple locations, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21351
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21351
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Print Service, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CVEs:CVE-2023-45780
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21398
Open SourceActive exploitation (sightings)HIGH2023-10-30
In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21398
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21334
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In App Ops Service, there is a possible disclosure of information about installed packages due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2023-21334
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21343
Open SourceActive exploitation (sightings)HIGH2023-10-30
In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21343
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21344
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Job Scheduler, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...
CVEs:CVE-2023-21344
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...
CVEs:CVE-2023-21332
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21332
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...
CVEs:CVE-2023-21333
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21333
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21393
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21393
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. Use...
CVEs:CVE-2023-21331
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21331
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21335
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User i...
CVEs:CVE-2023-21335
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21336
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. Us...
CVEs:CVE-2023-21336
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-21329
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21329
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21341
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2023-21341
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21338
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. U...
CVEs:CVE-2023-21338
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21296
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Permission, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. Use...
CVEs:CVE-2023-21296
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21375
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21375
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Media Resource Manager, there is a possible local arbitrary code execution due to use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21381
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21381
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21370
Open SourceActive exploitation (sightings)HIGH2023-10-30
In the Security Element API, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21370
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21371
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Secure Element, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21371
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In ContentService, there is a possible way to read installed sync content providers due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need...
CVEs:CVE-2023-21306
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21306
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21303
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Content, here is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User int...
CVEs:CVE-2023-21303
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21328
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User ...
CVEs:CVE-2023-21328
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In SELinux Policy, there is a possible restriction bypass due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21377
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21377
Open SourceActive exploitation (sightings)HIGH2023-10-30
In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21355
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21355
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21360
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21360
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges...
CVEs:CVE-2023-21326
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21326
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21312
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In IntentResolver, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21312
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Device Policy, there is a possible way to verify if a particular admin app is registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User i...
CVEs:CVE-2023-21320
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21320
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21376
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21376
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21378
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2023-21378
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21367
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2023-21367
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21368
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21368
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21369
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissions bypass. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for...
CVEs:CVE-2023-21369
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21357
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21357
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User i...
CVEs:CVE-2023-21325
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21325
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Permission Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges need...
CVEs:CVE-2023-21327
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21327
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User...
CVEs:CVE-2023-21307
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21307
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Composer, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21308
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21308
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User in...
CVEs:CVE-2023-21316
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21316
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User in...
CVEs:CVE-2023-21318
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21318
Open SourceActive exploitation (sightings)HIGH2023-10-30
In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2023-21319
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21319
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges...
CVEs:CVE-2023-21354
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21354
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21359
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21364
Open SourceActive exploitation (sightings)HIGH2023-10-30
In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21364
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed...
CVEs:CVE-2023-21350
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21350
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2023-21366
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21366
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21321
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21321
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...
CVEs:CVE-2023-21348
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2023-10-30
CVEs:CVE-2023-21348
Open SourceActive exploitation (sightings)MEDIUM2023-10-30
In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ne...
CVEs:CVE-2023-21345
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2023-10-30
CVEs:CVE-2023-21345
GoogleActive exploitation (sightings)MEDIUM2023-10-30
CVEs:CVE-2023-21365
Open SourceActive exploitation (sightings)HIGH2023-10-30
In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21365
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-10-30
CVEs:CVE-2023-21358
Open SourceActive exploitation (sightings)HIGH2023-10-30
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVEs:CVE-2023-21358
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2023-10-18
CVE-2023-38545 affecting package tensorflow for versions less than 2.16.1-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:3 |
tensorflow |
— |
Open SourcePoC exploitCRITICAL2023-10-31
Kubernetes privilege escalation vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aws-ebs-csi-driver-1.18 |
affected |
chainguard |
aws-ebs-csi-driver-1.18 |
— |
| aws-efs-csi-driver-fips |
affected |
chainguard |
aws-efs-csi-driver-fips |
— |
| aws-efs-csi-driver-fips-1.6 |
affected |
chainguard |
aws-efs-csi-driver-fips-1.6 |
— |
| calico-fips |
affected |
chainguard |
calico-fips |
— |
| calico-fips-3.25 |
affected |
chainguard |
calico-fips-3.25 |
— |
| cluster-autoscaler-fips-1.25 |
affected |
chainguard |
cluster-autoscaler-fips-1.25 |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
| nodetaint |
affected |
wolfi |
nodetaint |
— |
| nodetaint |
affected |
chainguard |
nodetaint |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
Open SourcePoC exploitCRITICAL2023-10-31
Kubernetes privilege escalation vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitHIGH2023-10-31
DEBIAN-CVE-2023-3676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourcePoC exploitCRITICAL2023-10-18
CVE-2023-38546 affecting package tensorflow for versions less than 2.16.1-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:3 |
tensorflow |
— |
Open SourcePoC exploitHIGH2023-10-16
Memory exhaustion in go.opentelemetry.io/contrib/instrumentation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| azure-container-networking |
affected |
chainguard |
azure-container-networking |
— |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| caddy |
affected |
wolfi |
caddy |
— |
| caddy |
affected |
chainguard |
caddy |
— |
| contrib/instrumentation/github.com/emicklei/go-restful/otelrestful |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful |
— |
| contrib/instrumentation/github.com/gin-gonic/gin/otelgin |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin |
— |
| contrib/instrumentation/github.com/gorilla/mux/otelmux |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux |
— |
| contrib/instrumentation/github.com/labstack/echo/otelecho |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho |
— |
| contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron |
— |
| contrib/instrumentation/net/http/httptrace/otelhttptrace |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace |
— |
| contrib/instrumentation/net/http/otelhttp |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| kube-oidc-proxy |
affected |
chainguard |
kube-oidc-proxy |
— |
| kubernetes-1.27 |
affected |
wolfi |
kubernetes-1.27 |
— |
| kubernetes-1.28 |
affected |
chainguard |
kubernetes-1.28 |
— |
| kubernetes-1.28 |
affected |
wolfi |
kubernetes-1.28 |
— |
| kubernetes-1.29 |
affected |
chainguard |
kubernetes-1.29 |
— |
| kubernetes-1.29 |
affected |
wolfi |
kubernetes-1.29 |
— |
| kubernetes-1.32 |
affected |
chainguard |
kubernetes-1.32 |
— |
| kubernetes-1.32 |
affected |
wolfi |
kubernetes-1.32 |
— |
| kubernetes-1.33 |
affected |
chainguard |
kubernetes-1.33 |
— |
| kubernetes-1.33 |
affected |
wolfi |
kubernetes-1.33 |
— |
| kubernetes-fips-1.32 |
affected |
chainguard |
kubernetes-fips-1.32 |
— |
| kubernetes-fips-1.33 |
affected |
chainguard |
kubernetes-fips-1.33 |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| metrics-server-fips |
affected |
chainguard |
metrics-server-fips |
— |
| prometheus-adapter |
affected |
chainguard |
prometheus-adapter |
— |
| prometheus-adapter |
affected |
wolfi |
prometheus-adapter |
— |
| prometheus-adapter-0.10 |
affected |
chainguard |
prometheus-adapter-0.10 |
— |
| prometheus-adapter-fips-0.10 |
affected |
chainguard |
prometheus-adapter-fips-0.10 |
— |
| rancher-webhook-0.4 |
affected |
chainguard |
rancher-webhook-0.4 |
— |
| rancher-webhook-fips-0.4 |
affected |
chainguard |
rancher-webhook-fips-0.4 |
— |
| up |
affected |
chainguard |
up |
— |
| up |
affected |
wolfi |
up |
— |
GooglePoC exploitHIGH2023-10-16
OpenTelemetry-Go Contrib vulnerable to denial of service in otelhttp due to unbound cardinality metrics
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| contrib/instrumentation/github.com/emicklei/go-restful/otelrestful |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful |
— |
| contrib/instrumentation/github.com/gin-gonic/gin/otelgin |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin |
— |
| contrib/instrumentation/github.com/gorilla/mux/otelmux |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux |
— |
| contrib/instrumentation/github.com/labstack/echo/otelecho |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho |
— |
| contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron |
— |
| contrib/instrumentation/net/http/httptrace/otelhttptrace |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace |
— |
| contrib/instrumentation/net/http/otelhttp |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp |
— |
Open SourcePoC exploitHIGH2023-10-16
OpenTelemetry-Go Contrib vulnerable to denial of service in otelhttp due to unbound cardinality metrics
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| azure-container-networking |
affected |
chainguard |
azure-container-networking |
— |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| caddy |
affected |
chainguard |
caddy |
— |
| caddy |
affected |
wolfi |
caddy |
— |
| calico |
affected |
wolfi |
calico |
— |
| calico |
affected |
chainguard |
calico |
— |
| calico-fips |
affected |
chainguard |
calico-fips |
— |
| cert-manager-1.11 |
affected |
wolfi |
cert-manager-1.11 |
— |
| cert-manager-1.11 |
affected |
chainguard |
cert-manager-1.11 |
— |
| cert-manager-1.12 |
affected |
wolfi |
cert-manager-1.12 |
— |
| cert-manager-1.12 |
affected |
chainguard |
cert-manager-1.12 |
— |
| cert-manager-1.13 |
affected |
wolfi |
cert-manager-1.13 |
— |
| cert-manager-1.13 |
affected |
chainguard |
cert-manager-1.13 |
— |
| cluster-autoscaler-fips-1.26 |
affected |
chainguard |
cluster-autoscaler-fips-1.26 |
— |
| cluster-autoscaler-fips-1.27 |
affected |
chainguard |
cluster-autoscaler-fips-1.27 |
— |
| cluster-autoscaler-fips-1.28 |
affected |
chainguard |
cluster-autoscaler-fips-1.28 |
— |
| contrib/instrumentation/github.com/emicklei/go-restful/otelrestful |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful |
— |
| contrib/instrumentation/github.com/gin-gonic/gin/otelgin |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin |
— |
| contrib/instrumentation/github.com/gorilla/mux/otelmux |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux |
— |
| contrib/instrumentation/github.com/labstack/echo/otelecho |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho |
— |
| contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron |
— |
| contrib/instrumentation/net/http/httptrace/otelhttptrace |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace |
— |
| contrib/instrumentation/net/http/otelhttp |
affected |
go.opentelemetry.io |
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp |
— |
| gatekeeper-3.12 |
affected |
chainguard |
gatekeeper-3.12 |
— |
| gatekeeper-3.12 |
affected |
wolfi |
gatekeeper-3.12 |
— |
| gatekeeper-3.13 |
affected |
chainguard |
gatekeeper-3.13 |
— |
| gatekeeper-3.13 |
affected |
wolfi |
gatekeeper-3.13 |
— |
| gitlab-kas |
affected |
wolfi |
gitlab-kas |
— |
| gitlab-kas |
affected |
chainguard |
gitlab-kas |
— |
| ipfs |
affected |
wolfi |
ipfs |
— |
| ipfs |
affected |
chainguard |
ipfs |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| keda |
affected |
chainguard |
keda |
— |
| keda |
affected |
wolfi |
keda |
— |
| keda-2.10 |
affected |
chainguard |
keda-2.10 |
— |
| keda-2.10 |
affected |
wolfi |
keda-2.10 |
— |
| keda-2.11 |
affected |
wolfi |
keda-2.11 |
— |
| keda-2.11 |
affected |
chainguard |
keda-2.11 |
— |
| kube-oidc-proxy |
affected |
chainguard |
kube-oidc-proxy |
— |
| kubernetes-1.28 |
affected |
wolfi |
kubernetes-1.28 |
— |
| kubernetes-1.28 |
affected |
chainguard |
kubernetes-1.28 |
— |
| kubernetes-1.29 |
affected |
chainguard |
kubernetes-1.29 |
— |
| kubernetes-1.29 |
affected |
wolfi |
kubernetes-1.29 |
— |
| kubernetes-1.32 |
affected |
wolfi |
kubernetes-1.32 |
— |
| kubernetes-1.32 |
affected |
chainguard |
kubernetes-1.32 |
— |
| kubernetes-1.33 |
affected |
chainguard |
kubernetes-1.33 |
— |
| kubernetes-1.33 |
affected |
wolfi |
kubernetes-1.33 |
— |
| kubernetes-fips-1.27 |
affected |
chainguard |
kubernetes-fips-1.27 |
— |
| kubernetes-fips-1.28 |
affected |
chainguard |
kubernetes-fips-1.28 |
— |
| kubernetes-fips-1.29 |
affected |
chainguard |
kubernetes-fips-1.29 |
— |
| kubernetes-fips-1.32 |
affected |
chainguard |
kubernetes-fips-1.32 |
— |
| kubernetes-fips-1.33 |
affected |
chainguard |
kubernetes-fips-1.33 |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| metrics-server-fips |
affected |
chainguard |
metrics-server-fips |
— |
| prometheus |
affected |
wolfi |
prometheus |
— |
| prometheus |
affected |
chainguard |
prometheus |
— |
| prometheus-2.38 |
affected |
chainguard |
prometheus-2.38 |
— |
| prometheus-adapter |
affected |
chainguard |
prometheus-adapter |
— |
| prometheus-adapter |
affected |
wolfi |
prometheus-adapter |
— |
| prometheus-adapter-0.10 |
affected |
chainguard |
prometheus-adapter-0.10 |
— |
| prometheus-adapter-fips-0.10 |
affected |
chainguard |
prometheus-adapter-fips-0.10 |
— |
| rancher-webhook-0.4 |
affected |
chainguard |
rancher-webhook-0.4 |
— |
| rancher-webhook-fips-0.4 |
affected |
chainguard |
rancher-webhook-fips-0.4 |
— |
| thanos-0.31 |
affected |
wolfi |
thanos-0.31 |
— |
| thanos-0.31 |
affected |
chainguard |
thanos-0.31 |
— |
| thanos-0.32 |
affected |
chainguard |
thanos-0.32 |
— |
| thanos-0.32 |
affected |
wolfi |
thanos-0.32 |
— |
| up |
affected |
wolfi |
up |
— |
| up |
affected |
chainguard |
up |
— |
Open SourcePoC exploitCRITICAL2023-10-11
CVE-2023-39325 affecting package golang for versions less than 1.20.7-2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-10-11
CVE-2023-39325 affecting package application-gateway-kubernetes-ingress for versions less than 1.7.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| application-gateway-kubernetes-ingress |
affected |
Azure Linux:3 |
application-gateway-kubernetes-ingress |
— |
Open SourcePoC exploitCRITICAL2023-10-11
CVE-2023-39325 affecting package golang for versions less than 1.20.7-2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-10-11
CVE-2023-39325 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-10-11
CVE-2023-39325 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-10-11
CVE-2023-39325 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-10-11
DEBIAN-CVE-2023-39325
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
Open SourcePoC exploitHIGH2023-10-11
HTTP/2 rapid reset can cause excessive work in net/http
CVEs:CVE-2023-39325
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourcePoC exploitCRITICAL2023-10-11
HTTP/2 rapid reset can cause excessive work in net/http
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aactl |
affected |
wolfi |
aactl |
— |
| aactl |
affected |
chainguard |
aactl |
— |
| amass |
affected |
wolfi |
amass |
— |
| amass |
affected |
chainguard |
amass |
— |
| apko |
affected |
wolfi |
apko |
— |
| apko |
affected |
chainguard |
apko |
— |
| argo-cd-2.7 |
affected |
wolfi |
argo-cd-2.7 |
— |
| argo-cd-2.7 |
affected |
chainguard |
argo-cd-2.7 |
— |
| argo-cd-2.8 |
affected |
wolfi |
argo-cd-2.8 |
— |
| argo-cd-2.8 |
affected |
chainguard |
argo-cd-2.8 |
— |
| atlantis |
affected |
chainguard |
atlantis |
— |
| atlantis |
affected |
wolfi |
atlantis |
— |
| atlantis-fips |
affected |
chainguard |
atlantis-fips |
— |
| aws-ebs-csi-driver |
affected |
wolfi |
aws-ebs-csi-driver |
— |
| aws-ebs-csi-driver |
affected |
chainguard |
aws-ebs-csi-driver |
— |
| aws-ebs-csi-driver-1.18 |
affected |
chainguard |
aws-ebs-csi-driver-1.18 |
— |
| aws-ebs-csi-driver-1.19 |
affected |
chainguard |
aws-ebs-csi-driver-1.19 |
— |
| aws-efs-csi-driver |
affected |
chainguard |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver |
affected |
wolfi |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver-fips |
affected |
chainguard |
aws-efs-csi-driver-fips |
— |
| aws-efs-csi-driver-fips-1.6 |
affected |
chainguard |
aws-efs-csi-driver-fips-1.6 |
— |
| aws-load-balancer-controller |
affected |
chainguard |
aws-load-balancer-controller |
— |
| aws-load-balancer-controller |
affected |
wolfi |
aws-load-balancer-controller |
— |
| aws-load-balancer-controller-2.4.5 |
affected |
chainguard |
aws-load-balancer-controller-2.4.5 |
— |
| aws-load-balancer-controller-fips |
affected |
chainguard |
aws-load-balancer-controller-fips |
— |
| azure-aad-pod-identity-mic |
affected |
chainguard |
azure-aad-pod-identity-mic |
— |
| bank-vaults |
affected |
chainguard |
bank-vaults |
— |
| bank-vaults |
affected |
wolfi |
bank-vaults |
— |
| bank-vaults-fips |
affected |
chainguard |
bank-vaults-fips |
— |
| bom |
affected |
chainguard |
bom |
— |
| bom |
affected |
wolfi |
bom |
— |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| caddy |
affected |
wolfi |
caddy |
— |
| caddy |
affected |
chainguard |
caddy |
— |
| calico-fips |
affected |
chainguard |
calico-fips |
— |
| calico-fips-3.25 |
affected |
chainguard |
calico-fips-3.25 |
— |
| cert-manager-fips-1.13 |
affected |
chainguard |
cert-manager-fips-1.13 |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| cloud-sql-proxy |
affected |
wolfi |
cloud-sql-proxy |
— |
| cloud-sql-proxy |
affected |
chainguard |
cloud-sql-proxy |
— |
| cluster-autoscaler-1.25 |
affected |
wolfi |
cluster-autoscaler-1.25 |
— |
| cluster-autoscaler-1.25 |
affected |
chainguard |
cluster-autoscaler-1.25 |
— |
| cluster-autoscaler-fips-1.25 |
affected |
chainguard |
cluster-autoscaler-fips-1.25 |
— |
| cluster-autoscaler-fips-1.26 |
affected |
chainguard |
cluster-autoscaler-fips-1.26 |
— |
| cluster-autoscaler-fips-1.27 |
affected |
chainguard |
cluster-autoscaler-fips-1.27 |
— |
| cluster-autoscaler-fips-1.28 |
affected |
chainguard |
cluster-autoscaler-fips-1.28 |
— |
| configmap-reload-fips |
affected |
chainguard |
configmap-reload-fips |
— |
| configmap-reload-fips-0.11 |
affected |
chainguard |
configmap-reload-fips-0.11 |
— |
| consul-1.15 |
affected |
wolfi |
consul-1.15 |
— |
| consul-1.15 |
affected |
chainguard |
consul-1.15 |
— |
| consul-1.16 |
affected |
chainguard |
consul-1.16 |
— |
| consul-1.16 |
affected |
wolfi |
consul-1.16 |
— |
| containerd |
affected |
chainguard |
containerd |
— |
| containerd |
affected |
wolfi |
containerd |
— |
| coredns |
affected |
wolfi |
coredns |
— |
| coredns |
affected |
chainguard |
coredns |
— |
| cosign |
affected |
chainguard |
cosign |
— |
| cosign |
affected |
wolfi |
cosign |
— |
| crossplane-provider-aws |
affected |
wolfi |
crossplane-provider-aws |
— |
| crossplane-provider-aws |
affected |
chainguard |
crossplane-provider-aws |
— |
| crossplane-provider-azure |
affected |
wolfi |
crossplane-provider-azure |
— |
| crossplane-provider-azure |
affected |
chainguard |
crossplane-provider-azure |
— |
| cue |
affected |
chainguard |
cue |
— |
| cue |
affected |
wolfi |
cue |
— |
| dex |
affected |
chainguard |
dex |
— |
| dex |
affected |
wolfi |
dex |
— |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| dgraph |
affected |
chainguard |
dgraph |
— |
| dgraph |
affected |
wolfi |
dgraph |
— |
| dive |
affected |
wolfi |
dive |
— |
| dive |
affected |
chainguard |
dive |
— |
| dynamic-localpv-provisioner |
affected |
chainguard |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner |
affected |
wolfi |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| external-dns |
affected |
wolfi |
external-dns |
— |
| external-dns |
affected |
chainguard |
external-dns |
— |
| external-dns-fips |
affected |
chainguard |
external-dns-fips |
— |
| external-secrets-0.7 |
affected |
chainguard |
external-secrets-0.7 |
— |
| external-secrets-operator |
affected |
chainguard |
external-secrets-operator |
— |
| external-secrets-operator |
affected |
wolfi |
external-secrets-operator |
— |
| falco |
affected |
chainguard |
falco |
— |
| falco |
affected |
wolfi |
falco |
— |
| falcoctl |
affected |
wolfi |
falcoctl |
— |
| falcoctl |
affected |
chainguard |
falcoctl |
— |
| falcoctl-fips |
affected |
chainguard |
falcoctl-fips |
— |
| falcoctl-fips-0.4 |
affected |
chainguard |
falcoctl-fips-0.4 |
— |
| flux |
affected |
chainguard |
flux |
— |
| flux |
affected |
wolfi |
flux |
— |
| flux-0 |
affected |
chainguard |
flux-0 |
— |
| flux-0.37 |
affected |
chainguard |
flux-0.37 |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-helm-controller-0 |
affected |
chainguard |
flux-helm-controller-0 |
— |
| flux-helm-controller-0.37 |
affected |
chainguard |
flux-helm-controller-0.37 |
— |
| flux-image-automation-controller |
affected |
wolfi |
flux-image-automation-controller |
— |
| flux-image-automation-controller |
affected |
chainguard |
flux-image-automation-controller |
— |
| flux-image-reflector-controller |
affected |
chainguard |
flux-image-reflector-controller |
— |
| flux-image-reflector-controller |
affected |
wolfi |
flux-image-reflector-controller |
— |
| flux-image-reflector-controller-0 |
affected |
chainguard |
flux-image-reflector-controller-0 |
— |
| flux-kustomize-controller |
affected |
chainguard |
flux-kustomize-controller |
— |
| flux-kustomize-controller |
affected |
wolfi |
flux-kustomize-controller |
— |
| flux-kustomize-controller-0 |
affected |
chainguard |
flux-kustomize-controller-0 |
— |
| flux-kustomize-controller-0.37 |
affected |
chainguard |
flux-kustomize-controller-0.37 |
— |
| flux-notification-controller |
affected |
chainguard |
flux-notification-controller |
— |
| flux-notification-controller |
affected |
wolfi |
flux-notification-controller |
— |
| flux-notification-controller-0 |
affected |
chainguard |
flux-notification-controller-0 |
— |
| flux-notification-controller-0.37 |
affected |
chainguard |
flux-notification-controller-0.37 |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| flux-source-controller-0 |
affected |
chainguard |
flux-source-controller-0 |
— |
| flux-source-controller-0.37 |
affected |
chainguard |
flux-source-controller-0.37 |
— |
| frp |
affected |
wolfi |
frp |
— |
| frp |
affected |
chainguard |
frp |
— |
| fuse-overlayfs-snapshotter |
affected |
chainguard |
fuse-overlayfs-snapshotter |
— |
| fuse-overlayfs-snapshotter |
affected |
wolfi |
fuse-overlayfs-snapshotter |
— |
| gatekeeper-3.12 |
affected |
wolfi |
gatekeeper-3.12 |
— |
| gatekeeper-3.12 |
affected |
chainguard |
gatekeeper-3.12 |
— |
| gitlab-pages |
affected |
wolfi |
gitlab-pages |
— |
| gitlab-pages |
affected |
chainguard |
gitlab-pages |
— |
| gitlab-runner |
affected |
wolfi |
gitlab-runner |
— |
| gitlab-runner |
affected |
chainguard |
gitlab-runner |
— |
| git-lfs |
affected |
chainguard |
git-lfs |
— |
| git-lfs |
affected |
wolfi |
git-lfs |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gke-gcloud-auth-plugin |
affected |
wolfi |
gke-gcloud-auth-plugin |
— |
| gke-gcloud-auth-plugin |
affected |
chainguard |
gke-gcloud-auth-plugin |
— |
| go-1.20 |
affected |
wolfi |
go-1.20 |
— |
| go-1.20 |
affected |
chainguard |
go-1.20 |
— |
| go-1.21 |
affected |
wolfi |
go-1.21 |
— |
| go-1.21 |
affected |
chainguard |
go-1.21 |
— |
| gobuster |
affected |
chainguard |
gobuster |
— |
| gobuster |
affected |
wolfi |
gobuster |
— |
| gomplate |
affected |
wolfi |
gomplate |
— |
| gomplate |
affected |
chainguard |
gomplate |
— |
| goreleaser-1.18 |
affected |
wolfi |
goreleaser-1.18 |
— |
| goreleaser-1.18 |
affected |
chainguard |
goreleaser-1.18 |
— |
| grafana-9.3 |
affected |
chainguard |
grafana-9.3 |
— |
| grpcurl |
affected |
wolfi |
grpcurl |
— |
| grpcurl |
affected |
chainguard |
grpcurl |
— |
| haproxy-ingress |
affected |
wolfi |
haproxy-ingress |
— |
| haproxy-ingress |
affected |
chainguard |
haproxy-ingress |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm-3 |
affected |
wolfi |
helm-3 |
— |
| helm-3 |
affected |
chainguard |
helm-3 |
— |
| helm-4 |
affected |
wolfi |
helm-4 |
— |
| helm-4 |
affected |
chainguard |
helm-4 |
— |
| hey |
affected |
wolfi |
hey |
— |
| hey |
affected |
chainguard |
hey |
— |
| hugo |
affected |
wolfi |
hugo |
— |
| hugo |
affected |
chainguard |
hugo |
— |
| influxd |
affected |
wolfi |
influxd |
— |
| influxd |
affected |
chainguard |
influxd |
— |
| istio-cni-1.19 |
affected |
wolfi |
istio-cni-1.19 |
— |
| istio-cni-1.19 |
affected |
chainguard |
istio-cni-1.19 |
— |
| istio-operator-1.19 |
affected |
wolfi |
istio-operator-1.19 |
— |
| istio-operator-1.19 |
affected |
chainguard |
istio-operator-1.19 |
— |
| istio-pilot-agent-1.18 |
affected |
wolfi |
istio-pilot-agent-1.18 |
— |
| istio-pilot-agent-1.18 |
affected |
chainguard |
istio-pilot-agent-1.18 |
— |
| istio-pilot-agent-1.19 |
affected |
wolfi |
istio-pilot-agent-1.19 |
— |
| istio-pilot-agent-1.19 |
affected |
chainguard |
istio-pilot-agent-1.19 |
— |
| istio-pilot-discovery-1.18 |
affected |
wolfi |
istio-pilot-discovery-1.18 |
— |
| istio-pilot-discovery-1.18 |
affected |
chainguard |
istio-pilot-discovery-1.18 |
— |
| istio-pilot-discovery-1.19 |
affected |
wolfi |
istio-pilot-discovery-1.19 |
— |
| istio-pilot-discovery-1.19 |
affected |
chainguard |
istio-pilot-discovery-1.19 |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k8sgpt-operator |
affected |
wolfi |
k8sgpt-operator |
— |
| k8sgpt-operator |
affected |
chainguard |
k8sgpt-operator |
— |
| kaf |
affected |
wolfi |
kaf |
— |
| kaf |
affected |
chainguard |
kaf |
— |
| karpenter |
affected |
chainguard |
karpenter |
— |
| karpenter |
affected |
wolfi |
karpenter |
— |
| karpenter-0.23 |
affected |
chainguard |
karpenter-0.23 |
— |
| keda |
affected |
chainguard |
keda |
— |
| keda |
affected |
wolfi |
keda |
— |
| keda-2.10 |
affected |
wolfi |
keda-2.10 |
— |
| keda-2.10 |
affected |
chainguard |
keda-2.10 |
— |
| keda-2.11 |
affected |
wolfi |
keda-2.11 |
— |
| keda-2.11 |
affected |
chainguard |
keda-2.11 |
— |
| keda-2.8 |
affected |
chainguard |
keda-2.8 |
— |
| keda-2.9 |
affected |
chainguard |
keda-2.9 |
— |
| kiam |
affected |
chainguard |
kiam |
— |
| kind |
affected |
chainguard |
kind |
— |
| kind |
affected |
wolfi |
kind |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kpt |
affected |
wolfi |
kpt |
— |
| kpt |
affected |
chainguard |
kpt |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kube-fluentd-operator |
affected |
chainguard |
kube-fluentd-operator |
— |
| kube-fluentd-operator |
affected |
wolfi |
kube-fluentd-operator |
— |
| kube-logging-logging-operator-3.17 |
affected |
chainguard |
kube-logging-logging-operator-3.17 |
— |
| kube-logging-logging-operator-4.1 |
affected |
chainguard |
kube-logging-logging-operator-4.1 |
— |
| kube-logging-operator |
affected |
wolfi |
kube-logging-operator |
— |
| kube-logging-operator |
affected |
chainguard |
kube-logging-operator |
— |
| kube-oidc-proxy |
affected |
chainguard |
kube-oidc-proxy |
— |
| kubernetes-1.19 |
affected |
chainguard |
kubernetes-1.19 |
— |
| kubernetes-1.20 |
affected |
chainguard |
kubernetes-1.20 |
— |
| kubernetes-1.21 |
affected |
chainguard |
kubernetes-1.21 |
— |
| kubernetes-1.22 |
affected |
chainguard |
kubernetes-1.22 |
— |
| kubernetes-1.23 |
affected |
chainguard |
kubernetes-1.23 |
— |
| kubernetes-1.24 |
affected |
chainguard |
kubernetes-1.24 |
— |
| kubernetes-1.24 |
affected |
wolfi |
kubernetes-1.24 |
— |
| kubernetes-csi-external-attacher-4.3 |
affected |
chainguard |
kubernetes-csi-external-attacher-4.3 |
— |
| kubernetes-csi-external-attacher-4.3 |
affected |
wolfi |
kubernetes-csi-external-attacher-4.3 |
— |
| kubernetes-csi-external-attacher-4.4 |
affected |
wolfi |
kubernetes-csi-external-attacher-4.4 |
— |
| kubernetes-csi-external-attacher-4.4 |
affected |
chainguard |
kubernetes-csi-external-attacher-4.4 |
— |
| kubernetes-csi-external-attacher-fips-4.3 |
affected |
chainguard |
kubernetes-csi-external-attacher-fips-4.3 |
— |
| kubernetes-csi-external-attacher-fips-4.4 |
affected |
chainguard |
kubernetes-csi-external-attacher-fips-4.4 |
— |
| kubernetes-csi-external-provisioner |
affected |
chainguard |
kubernetes-csi-external-provisioner |
— |
| kubernetes-csi-external-provisioner |
affected |
wolfi |
kubernetes-csi-external-provisioner |
— |
| kubernetes-csi-external-resizer |
affected |
chainguard |
kubernetes-csi-external-resizer |
— |
| kubernetes-csi-external-resizer |
affected |
wolfi |
kubernetes-csi-external-resizer |
— |
| kubernetes-csi-external-resizer-1.8 |
affected |
chainguard |
kubernetes-csi-external-resizer-1.8 |
— |
| kubernetes-csi-external-resizer-fips-1.8 |
affected |
chainguard |
kubernetes-csi-external-resizer-fips-1.8 |
— |
| kubernetes-csi-external-snapshotter |
affected |
wolfi |
kubernetes-csi-external-snapshotter |
— |
| kubernetes-csi-external-snapshotter |
affected |
chainguard |
kubernetes-csi-external-snapshotter |
— |
| kubernetes-csi-external-snapshotter-6.0 |
affected |
chainguard |
kubernetes-csi-external-snapshotter-6.0 |
— |
| kubernetes-csi-livenessprobe |
affected |
wolfi |
kubernetes-csi-livenessprobe |
— |
| kubernetes-csi-livenessprobe |
affected |
chainguard |
kubernetes-csi-livenessprobe |
— |
| kubernetes-csi-livenessprobe-2.10 |
affected |
chainguard |
kubernetes-csi-livenessprobe-2.10 |
— |
| kubernetes-csi-livenessprobe-fips |
affected |
chainguard |
kubernetes-csi-livenessprobe-fips |
— |
| kubernetes-csi-node-driver-registrar-2.9 |
affected |
chainguard |
kubernetes-csi-node-driver-registrar-2.9 |
— |
| kubernetes-csi-node-driver-registrar-2.9 |
affected |
wolfi |
kubernetes-csi-node-driver-registrar-2.9 |
— |
| kubernetes-csi-node-driver-registrar-fips-2.8 |
affected |
chainguard |
kubernetes-csi-node-driver-registrar-fips-2.8 |
— |
| kubernetes-csi-node-driver-registrar-fips-2.9 |
affected |
chainguard |
kubernetes-csi-node-driver-registrar-fips-2.9 |
— |
| kubernetes-dashboard |
affected |
wolfi |
kubernetes-dashboard |
— |
| kubernetes-dashboard |
affected |
chainguard |
kubernetes-dashboard |
— |
| kubernetes-dashboard-metrics-scraper |
affected |
chainguard |
kubernetes-dashboard-metrics-scraper |
— |
| kubernetes-dashboard-metrics-scraper |
affected |
wolfi |
kubernetes-dashboard-metrics-scraper |
— |
| kubernetes-dns-node-cache |
affected |
chainguard |
kubernetes-dns-node-cache |
— |
| kubernetes-dns-node-cache |
affected |
wolfi |
kubernetes-dns-node-cache |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
| kubernetes-ingress-defaultbackend |
affected |
wolfi |
kubernetes-ingress-defaultbackend |
— |
| kubernetes-ingress-defaultbackend |
affected |
chainguard |
kubernetes-ingress-defaultbackend |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kube-state-metrics |
affected |
wolfi |
kube-state-metrics |
— |
| kube-state-metrics |
affected |
chainguard |
kube-state-metrics |
— |
| kube-state-metrics-2.2.0 |
affected |
chainguard |
kube-state-metrics-2.2.0 |
— |
| kube-state-metrics-2.6 |
affected |
chainguard |
kube-state-metrics-2.6 |
— |
| kube-state-metrics-fips |
affected |
chainguard |
kube-state-metrics-fips |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubewatch |
affected |
wolfi |
kubewatch |
— |
| kubewatch |
affected |
chainguard |
kubewatch |
— |
| kyverno |
affected |
wolfi |
kyverno |
— |
| kyverno |
affected |
chainguard |
kyverno |
— |
| kyverno-1.8 |
affected |
chainguard |
kyverno-1.8 |
— |
| kyverno-policy-reporter-2.11 |
affected |
chainguard |
kyverno-policy-reporter-2.11 |
— |
| kyverno-policy-reporter-kyverno-plugin-1.5 |
affected |
chainguard |
kyverno-policy-reporter-kyverno-plugin-1.5 |
— |
| kyverno-policy-reporter-ui-1.7 |
affected |
chainguard |
kyverno-policy-reporter-ui-1.7 |
— |
| mc |
affected |
chainguard |
mc |
— |
| mc |
affected |
wolfi |
mc |
— |
| memcached-exporter |
affected |
chainguard |
memcached-exporter |
— |
| memcached-exporter |
affected |
wolfi |
memcached-exporter |
— |
| metacontroller |
affected |
chainguard |
metacontroller |
— |
| metacontroller |
affected |
wolfi |
metacontroller |
— |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| metrics-server-fips |
affected |
chainguard |
metrics-server-fips |
— |
| minio |
affected |
wolfi |
minio |
— |
| minio |
affected |
chainguard |
minio |
— |
| nats |
affected |
chainguard |
nats |
— |
| nats |
affected |
wolfi |
nats |
— |
| newrelic-infrastructure-agent |
affected |
chainguard |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent |
affected |
wolfi |
newrelic-infrastructure-agent |
— |
| nfs-subdir-external-provisioner |
affected |
wolfi |
nfs-subdir-external-provisioner |
— |
| nfs-subdir-external-provisioner |
affected |
chainguard |
nfs-subdir-external-provisioner |
— |
| nfs-subdir-external-provisioner-fips |
affected |
chainguard |
nfs-subdir-external-provisioner-fips |
— |
| node-problem-detector-0.8 |
affected |
chainguard |
node-problem-detector-0.8 |
— |
| node-problem-detector-0.8 |
affected |
wolfi |
node-problem-detector-0.8 |
— |
| nodetaint |
affected |
wolfi |
nodetaint |
— |
| nodetaint |
affected |
chainguard |
nodetaint |
— |
| nri-prometheus |
affected |
wolfi |
nri-prometheus |
— |
| nri-prometheus |
affected |
chainguard |
nri-prometheus |
— |
| oauth2-proxy |
affected |
wolfi |
oauth2-proxy |
— |
| oauth2-proxy |
affected |
chainguard |
oauth2-proxy |
— |
| ollama |
affected |
chainguard |
ollama |
— |
| ollama |
affected |
wolfi |
ollama |
— |
| opentofu |
affected |
wolfi |
opentofu |
— |
| opentofu |
affected |
chainguard |
opentofu |
— |
| prometheus |
affected |
chainguard |
prometheus |
— |
| prometheus |
affected |
wolfi |
prometheus |
— |
| prometheus-adapter |
affected |
wolfi |
prometheus-adapter |
— |
| prometheus-adapter |
affected |
chainguard |
prometheus-adapter |
— |
| prometheus-adapter-0.10 |
affected |
chainguard |
prometheus-adapter-0.10 |
— |
| prometheus-adapter-fips |
affected |
chainguard |
prometheus-adapter-fips |
— |
| prometheus-adapter-fips-0.10 |
affected |
chainguard |
prometheus-adapter-fips-0.10 |
— |
| prometheus-alertmanager |
affected |
wolfi |
prometheus-alertmanager |
— |
| prometheus-alertmanager |
affected |
chainguard |
prometheus-alertmanager |
— |
| prometheus-bind-exporter |
affected |
chainguard |
prometheus-bind-exporter |
— |
| prometheus-bind-exporter |
affected |
wolfi |
prometheus-bind-exporter |
— |
| prometheus-blackbox-exporter |
affected |
wolfi |
prometheus-blackbox-exporter |
— |
| prometheus-blackbox-exporter |
affected |
chainguard |
prometheus-blackbox-exporter |
— |
| prometheus-elasticsearch-exporter |
affected |
chainguard |
prometheus-elasticsearch-exporter |
— |
| prometheus-elasticsearch-exporter |
affected |
wolfi |
prometheus-elasticsearch-exporter |
— |
| prometheus-elasticsearch-exporter-fips |
affected |
chainguard |
prometheus-elasticsearch-exporter-fips |
— |
| prometheus-fips |
affected |
chainguard |
prometheus-fips |
— |
| prometheus-fips-2.38 |
affected |
chainguard |
prometheus-fips-2.38 |
— |
| prometheus-mongodb-exporter |
affected |
chainguard |
prometheus-mongodb-exporter |
— |
| prometheus-mongodb-exporter |
affected |
wolfi |
prometheus-mongodb-exporter |
— |
| prometheus-mongodb-exporter-fips |
affected |
chainguard |
prometheus-mongodb-exporter-fips |
— |
| prometheus-mongodb-exporter-fips-0.37 |
affected |
chainguard |
prometheus-mongodb-exporter-fips-0.37 |
— |
| prometheus-mysqld-exporter |
affected |
wolfi |
prometheus-mysqld-exporter |
— |
| prometheus-mysqld-exporter |
affected |
chainguard |
prometheus-mysqld-exporter |
— |
| prometheus-node-exporter |
affected |
chainguard |
prometheus-node-exporter |
— |
| prometheus-node-exporter |
affected |
wolfi |
prometheus-node-exporter |
— |
| prometheus-node-exporter-1.5 |
affected |
chainguard |
prometheus-node-exporter-1.5 |
— |
| prometheus-node-exporter-fips |
affected |
chainguard |
prometheus-node-exporter-fips |
— |
| prometheus-operator |
affected |
wolfi |
prometheus-operator |
— |
| prometheus-operator |
affected |
chainguard |
prometheus-operator |
— |
| prometheus-postgres-exporter |
affected |
chainguard |
prometheus-postgres-exporter |
— |
| prometheus-postgres-exporter |
affected |
wolfi |
prometheus-postgres-exporter |
— |
| prometheus-postgres-exporter-0.10 |
affected |
chainguard |
prometheus-postgres-exporter-0.10 |
— |
| prometheus-postgres-exporter-fips |
affected |
chainguard |
prometheus-postgres-exporter-fips |
— |
| prometheus-pushgateway |
affected |
chainguard |
prometheus-pushgateway |
— |
| prometheus-pushgateway |
affected |
wolfi |
prometheus-pushgateway |
— |
| prometheus-pushgateway-fips |
affected |
chainguard |
prometheus-pushgateway-fips |
— |
| prometheus-pushgateway-fips-1.4 |
affected |
chainguard |
prometheus-pushgateway-fips-1.4 |
— |
| prometheus-redis-exporter-fips-1.44 |
affected |
chainguard |
prometheus-redis-exporter-fips-1.44 |
— |
| prometheus-stackdriver-exporter |
affected |
chainguard |
prometheus-stackdriver-exporter |
— |
| prometheus-stackdriver-exporter |
affected |
wolfi |
prometheus-stackdriver-exporter |
— |
| prometheus-statsd-exporter |
affected |
chainguard |
prometheus-statsd-exporter |
— |
| prometheus-statsd-exporter |
affected |
wolfi |
prometheus-statsd-exporter |
— |
| prometheus-statsd-exporter-fips |
affected |
chainguard |
prometheus-statsd-exporter-fips |
— |
| pulumi |
affected |
chainguard |
pulumi |
— |
| pulumi |
affected |
wolfi |
pulumi |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| pulumi-language-dotnet |
affected |
chainguard |
pulumi-language-dotnet |
— |
| pulumi-language-dotnet |
affected |
wolfi |
pulumi-language-dotnet |
— |
| pulumi-language-java |
affected |
chainguard |
pulumi-language-java |
— |
| pulumi-language-java |
affected |
wolfi |
pulumi-language-java |
— |
| pulumi-language-yaml |
affected |
wolfi |
pulumi-language-yaml |
— |
| pulumi-language-yaml |
affected |
chainguard |
pulumi-language-yaml |
— |
| rqlite |
affected |
chainguard |
rqlite |
— |
| rqlite |
affected |
wolfi |
rqlite |
— |
| runc |
affected |
chainguard |
runc |
— |
| runc |
affected |
wolfi |
runc |
— |
| secrets-store-csi-driver |
affected |
wolfi |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver |
affected |
chainguard |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver-provider-gcp |
affected |
chainguard |
secrets-store-csi-driver-provider-gcp |
— |
| secrets-store-csi-driver-provider-gcp |
affected |
wolfi |
secrets-store-csi-driver-provider-gcp |
— |
| sigstore-scaffolding |
affected |
chainguard |
sigstore-scaffolding |
— |
| sigstore-scaffolding |
affected |
wolfi |
sigstore-scaffolding |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| smarter-device-manager-fips |
affected |
chainguard |
smarter-device-manager-fips |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
| src |
affected |
wolfi |
src |
— |
| src |
affected |
chainguard |
src |
— |
| stakater-reloader |
affected |
wolfi |
stakater-reloader |
— |
| stakater-reloader |
affected |
chainguard |
stakater-reloader |
— |
| stakater-reloader-0.0.119 |
affected |
chainguard |
stakater-reloader-0.0.119 |
— |
| stakater-reloader-0.0.128 |
affected |
chainguard |
stakater-reloader-0.0.128 |
— |
| tctl |
affected |
wolfi |
tctl |
— |
| tctl |
affected |
chainguard |
tctl |
— |
| tekton-chains |
affected |
wolfi |
tekton-chains |
— |
| tekton-chains |
affected |
chainguard |
tekton-chains |
— |
| telegraf-1.26 |
affected |
chainguard |
telegraf-1.26 |
— |
| telegraf-1.26 |
affected |
wolfi |
telegraf-1.26 |
— |
| telegraf-1.27 |
affected |
chainguard |
telegraf-1.27 |
— |
| telegraf-1.27 |
affected |
wolfi |
telegraf-1.27 |
— |
| terraform |
affected |
chainguard |
terraform |
— |
| terraform |
affected |
wolfi |
terraform |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| thanos-0.31 |
affected |
wolfi |
thanos-0.31 |
— |
| thanos-0.31 |
affected |
chainguard |
thanos-0.31 |
— |
| thanos-0.32 |
affected |
chainguard |
thanos-0.32 |
— |
| thanos-0.32 |
affected |
wolfi |
thanos-0.32 |
— |
| thanos-operator |
affected |
wolfi |
thanos-operator |
— |
| thanos-operator |
affected |
chainguard |
thanos-operator |
— |
| timoni |
affected |
wolfi |
timoni |
— |
| timoni |
affected |
chainguard |
timoni |
— |
| tkn |
affected |
wolfi |
tkn |
— |
| tkn |
affected |
chainguard |
tkn |
— |
| trillian |
affected |
chainguard |
trillian |
— |
| trillian |
affected |
wolfi |
trillian |
— |
| trust-manager |
affected |
wolfi |
trust-manager |
— |
| trust-manager |
affected |
chainguard |
trust-manager |
— |
| up |
affected |
chainguard |
up |
— |
| up |
affected |
wolfi |
up |
— |
| vault-1.13 |
affected |
chainguard |
vault-1.13 |
— |
| vault-1.13 |
affected |
wolfi |
vault-1.13 |
— |
| vault-csi-provider |
affected |
chainguard |
vault-csi-provider |
— |
| vault-csi-provider |
affected |
wolfi |
vault-csi-provider |
— |
| vault-k8s |
affected |
chainguard |
vault-k8s |
— |
| vault-k8s |
affected |
wolfi |
vault-k8s |
— |
| vault-k8s-fips |
affected |
chainguard |
vault-k8s-fips |
— |
| vertical-pod-autoscaler |
affected |
wolfi |
vertical-pod-autoscaler |
— |
| vertical-pod-autoscaler |
affected |
chainguard |
vertical-pod-autoscaler |
— |
| volume-modifier-for-k8s-fips |
affected |
chainguard |
volume-modifier-for-k8s-fips |
— |
| wavefront-collector-for-kubernetes-1.12 |
affected |
chainguard |
wavefront-collector-for-kubernetes-1.12 |
— |
| wavefront-collector-for-kubernetes-1.13 |
affected |
chainguard |
wavefront-collector-for-kubernetes-1.13 |
— |
| weaviate |
affected |
chainguard |
weaviate |
— |
| weaviate |
affected |
wolfi |
weaviate |
— |
| wireguard-go |
affected |
chainguard |
wireguard-go |
— |
| wireguard-go |
affected |
wolfi |
wireguard-go |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
| x/net |
affected |
golang.org |
— |
— |
| yq |
affected |
chainguard |
yq |
— |
| yq |
affected |
wolfi |
yq |
— |
| zot |
affected |
wolfi |
zot |
— |
| zot |
affected |
chainguard |
zot |
— |
Open SourcePoC exploitCRITICAL2023-10-11
HTTP/2 rapid reset can cause excessive work in net/http
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourcePoC exploitHIGH2023-10-11
HTTP/2 rapid reset can cause excessive work in net/http
CVEs:CVE-2023-39325
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
GooglePoC exploitCRITICAL2023-10-11
A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progre...
CVEs:CVE-2023-39325
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| astra_trident |
affected |
netapp |
— |
— |
| astra_trident_autosupport |
affected |
netapp |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
| http2 |
affected |
golang |
— |
— |
Open SourcePoC exploitCRITICAL2023-10-31
Kubernetes privilege escalation vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| argo-cd-2.7 |
affected |
wolfi |
argo-cd-2.7 |
— |
| argo-cd-2.7 |
affected |
chainguard |
argo-cd-2.7 |
— |
| argo-cd-2.8 |
affected |
chainguard |
argo-cd-2.8 |
— |
| argo-cd-2.8 |
affected |
wolfi |
argo-cd-2.8 |
— |
| aws-ebs-csi-driver-1.18 |
affected |
chainguard |
aws-ebs-csi-driver-1.18 |
— |
| aws-ebs-csi-driver-1.19 |
affected |
chainguard |
aws-ebs-csi-driver-1.19 |
— |
| aws-efs-csi-driver |
affected |
chainguard |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver |
affected |
wolfi |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver-fips |
affected |
chainguard |
aws-efs-csi-driver-fips |
— |
| aws-efs-csi-driver-fips-1.6 |
affected |
chainguard |
aws-efs-csi-driver-fips-1.6 |
— |
| calico |
affected |
chainguard |
calico |
— |
| calico |
affected |
wolfi |
calico |
— |
| calico-fips |
affected |
chainguard |
calico-fips |
— |
| calico-fips-3.25 |
affected |
chainguard |
calico-fips-3.25 |
— |
| cluster-autoscaler-1.25 |
affected |
chainguard |
cluster-autoscaler-1.25 |
— |
| cluster-autoscaler-1.25 |
affected |
wolfi |
cluster-autoscaler-1.25 |
— |
| cluster-autoscaler-fips-1.25 |
affected |
chainguard |
cluster-autoscaler-fips-1.25 |
— |
| cluster-autoscaler-fips-1.28 |
affected |
chainguard |
cluster-autoscaler-fips-1.28 |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
| nodetaint |
affected |
wolfi |
nodetaint |
— |
| nodetaint |
affected |
chainguard |
nodetaint |
— |
| secrets-store-csi-driver |
affected |
wolfi |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver |
affected |
chainguard |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver-fips |
affected |
chainguard |
secrets-store-csi-driver-fips |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
Open SourcePoC exploitCRITICAL2023-10-31
Kubernetes privilege escalation vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitHIGH2023-10-31
DEBIAN-CVE-2023-3955
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourcePoC exploitCRITICAL2023-10-05
Fix CVE(s): CVE-2022-48560
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python3.5 |
— |
| libpython3.5 |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5 |
— |
| libpython3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-dev |
— |
| libpython3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-minimal |
— |
| libpython3.5-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-stdlib |
— |
| libpython3.5-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-testsuite |
— |
| python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
python3.5 |
— |
| python3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-dev |
— |
| python3.5-doc |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-doc |
— |
| python3.5-examples |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-examples |
— |
| python3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-minimal |
— |
| python3.5-venv |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-venv |
— |
GooglePoC exploit2023-10-01
ASB-A-296463357
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitHIGH2023-10-12
CVE-2023-45142 affecting package kubernetes for versions less than 1.29.1-2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Azure Linux:3 |
kubernetes |
— |
Open SourcePoC exploit2023-10-17
Fix CVE(s): CVE-2022-48566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python3.5 |
— |
| libpython3.5 |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5 |
— |
| libpython3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-dev |
— |
| libpython3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-minimal |
— |
| libpython3.5-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-stdlib |
— |
| libpython3.5-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-testsuite |
— |
| python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
python3.5 |
— |
| python3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-dev |
— |
| python3.5-doc |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-doc |
— |
| python3.5-examples |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-examples |
— |
| python3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-minimal |
— |
| python3.5-venv |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-venv |
— |
Open SourcePoC exploit2023-10-16
Fix CVE(s): CVE-2022-48566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python2.7 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python2.7 |
— |
| libpython2.7 |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7 |
— |
| libpython2.7-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-dev |
— |
| libpython2.7-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-minimal |
— |
| libpython2.7-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-stdlib |
— |
| libpython2.7-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-testsuite |
— |
| python2.7 |
affected |
TuxCare:Ubuntu:16.04 |
python2.7 |
— |
| python2.7-dev |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-dev |
— |
| python2.7-doc |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-doc |
— |
| python2.7-examples |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-examples |
— |
| python2.7-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-minimal |
— |
Open SourcePoC exploit2023-10-16
Fix CVE(s): CVE-2022-48566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python2.7 |
affected |
TuxCare:Ubuntu:18.04 |
idle-python2.7 |
— |
| libpython2.7 |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7 |
— |
| libpython2.7-dev |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-dev |
— |
| libpython2.7-minimal |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-minimal |
— |
| libpython2.7-stdlib |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-stdlib |
— |
| libpython2.7-testsuite |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-testsuite |
— |
| python2.7 |
affected |
TuxCare:Ubuntu:18.04 |
python2.7 |
— |
| python2.7-dev |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-dev |
— |
| python2.7-doc |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-doc |
— |
| python2.7-examples |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-examples |
— |
| python2.7-minimal |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-minimal |
— |
Open SourcePoC exploit2023-10-16
Fix CVE(s): CVE-2022-48566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python3.6 |
affected |
TuxCare:Ubuntu:18.04 |
idle-python3.6 |
— |
| libpython3.6 |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6 |
— |
| libpython3.6-dev |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-dev |
— |
| libpython3.6-minimal |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-minimal |
— |
| libpython3.6-stdlib |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-stdlib |
— |
| libpython3.6-testsuite |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-testsuite |
— |
| python3.6 |
affected |
TuxCare:Ubuntu:18.04 |
python3.6 |
— |
| python3.6-dev |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-dev |
— |
| python3.6-doc |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-doc |
— |
| python3.6-examples |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-examples |
— |
| python3.6-minimal |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-minimal |
— |
| python3.6-venv |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-venv |
— |
Open SourcePoC exploitHIGH2023-10-02
`Cookie` HTTP header isn't stripped on cross-origin redirects
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dask-gateway |
affected |
wolfi |
dask-gateway |
— |
| dask-gateway |
affected |
chainguard |
dask-gateway |
— |
| k8s-sidecar |
affected |
wolfi |
k8s-sidecar |
— |
| k8s-sidecar |
affected |
chainguard |
k8s-sidecar |
— |
| kube-downscaler |
affected |
chainguard |
kube-downscaler |
— |
| kube-downscaler |
affected |
wolfi |
kube-downscaler |
— |
| kubeflow-jupyter-web-app |
affected |
chainguard |
kubeflow-jupyter-web-app |
— |
| kubeflow-jupyter-web-app |
affected |
wolfi |
kubeflow-jupyter-web-app |
— |
| kubeflow-volumes-web-app |
affected |
wolfi |
kubeflow-volumes-web-app |
— |
| kubeflow-volumes-web-app |
affected |
chainguard |
kubeflow-volumes-web-app |
— |
| py3.13-scanner-test-libraries |
affected |
chainguard |
py3.13-scanner-test-libraries |
— |
| py3-urllib3 |
affected |
chainguard |
py3-urllib3 |
— |
| py3-urllib3 |
affected |
wolfi |
py3-urllib3 |
— |
| py3-urllib3-1 |
affected |
chainguard |
py3-urllib3-1 |
— |
| py3-urllib3-1 |
affected |
wolfi |
py3-urllib3-1 |
— |
| urllib3 |
affected |
PyPI |
urllib3 |
— |
| urllib3 |
affected |
PyPI |
urllib3 |
— |
GooglePoC exploitHIGH2023-10-02
`Cookie` HTTP header isn't stripped on cross-origin redirects
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| urllib3 |
affected |
PyPI |
urllib3 |
— |
GooglePoC exploitCRITICAL2023-10-25
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| werkzeug |
affected |
PyPI |
werkzeug |
— |
Open SourcePoC exploitCRITICAL2023-10-25
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| airflow-2 |
affected |
chainguard |
airflow-2 |
— |
| airflow-3 |
affected |
wolfi |
airflow-3 |
— |
| airflow-3 |
affected |
chainguard |
airflow-3 |
— |
| airflow-core-2 |
affected |
chainguard |
airflow-core-2 |
— |
| kubeflow-jupyter-web-app |
affected |
chainguard |
kubeflow-jupyter-web-app |
— |
| kubeflow-jupyter-web-app |
affected |
wolfi |
kubeflow-jupyter-web-app |
— |
| kubeflow-pipelines-visualization-server |
affected |
chainguard |
kubeflow-pipelines-visualization-server |
— |
| kubeflow-pipelines-visualization-server |
affected |
wolfi |
kubeflow-pipelines-visualization-server |
— |
| kubeflow-volumes-web-app |
affected |
wolfi |
kubeflow-volumes-web-app |
— |
| kubeflow-volumes-web-app |
affected |
chainguard |
kubeflow-volumes-web-app |
— |
| py3-tensorflow-serving-api |
affected |
wolfi |
py3-tensorflow-serving-api |
— |
| py3-tensorflow-serving-api |
affected |
chainguard |
py3-tensorflow-serving-api |
— |
| py3-werkzeug |
affected |
chainguard |
py3-werkzeug |
— |
| py3-werkzeug |
affected |
wolfi |
py3-werkzeug |
— |
| werkzeug |
affected |
PyPI |
werkzeug |
— |
| werkzeug |
affected |
PyPI |
werkzeug |
— |
| Werkzeug |
affected |
PyPI |
Werkzeug |
— |
| Werkzeug |
affected |
PyPI |
— |
— |
Open SourcePoC exploitCRITICAL2023-10-13
grpc security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
openEuler:20.03-LTS-SP1 |
grpc |
— |
GooglePoC exploitHIGH2023-10-17
urllib3's request body not stripped after redirect from 303 status changes request method to GET
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| urllib3 |
affected |
PyPI |
urllib3 |
— |
Open SourcePoC exploitHIGH2023-10-17
urllib3's request body not stripped after redirect from 303 status changes request method to GET
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| az |
affected |
wolfi |
az |
— |
| az |
affected |
chainguard |
az |
— |
| jwt-tool |
affected |
chainguard |
jwt-tool |
— |
| jwt-tool |
affected |
wolfi |
jwt-tool |
— |
| k8s-sidecar-1.22 |
affected |
chainguard |
k8s-sidecar-1.22 |
— |
| kubeflow-jupyter-web-app |
affected |
wolfi |
kubeflow-jupyter-web-app |
— |
| kubeflow-jupyter-web-app |
affected |
chainguard |
kubeflow-jupyter-web-app |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| kubeflow-volumes-web-app |
affected |
chainguard |
kubeflow-volumes-web-app |
— |
| kubeflow-volumes-web-app |
affected |
wolfi |
kubeflow-volumes-web-app |
— |
| nvidia-nsight-compute-13.1 |
affected |
chainguard |
nvidia-nsight-compute-13.1 |
— |
| nvidia-nsight-compute-13.2 |
affected |
chainguard |
nvidia-nsight-compute-13.2 |
— |
| py3.11-pytorch-cuda-12.3 |
affected |
chainguard |
py3.11-pytorch-cuda-12.3 |
— |
| py3.11-torchaudio-cuda-12.3 |
affected |
chainguard |
py3.11-torchaudio-cuda-12.3 |
— |
| py3.11-torchvision-cuda-11.8 |
affected |
chainguard |
py3.11-torchvision-cuda-11.8 |
— |
| py3.11-torchvision-cuda-12.3 |
affected |
chainguard |
py3.11-torchvision-cuda-12.3 |
— |
| py3.13-scanner-test-libraries |
affected |
chainguard |
py3.13-scanner-test-libraries |
— |
| py3-cassandra-medusa |
affected |
wolfi |
py3-cassandra-medusa |
— |
| py3-cassandra-medusa |
affected |
chainguard |
py3-cassandra-medusa |
— |
| py3-pipenv |
affected |
chainguard |
py3-pipenv |
— |
| py3-pipenv |
affected |
wolfi |
py3-pipenv |
— |
| py3-tensorflow-serving-api |
affected |
chainguard |
py3-tensorflow-serving-api |
— |
| py3-tensorflow-serving-api |
affected |
wolfi |
py3-tensorflow-serving-api |
— |
| py3-torchvision-cuda-11.8 |
affected |
chainguard |
py3-torchvision-cuda-11.8 |
— |
| py3-urllib3-1 |
affected |
chainguard |
py3-urllib3-1 |
— |
| py3-urllib3-1 |
affected |
wolfi |
py3-urllib3-1 |
— |
| request-1276 |
affected |
chainguard |
request-1276 |
— |
| urllib3 |
affected |
PyPI |
urllib3 |
— |
| urllib3 |
affected |
PyPI |
urllib3 |
— |
Open SourcePoC exploitMEDIUM2023-10-18
BELL-CVE-2023-32732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Alpaquita:23 |
grpc |
— |
Open SourcePoC exploitHIGH2023-10-18
BELL-CVE-2023-32731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Alpaquita:23 |
grpc |
— |
Open SourcePoC exploitHIGH2023-10-18
BELL-CVE-2023-33953
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Alpaquita:23 |
grpc |
— |
| grpc |
affected |
Alpaquita:stream |
grpc |
— |
Open SourcePoC exploitCRITICAL2023-10-25
Command Injection in pip when used with Mercurial
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| jwt-tool |
affected |
chainguard |
jwt-tool |
— |
| jwt-tool |
affected |
wolfi |
jwt-tool |
— |
| k8s-sidecar-1.22 |
affected |
chainguard |
k8s-sidecar-1.22 |
— |
| pip |
affected |
PyPI |
pip |
— |
| pip |
affected |
PyPI |
pip |
— |
GooglePoC exploitCRITICAL2023-10-25
Command Injection in pip when used with Mercurial
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| pip |
affected |
PyPI |
pip |
— |
GooglePoC exploitHIGH2023-10-11
CVEs:CVE-2023-35649
Open SourcePoC exploitHIGH2023-10-11
In several functions of Exynos modem files, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35649
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-10-01
PUB-A-276971478
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitCRITICAL2023-10-11
In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35646
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2023-10-11
CVEs:CVE-2023-35646
GooglePoC exploitHIGH2023-10-01
PUB-A-276972140
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitHIGH2023-10-18
BELL-CVE-2023-1428
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Alpaquita:23 |
grpc |
— |
GooglePoC exploit2023-10-02
In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.
CVEs:CVE-2023-32820
GooglePoC exploitHIGH2023-10-02
CVEs:CVE-2023-32820
Open SourcePoC exploitHIGH2023-10-02
In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637...
CVEs:CVE-2023-32820
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GooglePoC exploit2023-10-01
ASB-A-294781433
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploitCRITICAL2023-10-11
CVEs:CVE-2023-35648
Open SourcePoC exploitCRITICAL2023-10-11
In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction...
CVEs:CVE-2023-35648
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-10-01
PUB-A-286373897
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploit2023-10-01
ASB-A-287627703
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploitHIGH2023-10-11
CVEs:CVE-2023-35656
Open SourcePoC exploitHIGH2023-10-11
In multiple functions of protocolembmsadapter.cpp, there is a possible out
of bounds read due to a missing bounds check. This could lead to remote
information disclosure with no additional execution privileges needed. User
interaction is n...
CVEs:CVE-2023-35656
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2023-10-11
In Init of protocolnetadapter.cpp, there is a possible out of bounds read
due to a missing bounds check. This could lead to remote information
disclosure with no additional execution privileges needed. User interaction
is not needed for e...
CVEs:CVE-2023-35663
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-10-11
CVEs:CVE-2023-35663
GooglePoC exploitHIGH2023-10-01
PUB-A-286537026
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploitNONE2023-10-01
PUB-A-286718842
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitHIGH2023-10-03
In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2023-40140
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-10-03
CVEs:CVE-2023-40140
GooglePoC exploitLOW2023-10-03
CVEs:CVE-2023-40127
Open SourcePoC exploitMEDIUM2023-10-03
In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40127
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitMEDIUM2023-10-03
In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2023-40133
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-10-03
CVEs:CVE-2023-40133
GooglePoC exploit2023-10-01
PUB-A-240605080
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploit2023-10-01
PUB-A-253296923
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploitHIGH2023-10-03
CVEs:CVE-2023-21266
Open SourcePoC exploitHIGH2023-10-03
In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2023-21266
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2023-10-03
In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User i...
CVEs:CVE-2023-40130
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-10-03
CVEs:CVE-2023-40130
GooglePoC exploit2023-10-01
ASB-A-290061916
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GooglePoC exploit2023-10-01
ASB-A-290061247
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GooglePoC exploit2023-10-01
PUB-A-276762572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitMEDIUM2023-10-03
In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not need...
CVEs:CVE-2023-21291
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-10-03
CVEs:CVE-2023-21291
Open SourcePoC exploitHIGH2023-10-03
In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2023-40117
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-10-03
CVEs:CVE-2023-40117
GooglePoC exploitHIGH2023-10-03
CVEs:CVE-2023-40116
Open SourcePoC exploitHIGH2023-10-03
In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. Use...
CVEs:CVE-2023-40116
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-10-03
CVEs:CVE-2023-40128
Open SourcePoC exploitHIGH2023-10-03
In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-10-03
CVEs:CVE-2023-40120
Open SourcePoC exploitHIGH2023-10-03
In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2023-40120
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-10-03
CVEs:CVE-2023-40125
Open SourcePoC exploitHIGH2023-10-03
In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2023-40125
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitMEDIUM2023-10-11
In ctrl_roi of stmvl53l1_module.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35654
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-10-11
CVEs:CVE-2023-35654
Open SourcePoC exploitHIGH2023-10-11
In lwis_transaction_client_cleanup of lwis_transaction.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2023-35660
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-10-11
CVEs:CVE-2023-35660
Open SourcePoC exploitHIGH2023-10-11
In temp_residency_name_store of thermal_metrics.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2023-40141
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-10-11
CVEs:CVE-2023-40141
GooglePoC exploitHIGH2023-10-01
PUB-A-239873016
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploitNONE2023-10-01
PUB-A-272492131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploitHIGH2023-10-01
PUB-A-274446016
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitMEDIUM2023-10-11
In TBD of TBD, there is a possible way to access location information due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35653
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-10-11
CVEs:CVE-2023-35653
Open SourcePoC exploitMEDIUM2023-10-02
In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issu...
CVEs:CVE-2023-32819
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-10-02
CVEs:CVE-2023-32819
GooglePoC exploit2023-10-01
ASB-A-294779649
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploitMEDIUM2023-10-01
PUB-A-272281209
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitHIGH2023-10-03
In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-40638
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-10-03
CVEs:CVE-2023-40638
GooglePoC exploit2023-10-01
ASB-A-296491611
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploitHIGH2023-10-11
CVEs:CVE-2023-3781
Open SourcePoC exploitHIGH2023-10-11
there is a possible use-after-free write due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-3781
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-10-01
PUB-A-289470723
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-05
CVE-2023-39323 affecting package golang for versions less than 1.20.10-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-05
CVE-2023-39323 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-05
CVE-2023-39323 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-05
CVE-2023-39323 affecting package golang for versions less than 1.20.10-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-05
CVE-2023-39323 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-05
DEBIAN-CVE-2023-39323
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-25
Ingress-nginx path sanitization can be bypassed
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
k8s.io |
k8s.io/ingress-nginx |
— |
| ingress-nginx-controller |
affected |
wolfi |
ingress-nginx-controller |
— |
| ingress-nginx-controller |
affected |
chainguard |
ingress-nginx-controller |
— |
| ingress-nginx-controller-1.9 |
affected |
chainguard |
ingress-nginx-controller-1.9 |
— |
| ingress-nginx-controller-fips |
affected |
chainguard |
ingress-nginx-controller-fips |
— |
| ingress-nginx-controller-fips-1.9 |
affected |
chainguard |
ingress-nginx-controller-fips-1.9 |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-25
Ingress-nginx path sanitization can be bypassed
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
k8s.io |
k8s.io/ingress-nginx |
— |
GoogleCoalition ESS < 30%HIGH2023-10-25
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
CVEs:CVE-2022-4886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
kubernetes |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-25
Ingress-nginx path sanitization can be bypassed
CVEs:CVE-2022-4886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
k8s.io |
k8s.io/ingress-nginx |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-25
The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute.
CVEs:CVE-2023-45886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| big-ip_global_traffic_manager |
affected |
f5 |
— |
— |
| big-ip_local_traffic_manager |
affected |
f5 |
— |
— |
| big-ip_next |
affected |
f5 |
— |
— |
| big-ip_next_cloud-native_network_functions |
affected |
f5 |
— |
— |
| big-ip_next_service_proxy_for_kubernetes |
affected |
f5 |
— |
— |
| zebos |
affected |
ipinfusion |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-25
CVEs:CVE-2023-45886
Open SourceCoalition ESS < 30%HIGH2023-10-29
Adobe Acrobat for Edge version 118.0.2088.46 (and earlier) is affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Expl...
CVEs:CVE-2023-44323
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-29
CVEs:CVE-2023-44323
Open SourceCoalition ESS < 30%CRITICAL2023-10-30
Updated chromium-browser-stable packages fix bugs including security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:9 |
chromium-browser-stable |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-26
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourceCoalition ESS < 30%2023-10-26
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-25
DEBIAN-CVE-2023-5472
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-10-24
Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5472
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-24
CVEs:CVE-2023-5472
GoogleCoalition ESS < 30%2023-10-24
Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5472
GoogleCoalition ESS < 30%CRITICAL2023-10-31
Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-5856
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-31
CVEs:CVE-2023-5856
GoogleCoalition ESS < 30%MEDIUM2023-10-31
CVEs:CVE-2023-5851
GoogleCoalition ESS < 30%MEDIUM2023-10-31
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-5851
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
Kube-proxy may unintentionally forward traffic
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
| nodetaint |
affected |
wolfi |
nodetaint |
— |
| nodetaint |
affected |
chainguard |
nodetaint |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
Kube-proxy may unintentionally forward traffic
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
CVEs:CVE-2023-36409
Open SourceCoalition ESS < 30%HIGH2023-10-10
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVEs:CVE-2023-36409
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-11
DEBIAN-CVE-2023-5474
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2023-10-10
Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
CVEs:CVE-2023-5474
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-10
CVEs:CVE-2023-5474
Open SourceCoalition ESS < 30%MEDIUM2023-10-11
DEBIAN-CVE-2023-5483
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
CVEs:CVE-2023-5483
GoogleCoalition ESS < 30%2023-10-10
Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-5483
GoogleCoalition ESS < 30%MEDIUM2023-10-10
Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-5483
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-11
DEBIAN-CVE-2023-5478
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
CVEs:CVE-2023-5478
GoogleCoalition ESS < 30%MEDIUM2023-10-10
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-5478
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-11
DEBIAN-CVE-2023-5481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
CVEs:CVE-2023-5481
GoogleCoalition ESS < 30%MEDIUM2023-10-10
Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-5481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-11
DEBIAN-CVE-2023-5473
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
CVEs:CVE-2023-5473
GoogleCoalition ESS < 30%CRITICAL2023-10-10
Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-5473
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-11
DEBIAN-CVE-2023-5486
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
CVEs:CVE-2023-5486
GoogleCoalition ESS < 30%MEDIUM2023-10-10
Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-5486
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-31
CVEs:CVE-2023-5853
GoogleCoalition ESS < 30%MEDIUM2023-10-31
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-5853
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-31
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-5858
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-31
CVEs:CVE-2023-5858
GoogleCoalition ESS < 30%2023-10-01
ASB-A-294779648
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-11
DEBIAN-CVE-2023-5487
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: ...
CVEs:CVE-2023-5487
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
CVEs:CVE-2023-5487
GoogleCoalition ESS < 30%MEDIUM2023-10-25
CVEs:CVE-2023-5744
GoogleCoalition ESS < 30%HIGH2023-10-24
The Very Simple Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vsgmap' shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attr...
CVEs:CVE-2023-5744
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| very_simple_google_maps |
affected |
very_simple_google_maps_project |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-11
DEBIAN-CVE-2023-5479
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-5479
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
CVEs:CVE-2023-5479
Open SourceCoalition ESS < 30%MEDIUM2023-10-11
DEBIAN-CVE-2023-5475
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2023-10-10
Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
CVEs:CVE-2023-5475
GoogleCoalition ESS < 30%MEDIUM2023-10-10
CVEs:CVE-2023-5475
GoogleCoalition ESS < 30%MEDIUM2023-10-10
Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severit...
CVEs:CVE-2023-5475
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-12
kOps privilege escalation vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kops |
affected |
k8s.io |
k8s.io/kops |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-12
kOps privilege escalation vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kops |
affected |
k8s.io |
k8s.io/kops |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-5315
GoogleCoalition ESS < 30%HIGH2023-10-30
The Google Maps made Simple plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exist...
CVEs:CVE-2023-5315
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_maps_made_simple |
affected |
matthewschwartz |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-20
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attacke...
CVEs:CVE-2022-4943
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_authenticator |
affected |
miniorange |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-20
CVEs:CVE-2022-4943
Open SourceCoalition ESS < 30%MEDIUM2023-10-11
DEBIAN-CVE-2023-5477
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)
CVEs:CVE-2023-5477
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-10
CVEs:CVE-2023-5477
GoogleCoalition ESS < 30%CRITICAL2023-10-11
CVEs:CVE-2023-35662
Open SourceCoalition ESS < 30%CRITICAL2023-10-11
there is a possible out of bounds write due to buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35662
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-01
PUB-A-276971805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2023-10-05
CVEs:CVE-2022-3248
Open SourceCoalition ESS < 30%CRITICAL2023-10-05
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.
CVEs:CVE-2022-3248
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| advanced_cluster_management_for_kubernetes |
affected |
redhat |
— |
— |
| openshift_container_platform |
affected |
redhat |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-08
CVEs:CVE-2023-40632
Open SourceCoalition ESS < 30%CRITICAL2023-10-08
In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure no additional execution privileges needed
CVEs:CVE-2023-40632
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-10-16
Google Sheets data source plugin for Grafana information disclosure vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grafana/google-sheets-datasource |
affected |
github.com |
github.com/grafana/google-sheets-datasource |
— |
GoogleCoalition ESS < 30%CRITICAL2023-10-16
Google Sheets data source plugin for Grafana information disclosure vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grafana/google-sheets-datasource |
affected |
github.com |
github.com/grafana/google-sheets-datasource |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-16
Google Sheets data source plugin for Grafana information disclosure vulnerability
CVEs:CVE-2023-4457
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grafana/google-sheets-datasource |
affected |
github.com |
github.com/grafana/google-sheets-datasource |
— |
GoogleCoalition ESS < 30%CRITICAL2023-10-16
Grafana is an open-source platform for monitoring and observability.
The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability.
The plugin did not properly sanitize error messa...
CVEs:CVE-2023-4457
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_sheets |
affected |
grafana |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-16
Google Sheets data source plugin for Grafana information disclosure vulnerability
CVEs:CVE-2023-4457
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grafana/google-sheets-datasource |
affected |
github.com |
github.com/grafana/google-sheets-datasource |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-10-31
DEBIAN-CVE-2023-46129
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-nats-io-nkeys |
affected |
Debian:13 |
golang-github-nats-io-nkeys |
— |
| golang-github-nats-io-nkeys |
affected |
Debian:14 |
golang-github-nats-io-nkeys |
— |
| nats-server |
affected |
Debian:13 |
nats-server |
— |
| nats-server |
affected |
Debian:14 |
nats-server |
— |
GoogleCoalition ESS < 30%2023-10-01
PUB-A-271904738
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21347
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21347
GoogleCoalition ESS < 30%HIGH2023-10-11
CVEs:CVE-2023-35661
Open SourceCoalition ESS < 30%HIGH2023-10-11
In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2023-35661
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-01
PUB-A-254938063
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2023-10-11
CVEs:CVE-2023-35647
Open SourceCoalition ESS < 30%CRITICAL2023-10-11
In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction...
CVEs:CVE-2023-35647
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-01
PUB-A-278109661
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-11
In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction...
CVEs:CVE-2023-35652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-11
CVEs:CVE-2023-35652
GoogleCoalition ESS < 30%MEDIUM2023-10-01
PUB-A-278108845
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2023-10-01
ASB-A-287624919
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2023-10-01
ASB-A-296461583
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2023-10-03
CVEs:CVE-2023-38396
GoogleCoalition ESS < 30%HIGH2023-10-03
Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez plugin <= 3.1.2 versions.
CVEs:CVE-2023-38396
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-map-shortcode |
affected |
web-argument |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-04
CVEs:CVE-2023-40561
GoogleCoalition ESS < 30%HIGH2023-10-04
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugin <= 3.7.1 versions.
CVEs:CVE-2023-40561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enhanced_ecommerce_google_analytics_for_woocommerce |
affected |
multidots |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-03
CVEs:CVE-2023-40129
Open SourceCoalition ESS < 30%HIGH2023-10-03
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2023-40129
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-16
CVEs:CVE-2023-45273
GoogleCoalition ESS < 30%HIGH2023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Matt McKenny Stout Google Calendar plugin <= 1.2.3 versions.
CVEs:CVE-2023-45273
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stout_google_calendar |
affected |
mattmckenny |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-03
In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40121
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-03
CVEs:CVE-2023-40121
GoogleCoalition ESS < 30%HIGH2023-10-16
CVEs:CVE-2023-45831
GoogleCoalition ESS < 30%HIGH2023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Pixelative, Mohsin Rafique AMP WP – Google AMP For WordPress plugin <= 1.5.15 versions.
CVEs:CVE-2023-45831
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_amp |
affected |
pixelative |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21361
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Bluetooth, there is a possibility of code-execution due to a use after free. This could lead to paired device escalation of privilege in the privileged Bluetooth process with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2023-21361
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-03
In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21253
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-03
CVEs:CVE-2023-21253
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-40101
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In collapse of canonicalize_md.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-03
In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2023-21244
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-03
CVEs:CVE-2023-21244
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21337
Open SourceCoalition ESS < 30%HIGH2023-10-30
In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. Us...
CVEs:CVE-2023-21337
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2023-10-01
PUB-A-253297595
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2021-39810
Open SourceCoalition ESS < 30%HIGH2023-10-30
In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no add...
CVEs:CVE-2021-39810
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2023-10-01
PUB-A-261492822
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2023-10-01
ASB-A-290060972
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-03
CVEs:CVE-2023-21252
Open SourceCoalition ESS < 30%MEDIUM2023-10-03
In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction ...
CVEs:CVE-2023-21252
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21396
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21396
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges need...
CVEs:CVE-2022-20264
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2022-20264
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In SliceManagerService, there is a possible way to check if a content provider is installed due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-21295
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21295
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21293
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges n...
CVEs:CVE-2023-21293
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21387
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not n...
CVEs:CVE-2023-21387
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21397
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21397
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Overlay Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....
CVEs:CVE-2023-21330
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21330
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21388
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21388
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21389
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21389
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21390
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21390
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21340
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21340
Open SourceCoalition ESS < 30%HIGH2023-10-11
In TBD of TBD, there is a possible way to bypass carrier restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40142
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-11
CVEs:CVE-2023-40142
GoogleCoalition ESS < 30%NONE2023-10-01
PUB-A-279767668
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21310
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21310
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User inter...
CVEs:CVE-2023-21394
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21394
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Settings, there is a possible way for the user to unintentionally send extra data due to an unclear prompt. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
CVEs:CVE-2023-21383
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21383
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21372
Open SourceCoalition ESS < 30%HIGH2023-10-30
In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21372
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21324
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges need...
CVEs:CVE-2023-21324
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21294
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21294
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21380
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21380
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....
CVEs:CVE-2023-21302
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21302
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21298
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Slice, there is a possible disclosure of installed applications due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2023-21298
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Content Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....
CVEs:CVE-2023-21304
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21304
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....
CVEs:CVE-2023-21299
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21299
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21300
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...
CVEs:CVE-2023-21300
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-03
In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2023-40137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-10-03
CVEs:CVE-2023-40137
GoogleCoalition ESS < 30%LOW2023-10-03
CVEs:CVE-2023-40138
Open SourceCoalition ESS < 30%MEDIUM2023-10-03
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40138
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21374
Open SourceCoalition ESS < 30%HIGH2023-10-30
In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21374
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Package Manager, there is a possible possible permissions bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21384
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21384
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User in...
CVEs:CVE-2023-21305
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21305
Open SourceCoalition ESS < 30%MEDIUM2023-10-03
In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee...
CVEs:CVE-2023-40123
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-03
CVEs:CVE-2023-40123
Open SourceCoalition ESS < 30%MEDIUM2023-10-03
In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2023-40135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-10-03
CVEs:CVE-2023-40135
Open SourceCoalition ESS < 30%MEDIUM2023-10-03
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40139
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-03
CVEs:CVE-2023-40139
GoogleCoalition ESS < 30%MEDIUM2023-10-02
CVEs:CVE-2023-32826
GoogleCoalition ESS < 30%MEDIUM2023-10-02
CVEs:CVE-2023-32827
GoogleCoalition ESS < 30%MEDIUM2023-10-02
CVEs:CVE-2023-32828
GoogleCoalition ESS < 30%MEDIUM2023-10-02
CVEs:CVE-2023-32830
Open SourceCoalition ESS < 30%HIGH2023-10-02
In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03802522; Issue ID:...
CVEs:CVE-2023-32830
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-02
In vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767817; Issue ID: ALP...
CVEs:CVE-2023-32828
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-02
In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07...
CVEs:CVE-2023-32827
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-02
In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07...
CVEs:CVE-2023-32826
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21379
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21379
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21385
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21385
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21314
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21314
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In ContentService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...
CVEs:CVE-2023-21317
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21317
GoogleCoalition ESS < 30%LOW2023-10-03
CVEs:CVE-2023-40134
Open SourceCoalition ESS < 30%MEDIUM2023-10-03
In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2023-40134
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-10-03
CVEs:CVE-2023-40136
Open SourceCoalition ESS < 30%MEDIUM2023-10-03
In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2023-40136
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-02
CVEs:CVE-2023-32821
Open SourceCoalition ESS < 30%HIGH2023-10-02
In video, there is a possible out of bounds write due to a permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08013430; Issue ID: ...
CVEs:CVE-2023-32821
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-02
CVEs:CVE-2023-32829
GoogleCoalition ESS < 30%MEDIUM2023-10-02
CVEs:CVE-2023-32822
Open SourceCoalition ESS < 30%HIGH2023-10-02
In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07713478; Issue ID: ...
CVEs:CVE-2023-32829
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-02
In ftm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07994229; Issue ID: ...
CVEs:CVE-2023-32822
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In ActivityManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges...
CVEs:CVE-2023-21301
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21301
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Activity Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed...
CVEs:CVE-2023-21323
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21323
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21297
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In SEPolicy, there is a possible way to access the factory MAC address due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21297
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21352
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21352
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In libcore, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21309
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21309
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21313
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21313
GoogleCoalition ESS < 30%HIGH2023-10-03
CVEs:CVE-2023-40131
Open SourceCoalition ESS < 30%HIGH2023-10-03
In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-02
CVEs:CVE-2023-32824
GoogleCoalition ESS < 30%MEDIUM2023-10-02
CVEs:CVE-2023-32823
Open SourceCoalition ESS < 30%HIGH2023-10-02
In rpmb , there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07912966; Issue ID: ALPS07912961.
CVEs:CVE-2023-32824
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-02
In rpmb , there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07912966; Issue ID: ...
CVEs:CVE-2023-32823
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2023-21373
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-30
CVEs:CVE-2023-21373
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....
CVEs:CVE-2023-21349
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-10-30
CVEs:CVE-2023-21349
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2023-21311
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21311
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40651
Open SourceCoalition ESS < 30%CRITICAL2023-10-08
In urild service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-40651
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile...
CVEs:CVE-2023-21346
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-10-30
CVEs:CVE-2023-21346
Open SourceCoalition ESS < 30%MEDIUM2023-10-08
In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed
CVEs:CVE-2023-40654
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40654
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40636
Open SourceCoalition ESS < 30%HIGH2023-10-08
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with System execution privileges needed
CVEs:CVE-2023-40636
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-10-30
In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User in...
CVEs:CVE-2023-21382
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21382
Open SourceCoalition ESS < 30%CRITICAL2023-10-08
In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-40652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40652
Open SourceCoalition ESS < 30%MEDIUM2023-10-08
In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed
CVEs:CVE-2023-40653
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40653
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40631
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
CVEs:CVE-2023-40631
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-30
CVEs:CVE-2023-21362
Open SourceCoalition ESS < 30%HIGH2023-10-30
In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21362
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-08
CVEs:CVE-2023-40634
Open SourceCoalition ESS < 30%CRITICAL2023-10-08
In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-40634
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-08
CVEs:CVE-2023-40635
Open SourceCoalition ESS < 30%HIGH2023-10-08
In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-40635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40641
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40641
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40642
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40642
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40643
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40643
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40644
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40644
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40645
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40645
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40646
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40646
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40647
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40647
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40648
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40648
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40649
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40649
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-10-08
In Telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40650
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40650
Open SourceCoalition ESS < 30%HIGH2023-10-08
In phasecheckserver, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-40633
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40633
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40637
Open SourceCoalition ESS < 30%HIGH2023-10-08
In telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-40637
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40639
Open SourceCoalition ESS < 30%HIGH2023-10-08
In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-40639
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-08
CVEs:CVE-2023-40640
Open SourceCoalition ESS < 30%HIGH2023-10-08
In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-40640
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-10-11
CVEs:CVE-2023-35645
Open SourceCoalition ESS < 30%HIGH2023-10-11
In tbd of tbd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35645
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-10-01
PUB-A-283787360
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleEPSS <= 49%HIGH2023-10-12
CVEs:CVE-2023-23651
GoogleEPSS <= 49%CRITICAL2023-10-12
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.
CVEs:CVE-2023-23651
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mainwp_google_analytics_extension |
affected |
mainwp |
— |
— |
Open SourceEPSS <= 49%HIGH2023-10-03
Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi and connect arbitrary Wi-Fi without User Interaction.
CVEs:CVE-2023-30727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%HIGH2023-10-03
CVEs:CVE-2023-30727
GoogleEPSS <= 49%MEDIUM2023-10-03
CVEs:CVE-2023-30731
Open SourceEPSS <= 49%MEDIUM2023-10-03
Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.
CVEs:CVE-2023-30731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceEPSS <= 49%HIGH2023-10-03
Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
CVEs:CVE-2023-30692
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%HIGH2023-10-03
CVEs:CVE-2023-30692
GoogleEPSS <= 49%HIGH2023-10-03
CVEs:CVE-2023-30690
Open SourceEPSS <= 49%HIGH2023-10-03
Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
CVEs:CVE-2023-30690
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%CRITICAL2023-10-03
CVEs:CVE-2023-30733
Open SourceEPSS <= 49%HIGH2023-10-03
Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attackers to perform code execution.
CVEs:CVE-2023-30733
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%LOW2023-10-03
CVEs:CVE-2023-30732
Open SourceEPSS <= 49%MEDIUM2023-10-03
Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.
CVEs:CVE-2023-30732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%2023-10-01
PUB-A-245789946
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceEPSS <= 49%HIGH2023-10-11
In CanConvertPadV2Op of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2023-35655
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2023-10-11
CVEs:CVE-2023-35655
GoogleEPSS <= 49%HIGH2023-10-01
PUB-A-264509020
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceAll remainingNONE2023-10-30
/sys/devices/virtual/powercap accessible by default to containers
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aactl |
affected |
chainguard |
aactl |
— |
| aactl |
affected |
wolfi |
aactl |
— |
| apko |
affected |
chainguard |
apko |
— |
| apko |
affected |
wolfi |
apko |
— |
| argo-workflows |
affected |
chainguard |
argo-workflows |
— |
| argo-workflows |
affected |
wolfi |
argo-workflows |
— |
| bom |
affected |
chainguard |
bom |
— |
| bom |
affected |
wolfi |
bom |
— |
| cert-manager-1.11 |
affected |
wolfi |
cert-manager-1.11 |
— |
| cert-manager-1.11 |
affected |
chainguard |
cert-manager-1.11 |
— |
| cert-manager-1.12 |
affected |
wolfi |
cert-manager-1.12 |
— |
| cert-manager-1.12 |
affected |
chainguard |
cert-manager-1.12 |
— |
| cert-manager-1.13 |
affected |
chainguard |
cert-manager-1.13 |
— |
| cert-manager-1.13 |
affected |
wolfi |
cert-manager-1.13 |
— |
| cert-manager-fips-1.13 |
affected |
chainguard |
cert-manager-fips-1.13 |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| conftest |
affected |
wolfi |
conftest |
— |
| conftest |
affected |
chainguard |
conftest |
— |
| conftest-fips |
affected |
chainguard |
conftest-fips |
— |
| cosign |
affected |
chainguard |
cosign |
— |
| cosign |
affected |
wolfi |
cosign |
— |
| ctop |
affected |
chainguard |
ctop |
— |
| ctop |
affected |
wolfi |
ctop |
— |
| docker |
affected |
wolfi |
docker |
— |
| docker |
affected |
chainguard |
docker |
— |
| docker/docker |
affected |
github.com |
github.com/docker/docker |
— |
| docker/docker |
affected |
github.com |
github.com/docker/docker |
— |
| falco |
affected |
wolfi |
falco |
— |
| falco |
affected |
chainguard |
falco |
— |
| falcoctl-fips |
affected |
chainguard |
falcoctl-fips |
— |
| falcoctl-fips-0.4 |
affected |
chainguard |
falcoctl-fips-0.4 |
— |
| flux |
affected |
wolfi |
flux |
— |
| flux |
affected |
chainguard |
flux |
— |
| flux-0 |
affected |
chainguard |
flux-0 |
— |
| flux-0.37 |
affected |
chainguard |
flux-0.37 |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-helm-controller-0 |
affected |
chainguard |
flux-helm-controller-0 |
— |
| flux-helm-controller-0.37 |
affected |
chainguard |
flux-helm-controller-0.37 |
— |
| flux-image-reflector-controller |
affected |
wolfi |
flux-image-reflector-controller |
— |
| flux-image-reflector-controller |
affected |
chainguard |
flux-image-reflector-controller |
— |
| flux-image-reflector-controller-0 |
affected |
chainguard |
flux-image-reflector-controller-0 |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| flux-source-controller-0 |
affected |
chainguard |
flux-source-controller-0 |
— |
| flux-source-controller-0.37 |
affected |
chainguard |
flux-source-controller-0.37 |
— |
| flux-source-controller-2.0 |
affected |
chainguard |
flux-source-controller-2.0 |
— |
| github.com/docker/docker |
affected |
Go |
github.com/docker/docker |
— |
| gitlab-runner-fips-17.0 |
affected |
chainguard |
gitlab-runner-fips-17.0 |
— |
| goreleaser-1.18 |
affected |
wolfi |
goreleaser-1.18 |
— |
| goreleaser-1.18 |
affected |
chainguard |
goreleaser-1.18 |
— |
| grype |
affected |
chainguard |
grype |
— |
| grype |
affected |
wolfi |
grype |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm-3 |
affected |
wolfi |
helm-3 |
— |
| helm-3 |
affected |
chainguard |
helm-3 |
— |
| helm-4 |
affected |
wolfi |
helm-4 |
— |
| helm-4 |
affected |
chainguard |
helm-4 |
— |
| helm-push |
affected |
wolfi |
helm-push |
— |
| helm-push |
affected |
chainguard |
helm-push |
— |
| istio-operator-1.19 |
affected |
chainguard |
istio-operator-1.19 |
— |
| istio-operator-1.19 |
affected |
wolfi |
istio-operator-1.19 |
— |
| istio-operator-fips-1.19 |
affected |
chainguard |
istio-operator-fips-1.19 |
— |
| istio-pilot-agent-1.19 |
affected |
chainguard |
istio-pilot-agent-1.19 |
— |
| istio-pilot-agent-1.19 |
affected |
wolfi |
istio-pilot-agent-1.19 |
— |
| istio-pilot-agent-fips-1.19 |
affected |
chainguard |
istio-pilot-agent-fips-1.19 |
— |
| istio-pilot-discovery-1.19 |
affected |
chainguard |
istio-pilot-discovery-1.19 |
— |
| istio-pilot-discovery-1.19 |
affected |
wolfi |
istio-pilot-discovery-1.19 |
— |
| istio-pilot-discovery-fips-1.19 |
affected |
chainguard |
istio-pilot-discovery-fips-1.19 |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| ko |
affected |
chainguard |
ko |
— |
| ko |
affected |
wolfi |
ko |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kpt |
affected |
wolfi |
kpt |
— |
| kpt |
affected |
chainguard |
kpt |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kyverno |
affected |
chainguard |
kyverno |
— |
| kyverno |
affected |
wolfi |
kyverno |
— |
| kyverno-1.8 |
affected |
chainguard |
kyverno-1.8 |
— |
| loki |
affected |
wolfi |
loki |
— |
| loki |
affected |
chainguard |
loki |
— |
| melange |
affected |
chainguard |
melange |
— |
| melange |
affected |
wolfi |
melange |
— |
| newrelic-infrastructure-agent |
affected |
wolfi |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent |
affected |
chainguard |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent-1.43 |
affected |
chainguard |
newrelic-infrastructure-agent-1.43 |
— |
| paranoia |
affected |
wolfi |
paranoia |
— |
| paranoia |
affected |
chainguard |
paranoia |
— |
| prometheus |
affected |
chainguard |
prometheus |
— |
| prometheus |
affected |
wolfi |
prometheus |
— |
| prometheus-2.38 |
affected |
chainguard |
prometheus-2.38 |
— |
| prometheus-2.45 |
affected |
wolfi |
prometheus-2.45 |
— |
| prometheus-2.45 |
affected |
chainguard |
prometheus-2.45 |
— |
| prometheus-fips |
affected |
chainguard |
prometheus-fips |
— |
| rancher-agent-2.8 |
affected |
chainguard |
rancher-agent-2.8 |
— |
| scorecard |
affected |
wolfi |
scorecard |
— |
| scorecard |
affected |
chainguard |
scorecard |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| spire-server |
affected |
chainguard |
spire-server |
— |
| spire-server |
affected |
wolfi |
spire-server |
— |
| spire-server-fips |
affected |
chainguard |
spire-server-fips |
— |
| tekton-chains |
affected |
chainguard |
tekton-chains |
— |
| tekton-chains |
affected |
wolfi |
tekton-chains |
— |
| tekton-pipelines |
affected |
wolfi |
tekton-pipelines |
— |
| tekton-pipelines |
affected |
chainguard |
tekton-pipelines |
— |
| telegraf-1.26 |
affected |
chainguard |
telegraf-1.26 |
— |
| telegraf-1.26 |
affected |
wolfi |
telegraf-1.26 |
— |
| telegraf-1.27 |
affected |
wolfi |
telegraf-1.27 |
— |
| telegraf-1.27 |
affected |
chainguard |
telegraf-1.27 |
— |
| traefik |
affected |
chainguard |
traefik |
— |
| traefik |
affected |
wolfi |
traefik |
— |
| up |
affected |
chainguard |
up |
— |
| up |
affected |
wolfi |
up |
— |
GoogleAll remainingNONE2023-10-30
/sys/devices/virtual/powercap accessible by default to containers
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| docker/docker |
affected |
github.com |
github.com/docker/docker |
— |
Open SourceAll remainingCRITICAL2023-10-25
gRPC-Go HTTP/2 Rapid Reset vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
google.golang.org |
google.golang.org/grpc |
— |
Open SourceAll remainingCRITICAL2023-10-25
gRPC-Go HTTP/2 Rapid Reset vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aactl |
affected |
chainguard |
aactl |
— |
| aactl |
affected |
wolfi |
aactl |
— |
| aws-ebs-csi-driver-1.18 |
affected |
chainguard |
aws-ebs-csi-driver-1.18 |
— |
| aws-ebs-csi-driver-1.19 |
affected |
chainguard |
aws-ebs-csi-driver-1.19 |
— |
| aws-efs-csi-driver-fips |
affected |
chainguard |
aws-efs-csi-driver-fips |
— |
| aws-efs-csi-driver-fips-1.6 |
affected |
chainguard |
aws-efs-csi-driver-fips-1.6 |
— |
| bank-vaults-fips |
affected |
chainguard |
bank-vaults-fips |
— |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| calico-fips |
affected |
chainguard |
calico-fips |
— |
| calico-fips-3.25 |
affected |
chainguard |
calico-fips-3.25 |
— |
| cluster-autoscaler-fips-1.25 |
affected |
chainguard |
cluster-autoscaler-fips-1.25 |
— |
| cluster-autoscaler-fips-1.28 |
affected |
chainguard |
cluster-autoscaler-fips-1.28 |
— |
| conftest-fips |
affected |
chainguard |
conftest-fips |
— |
| cortex |
affected |
chainguard |
cortex |
— |
| cortex |
affected |
wolfi |
cortex |
— |
| dgraph |
affected |
chainguard |
dgraph |
— |
| dgraph |
affected |
wolfi |
dgraph |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| falco |
affected |
chainguard |
falco |
— |
| falco |
affected |
wolfi |
falco |
— |
| falcoctl-fips |
affected |
chainguard |
falcoctl-fips |
— |
| flux-source-controller-0 |
affected |
chainguard |
flux-source-controller-0 |
— |
| flux-source-controller-0.37 |
affected |
chainguard |
flux-source-controller-0.37 |
— |
| gatekeeper-fips-3.14 |
affected |
chainguard |
gatekeeper-fips-3.14 |
— |
| goreleaser-1.18 |
affected |
chainguard |
goreleaser-1.18 |
— |
| goreleaser-1.18 |
affected |
wolfi |
goreleaser-1.18 |
— |
| grafana-7 |
affected |
chainguard |
grafana-7 |
— |
| grafana-8 |
affected |
chainguard |
grafana-8 |
— |
| grafana-9.3 |
affected |
chainguard |
grafana-9.3 |
— |
| grpc |
affected |
google.golang.org |
google.golang.org/grpc |
— |
| grpc |
affected |
google.golang.org |
google.golang.org/grpc |
— |
| ipfs |
affected |
chainguard |
ipfs |
— |
| ipfs |
affected |
wolfi |
ipfs |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| kiam |
affected |
chainguard |
kiam |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kube-oidc-proxy |
affected |
chainguard |
kube-oidc-proxy |
— |
| kubernetes-csi-external-attacher-4.3 |
affected |
wolfi |
kubernetes-csi-external-attacher-4.3 |
— |
| kubernetes-csi-external-attacher-4.3 |
affected |
chainguard |
kubernetes-csi-external-attacher-4.3 |
— |
| kubernetes-csi-external-attacher-fips-4.3 |
affected |
chainguard |
kubernetes-csi-external-attacher-fips-4.3 |
— |
| kubernetes-csi-external-resizer-1.8 |
affected |
chainguard |
kubernetes-csi-external-resizer-1.8 |
— |
| kubernetes-csi-external-resizer-fips-1.8 |
affected |
chainguard |
kubernetes-csi-external-resizer-fips-1.8 |
— |
| kubernetes-csi-external-snapshotter-6.0 |
affected |
chainguard |
kubernetes-csi-external-snapshotter-6.0 |
— |
| kubernetes-csi-livenessprobe-2.10 |
affected |
chainguard |
kubernetes-csi-livenessprobe-2.10 |
— |
| kubernetes-csi-livenessprobe-fips |
affected |
chainguard |
kubernetes-csi-livenessprobe-fips |
— |
| kubernetes-csi-livenessprobe-fips-2.10 |
affected |
chainguard |
kubernetes-csi-livenessprobe-fips-2.10 |
— |
| kubernetes-csi-node-driver-registrar-fips-2.8 |
affected |
chainguard |
kubernetes-csi-node-driver-registrar-fips-2.8 |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| metrics-server-fips |
affected |
chainguard |
metrics-server-fips |
— |
| neuvector-agent |
affected |
wolfi |
neuvector-agent |
— |
| neuvector-agent |
affected |
chainguard |
neuvector-agent |
— |
| plutono |
affected |
chainguard |
plutono |
— |
| plutono-fips |
affected |
chainguard |
plutono-fips |
— |
| prometheus-2.38 |
affected |
chainguard |
prometheus-2.38 |
— |
| prometheus-adapter-fips-0.10 |
affected |
chainguard |
prometheus-adapter-fips-0.10 |
— |
| prometheus-blackbox-exporter |
affected |
wolfi |
prometheus-blackbox-exporter |
— |
| prometheus-blackbox-exporter |
affected |
chainguard |
prometheus-blackbox-exporter |
— |
| prometheus-stackdriver-exporter |
affected |
wolfi |
prometheus-stackdriver-exporter |
— |
| prometheus-stackdriver-exporter |
affected |
chainguard |
prometheus-stackdriver-exporter |
— |
| scorecard |
affected |
chainguard |
scorecard |
— |
| scorecard |
affected |
wolfi |
scorecard |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| smarter-device-manager-fips |
affected |
chainguard |
smarter-device-manager-fips |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
| src |
affected |
wolfi |
src |
— |
| src |
affected |
chainguard |
src |
— |
| terraform-fips-1.5 |
affected |
chainguard |
terraform-fips-1.5 |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| timestamp-authority-fips |
affected |
chainguard |
timestamp-authority-fips |
— |
| up |
affected |
wolfi |
up |
— |
| up |
affected |
chainguard |
up |
— |
| vault-csi-provider |
affected |
wolfi |
vault-csi-provider |
— |
| vault-csi-provider |
affected |
chainguard |
vault-csi-provider |
— |
| volcano |
affected |
chainguard |
volcano |
— |
| volcano-fips |
affected |
chainguard |
volcano-fips |
— |
| volume-modifier-for-k8s-fips |
affected |
chainguard |
volume-modifier-for-k8s-fips |
— |
Open SourceAll remaining2023-10-20
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |