Google Security Advisories · October 2023 — Google Security Advisories
660 advisories 377 CVEs 40 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2023-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 40 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

RHSA-2023:5009

Open SourceExploitedCISA KEV listedHIGH2023-10-31

Red Hat Security Advisory: OpenShift Container Platform 4.14.0 security update

Affected products

ProductStatusVendorPackageEcosystem
afterburn affected Red Hat:openshift:4.14::el9 afterburn
afterburn-debuginfo affected Red Hat:openshift:4.14::el9 afterburn-debuginfo
afterburn-dracut affected Red Hat:openshift:4.14::el9 afterburn-dracut
bpftool affected Red Hat:openshift:4.14::el9 bpftool
bpftool-debuginfo affected Red Hat:openshift:4.14::el9 bpftool-debuginfo
buildah affected Red Hat:openshift:4.14::el8 buildah
buildah affected Red Hat:openshift:4.14::el9 buildah
buildah-debuginfo affected Red Hat:openshift:4.14::el9 buildah-debuginfo
buildah-debuginfo affected Red Hat:openshift:4.14::el8 buildah-debuginfo
buildah-debugsource affected Red Hat:openshift:4.14::el9 buildah-debugsource
buildah-debugsource affected Red Hat:openshift:4.14::el8 buildah-debugsource
buildah-tests affected Red Hat:openshift:4.14::el8 buildah-tests
buildah-tests affected Red Hat:openshift:4.14::el9 buildah-tests
buildah-tests-debuginfo affected Red Hat:openshift:4.14::el8 buildah-tests-debuginfo
buildah-tests-debuginfo affected Red Hat:openshift:4.14::el9 buildah-tests-debuginfo
butane affected Red Hat:openshift:4.14::el8 butane
butane-debuginfo affected Red Hat:openshift:4.14::el8 butane-debuginfo
butane-debugsource affected Red Hat:openshift:4.14::el8 butane-debugsource
butane-redistributable affected Red Hat:openshift:4.14::el8 butane-redistributable
catch affected Red Hat:openshift:4.14::el9 catch
catch-debuginfo affected Red Hat:openshift:4.14::el9 catch-debuginfo
catch-debugsource affected Red Hat:openshift:4.14::el9 catch-debugsource
catch-devel affected Red Hat:openshift:4.14::el9 catch-devel
conmon affected Red Hat:openshift:4.14::el8 conmon
conmon affected Red Hat:openshift:4.14::el9 conmon
conmon-debuginfo affected Red Hat:openshift:4.14::el9 conmon-debuginfo
conmon-debuginfo affected Red Hat:openshift:4.14::el8 conmon-debuginfo
conmon-debugsource affected Red Hat:openshift:4.14::el9 conmon-debugsource
conmon-debugsource affected Red Hat:openshift:4.14::el8 conmon-debugsource
containernetworking-plugins affected Red Hat:openshift:4.14::el8 containernetworking-plugins
containernetworking-plugins-debuginfo affected Red Hat:openshift:4.14::el8 containernetworking-plugins-debuginfo
containernetworking-plugins-debugsource affected Red Hat:openshift:4.14::el8 containernetworking-plugins-debugsource
containers-common affected Red Hat:openshift:4.14::el8 containers-common
container-selinux affected Red Hat:openshift:4.14::el8 container-selinux
container-selinux affected Red Hat:openshift:4.14::el9 container-selinux
coreos-installer affected Red Hat:openshift:4.14::el9 coreos-installer
coreos-installer affected Red Hat:openshift:4.14::el8 coreos-installer
coreos-installer-bootinfra affected Red Hat:openshift:4.14::el8 coreos-installer-bootinfra
coreos-installer-bootinfra affected Red Hat:openshift:4.14::el9 coreos-installer-bootinfra
coreos-installer-bootinfra-debuginfo affected Red Hat:openshift:4.14::el9 coreos-installer-bootinfra-debuginfo
coreos-installer-bootinfra-debuginfo affected Red Hat:openshift:4.14::el8 coreos-installer-bootinfra-debuginfo
coreos-installer-debuginfo affected Red Hat:openshift:4.14::el8 coreos-installer-debuginfo
coreos-installer-debuginfo affected Red Hat:openshift:4.14::el9 coreos-installer-debuginfo
coreos-installer-debugsource affected Red Hat:openshift:4.14::el8 coreos-installer-debugsource
coreos-installer-debugsource affected Red Hat:openshift:4.14::el9 coreos-installer-debugsource
coreos-installer-dracut affected Red Hat:openshift:4.14::el9 coreos-installer-dracut
coreos-installer-dracut affected Red Hat:openshift:4.14::el8 coreos-installer-dracut
cri-o affected Red Hat:openshift:4.14::el8 cri-o
cri-o affected Red Hat:openshift:4.14::el9 cri-o
cri-o-debuginfo affected Red Hat:openshift:4.14::el8 cri-o-debuginfo
cri-o-debuginfo affected Red Hat:openshift:4.14::el9 cri-o-debuginfo
cri-o-debugsource affected Red Hat:openshift:4.14::el8 cri-o-debugsource
cri-o-debugsource affected Red Hat:openshift:4.14::el9 cri-o-debugsource
cri-tools affected Red Hat:openshift:4.14::el9 cri-tools
cri-tools affected Red Hat:openshift:4.14::el8 cri-tools
cri-tools-debuginfo affected Red Hat:openshift:4.14::el8 cri-tools-debuginfo
cri-tools-debuginfo affected Red Hat:openshift:4.14::el9 cri-tools-debuginfo
cri-tools-debugsource affected Red Hat:openshift:4.14::el8 cri-tools-debugsource
cri-tools-debugsource affected Red Hat:openshift:4.14::el9 cri-tools-debugsource
crun affected Red Hat:openshift:4.14::el9 crun
crun affected Red Hat:openshift:4.14::el8 crun
crun-debuginfo affected Red Hat:openshift:4.14::el8 crun-debuginfo
crun-debuginfo affected Red Hat:openshift:4.14::el9 crun-debuginfo
crun-debugsource affected Red Hat:openshift:4.14::el9 crun-debugsource
crun-debugsource affected Red Hat:openshift:4.14::el8 crun-debugsource
crun-wasm affected Red Hat:openshift:4.14::el8 crun-wasm
crun-wasm affected Red Hat:openshift:4.14::el9 crun-wasm
crun-wasm-debuginfo affected Red Hat:openshift:4.14::el9 crun-wasm-debuginfo
crun-wasm-debugsource affected Red Hat:openshift:4.14::el9 crun-wasm-debugsource
fmt affected Red Hat:openshift:4.14::el9 fmt
fmt-debuginfo affected Red Hat:openshift:4.14::el9 fmt-debuginfo
fmt-debugsource affected Red Hat:openshift:4.14::el9 fmt-debugsource
fmt-devel affected Red Hat:openshift:4.14::el9 fmt-devel
gmock affected Red Hat:openshift:4.14::el9 gmock
gmock-debuginfo affected Red Hat:openshift:4.14::el9 gmock-debuginfo
gmock-devel affected Red Hat:openshift:4.14::el9 gmock-devel
golang-github-prometheus-promu affected Red Hat:openshift:4.14::el8 golang-github-prometheus-promu
google-benchmark affected Red Hat:openshift:4.14::el9 google-benchmark
google-benchmark-debuginfo affected Red Hat:openshift:4.14::el9 google-benchmark-debuginfo
google-benchmark-debugsource affected Red Hat:openshift:4.14::el9 google-benchmark-debugsource
google-benchmark-devel affected Red Hat:openshift:4.14::el9 google-benchmark-devel
google-benchmark-doc affected Red Hat:openshift:4.14::el9 google-benchmark-doc
gtest affected Red Hat:openshift:4.14::el9 gtest
gtest-debuginfo affected Red Hat:openshift:4.14::el9 gtest-debuginfo
gtest-debugsource affected Red Hat:openshift:4.14::el9 gtest-debugsource
gtest-devel affected Red Hat:openshift:4.14::el9 gtest-devel
haproxy affected Red Hat:openshift:4.14::el8 haproxy
haproxy26 affected Red Hat:openshift:4.14::el8 haproxy26
haproxy26-debuginfo affected Red Hat:openshift:4.14::el8 haproxy26-debuginfo
haproxy-debugsource affected Red Hat:openshift:4.14::el8 haproxy-debugsource
ignition affected Red Hat:openshift:4.14::el9 ignition
ignition-debuginfo affected Red Hat:openshift:4.14::el9 ignition-debuginfo
ignition-debugsource affected Red Hat:openshift:4.14::el9 ignition-debugsource
ignition-validate affected Red Hat:openshift:4.14::el9 ignition-validate
ignition-validate-debuginfo affected Red Hat:openshift:4.14::el9 ignition-validate-debuginfo
kata-containers affected Red Hat:openshift:4.14::el9 kata-containers
kernel affected Red Hat:openshift:4.14::el9 kernel
kernel-64k affected Red Hat:openshift:4.14::el9 kernel-64k
kernel-64k-core affected Red Hat:openshift:4.14::el9 kernel-64k-core
kernel-64k-debug affected Red Hat:openshift:4.14::el9 kernel-64k-debug
kernel-64k-debug-core affected Red Hat:openshift:4.14::el9 kernel-64k-debug-core
kernel-64k-debug-debuginfo affected Red Hat:openshift:4.14::el9 kernel-64k-debug-debuginfo
kernel-64k-debug-devel affected Red Hat:openshift:4.14::el9 kernel-64k-debug-devel
kernel-64k-debug-devel-matched affected Red Hat:openshift:4.14::el9 kernel-64k-debug-devel-matched
kernel-64k-debuginfo affected Red Hat:openshift:4.14::el9 kernel-64k-debuginfo
kernel-64k-debug-modules affected Red Hat:openshift:4.14::el9 kernel-64k-debug-modules
kernel-64k-debug-modules-core affected Red Hat:openshift:4.14::el9 kernel-64k-debug-modules-core
kernel-64k-debug-modules-extra affected Red Hat:openshift:4.14::el9 kernel-64k-debug-modules-extra
kernel-64k-debug-modules-internal affected Red Hat:openshift:4.14::el9 kernel-64k-debug-modules-internal
kernel-64k-debug-modules-partner affected Red Hat:openshift:4.14::el9 kernel-64k-debug-modules-partner
kernel-64k-devel affected Red Hat:openshift:4.14::el9 kernel-64k-devel
kernel-64k-devel-matched affected Red Hat:openshift:4.14::el9 kernel-64k-devel-matched
kernel-64k-modules affected Red Hat:openshift:4.14::el9 kernel-64k-modules
kernel-64k-modules-core affected Red Hat:openshift:4.14::el9 kernel-64k-modules-core
kernel-64k-modules-extra affected Red Hat:openshift:4.14::el9 kernel-64k-modules-extra
kernel-64k-modules-internal affected Red Hat:openshift:4.14::el9 kernel-64k-modules-internal
kernel-64k-modules-partner affected Red Hat:openshift:4.14::el9 kernel-64k-modules-partner
kernel-abi-stablelists affected Red Hat:openshift:4.14::el9 kernel-abi-stablelists
kernel-core affected Red Hat:openshift:4.14::el9 kernel-core
kernel-debug affected Red Hat:openshift:4.14::el9 kernel-debug
kernel-debug-core affected Red Hat:openshift:4.14::el9 kernel-debug-core
kernel-debug-debuginfo affected Red Hat:openshift:4.14::el9 kernel-debug-debuginfo
kernel-debug-devel affected Red Hat:openshift:4.14::el9 kernel-debug-devel
kernel-debug-devel-matched affected Red Hat:openshift:4.14::el9 kernel-debug-devel-matched
kernel-debuginfo affected Red Hat:openshift:4.14::el9 kernel-debuginfo
kernel-debuginfo-common-aarch64 affected Red Hat:openshift:4.14::el9 kernel-debuginfo-common-aarch64
kernel-debuginfo-common-ppc64le affected Red Hat:openshift:4.14::el9 kernel-debuginfo-common-ppc64le
kernel-debuginfo-common-s390x affected Red Hat:openshift:4.14::el9 kernel-debuginfo-common-s390x
kernel-debuginfo-common-x86_64 affected Red Hat:openshift:4.14::el9 kernel-debuginfo-common-x86_64
kernel-debug-modules affected Red Hat:openshift:4.14::el9 kernel-debug-modules
kernel-debug-modules-core affected Red Hat:openshift:4.14::el9 kernel-debug-modules-core
kernel-debug-modules-extra affected Red Hat:openshift:4.14::el9 kernel-debug-modules-extra
kernel-debug-modules-internal affected Red Hat:openshift:4.14::el9 kernel-debug-modules-internal
kernel-debug-modules-partner affected Red Hat:openshift:4.14::el9 kernel-debug-modules-partner
kernel-debug-uki-virt affected Red Hat:openshift:4.14::el9 kernel-debug-uki-virt
kernel-devel affected Red Hat:openshift:4.14::el9 kernel-devel
kernel-devel-matched affected Red Hat:openshift:4.14::el9 kernel-devel-matched
kernel-doc affected Red Hat:openshift:4.14::el9 kernel-doc
kernel-ipaclones-internal affected Red Hat:openshift:4.14::el9 kernel-ipaclones-internal
kernel-modules affected Red Hat:openshift:4.14::el9 kernel-modules
kernel-modules-core affected Red Hat:openshift:4.14::el9 kernel-modules-core
kernel-modules-extra affected Red Hat:openshift:4.14::el9 kernel-modules-extra
kernel-modules-internal affected Red Hat:openshift:4.14::el9 kernel-modules-internal
kernel-modules-partner affected Red Hat:openshift:4.14::el9 kernel-modules-partner
kernel-rt affected Red Hat:openshift:4.14::el9 kernel-rt
kernel-rt-core affected Red Hat:openshift:4.14::el9 kernel-rt-core
kernel-rt-debug affected Red Hat:openshift:4.14::el9 kernel-rt-debug
kernel-rt-debug-core affected Red Hat:openshift:4.14::el9 kernel-rt-debug-core
kernel-rt-debug-debuginfo affected Red Hat:openshift:4.14::el9 kernel-rt-debug-debuginfo
kernel-rt-debug-devel affected Red Hat:openshift:4.14::el9 kernel-rt-debug-devel
kernel-rt-debug-devel-matched affected Red Hat:openshift:4.14::el9 kernel-rt-debug-devel-matched
kernel-rt-debuginfo affected Red Hat:openshift:4.14::el9 kernel-rt-debuginfo
kernel-rt-debuginfo-common-x86_64 affected Red Hat:openshift:4.14::el9 kernel-rt-debuginfo-common-x86_64
kernel-rt-debug-kvm affected Red Hat:openshift:4.14::el9 kernel-rt-debug-kvm
kernel-rt-debug-modules affected Red Hat:openshift:4.14::el9 kernel-rt-debug-modules
kernel-rt-debug-modules-core affected Red Hat:openshift:4.14::el9 kernel-rt-debug-modules-core
kernel-rt-debug-modules-extra affected Red Hat:openshift:4.14::el9 kernel-rt-debug-modules-extra
kernel-rt-debug-modules-internal affected Red Hat:openshift:4.14::el9 kernel-rt-debug-modules-internal
kernel-rt-debug-modules-partner affected Red Hat:openshift:4.14::el9 kernel-rt-debug-modules-partner
kernel-rt-devel affected Red Hat:openshift:4.14::el9 kernel-rt-devel
kernel-rt-devel-matched affected Red Hat:openshift:4.14::el9 kernel-rt-devel-matched
kernel-rt-kvm affected Red Hat:openshift:4.14::el9 kernel-rt-kvm
kernel-rt-modules affected Red Hat:openshift:4.14::el9 kernel-rt-modules
kernel-rt-modules-core affected Red Hat:openshift:4.14::el9 kernel-rt-modules-core
kernel-rt-modules-extra affected Red Hat:openshift:4.14::el9 kernel-rt-modules-extra
kernel-rt-modules-internal affected Red Hat:openshift:4.14::el9 kernel-rt-modules-internal
kernel-rt-modules-partner affected Red Hat:openshift:4.14::el9 kernel-rt-modules-partner
kernel-rt-selftests-internal affected Red Hat:openshift:4.14::el9 kernel-rt-selftests-internal
kernel-selftests-internal affected Red Hat:openshift:4.14::el9 kernel-selftests-internal
kernel-tools affected Red Hat:openshift:4.14::el9 kernel-tools
kernel-tools-debuginfo affected Red Hat:openshift:4.14::el9 kernel-tools-debuginfo
kernel-tools-libs affected Red Hat:openshift:4.14::el9 kernel-tools-libs
kernel-tools-libs-devel affected Red Hat:openshift:4.14::el9 kernel-tools-libs-devel
kernel-uki-virt affected Red Hat:openshift:4.14::el9 kernel-uki-virt
kernel-zfcpdump affected Red Hat:openshift:4.14::el9 kernel-zfcpdump
kernel-zfcpdump-core affected Red Hat:openshift:4.14::el9 kernel-zfcpdump-core
kernel-zfcpdump-debuginfo affected Red Hat:openshift:4.14::el9 kernel-zfcpdump-debuginfo
kernel-zfcpdump-devel affected Red Hat:openshift:4.14::el9 kernel-zfcpdump-devel
kernel-zfcpdump-devel-matched affected Red Hat:openshift:4.14::el9 kernel-zfcpdump-devel-matched
kernel-zfcpdump-modules affected Red Hat:openshift:4.14::el9 kernel-zfcpdump-modules
kernel-zfcpdump-modules-core affected Red Hat:openshift:4.14::el9 kernel-zfcpdump-modules-core
kernel-zfcpdump-modules-extra affected Red Hat:openshift:4.14::el9 kernel-zfcpdump-modules-extra
kernel-zfcpdump-modules-internal affected Red Hat:openshift:4.14::el9 kernel-zfcpdump-modules-internal
kernel-zfcpdump-modules-partner affected Red Hat:openshift:4.14::el9 kernel-zfcpdump-modules-partner
nmstate affected Red Hat:openshift:4.14::el8 nmstate
nmstate-debuginfo affected Red Hat:openshift:4.14::el8 nmstate-debuginfo
nmstate-debugsource affected Red Hat:openshift:4.14::el8 nmstate-debugsource
nmstate-devel affected Red Hat:openshift:4.14::el8 nmstate-devel
nmstate-libs affected Red Hat:openshift:4.14::el8 nmstate-libs
nmstate-libs-debuginfo affected Red Hat:openshift:4.14::el8 nmstate-libs-debuginfo
nmstate-static affected Red Hat:openshift:4.14::el8 nmstate-static
openshift affected Red Hat:openshift:4.14::el8 openshift
openshift affected Red Hat:openshift:4.14::el9 openshift
openshift4-aws-iso affected Red Hat:openshift:4.14::el8 openshift4-aws-iso
openshift-ansible affected Red Hat:openshift:4.14::el8 openshift-ansible
openshift-ansible affected Red Hat:openshift:4.14::el9 openshift-ansible
openshift-ansible-test affected Red Hat:openshift:4.14::el9 openshift-ansible-test
openshift-ansible-test affected Red Hat:openshift:4.14::el8 openshift-ansible-test
openshift-clients affected Red Hat:openshift:4.14::el9 openshift-clients
openshift-clients affected Red Hat:openshift:4.14::el8 openshift-clients
openshift-clients-redistributable affected Red Hat:openshift:4.14::el9 openshift-clients-redistributable
openshift-clients-redistributable affected Red Hat:openshift:4.14::el8 openshift-clients-redistributable
openshift-hyperkube affected Red Hat:openshift:4.14::el9 openshift-hyperkube
openshift-hyperkube affected Red Hat:openshift:4.14::el8 openshift-hyperkube
openshift-kuryr affected Red Hat:openshift:4.14::el8 openshift-kuryr
openshift-kuryr-cni affected Red Hat:openshift:4.14::el8 openshift-kuryr-cni
openshift-kuryr-common affected Red Hat:openshift:4.14::el8 openshift-kuryr-common
openshift-kuryr-controller affected Red Hat:openshift:4.14::el8 openshift-kuryr-controller
openshift-prometheus-promu affected Red Hat:openshift:4.14::el8 openshift-prometheus-promu
openstack-ironic affected Red Hat:openshift_ironic:4.14::el9 openstack-ironic
openstack-ironic-api affected Red Hat:openshift_ironic:4.14::el9 openstack-ironic-api
openstack-ironic-common affected Red Hat:openshift_ironic:4.14::el9 openstack-ironic-common
openstack-ironic-conductor affected Red Hat:openshift_ironic:4.14::el9 openstack-ironic-conductor
openstack-ironic-dnsmasq-tftp-server affected Red Hat:openshift_ironic:4.14::el9 openstack-ironic-dnsmasq-tftp-server
openstack-ironic-inspector affected Red Hat:openshift_ironic:4.14::el9 openstack-ironic-inspector
openstack-ironic-inspector-api affected Red Hat:openshift_ironic:4.14::el9 openstack-ironic-inspector-api
openstack-ironic-inspector-conductor affected Red Hat:openshift_ironic:4.14::el9 openstack-ironic-inspector-conductor
openstack-ironic-inspector-dnsmasq affected Red Hat:openshift_ironic:4.14::el9 openstack-ironic-inspector-dnsmasq
openstack-ironic-python-agent affected Red Hat:openshift_ironic:4.14::el9 openstack-ironic-python-agent
ovn23.09 affected Red Hat:openshift:4.14::el9 ovn23.09
ovn23.09-central affected Red Hat:openshift:4.14::el9 ovn23.09-central
ovn23.09-central-debuginfo affected Red Hat:openshift:4.14::el9 ovn23.09-central-debuginfo
ovn23.09-debuginfo affected Red Hat:openshift:4.14::el9 ovn23.09-debuginfo
ovn23.09-debugsource affected Red Hat:openshift:4.14::el9 ovn23.09-debugsource
ovn23.09-host affected Red Hat:openshift:4.14::el9 ovn23.09-host
ovn23.09-host-debuginfo affected Red Hat:openshift:4.14::el9 ovn23.09-host-debuginfo
ovn23.09-vtep affected Red Hat:openshift:4.14::el9 ovn23.09-vtep
ovn23.09-vtep-debuginfo affected Red Hat:openshift:4.14::el9 ovn23.09-vtep-debuginfo
perf affected Red Hat:openshift:4.14::el9 perf
perf-debuginfo affected Red Hat:openshift:4.14::el9 perf-debuginfo
podman affected Red Hat:openshift:4.14::el8 podman
podman affected Red Hat:openshift:4.14::el9 podman
podman-catatonit affected Red Hat:openshift:4.14::el8 podman-catatonit
podman-catatonit-debuginfo affected Red Hat:openshift:4.14::el8 podman-catatonit-debuginfo
podman-debuginfo affected Red Hat:openshift:4.14::el8 podman-debuginfo
podman-debuginfo affected Red Hat:openshift:4.14::el9 podman-debuginfo
podman-debugsource affected Red Hat:openshift:4.14::el9 podman-debugsource
podman-debugsource affected Red Hat:openshift:4.14::el8 podman-debugsource
podman-docker affected Red Hat:openshift:4.14::el9 podman-docker
podman-docker affected Red Hat:openshift:4.14::el8 podman-docker
podman-gvproxy affected Red Hat:openshift:4.14::el9 podman-gvproxy
podman-gvproxy affected Red Hat:openshift:4.14::el8 podman-gvproxy
podman-gvproxy-debuginfo affected Red Hat:openshift:4.14::el8 podman-gvproxy-debuginfo
podman-gvproxy-debuginfo affected Red Hat:openshift:4.14::el9 podman-gvproxy-debuginfo
podman-plugins affected Red Hat:openshift:4.14::el9 podman-plugins
podman-plugins affected Red Hat:openshift:4.14::el8 podman-plugins
podman-plugins-debuginfo affected Red Hat:openshift:4.14::el9 podman-plugins-debuginfo
podman-plugins-debuginfo affected Red Hat:openshift:4.14::el8 podman-plugins-debuginfo
podman-remote affected Red Hat:openshift:4.14::el9 podman-remote
podman-remote affected Red Hat:openshift:4.14::el8 podman-remote
podman-remote-debuginfo affected Red Hat:openshift:4.14::el8 podman-remote-debuginfo
podman-remote-debuginfo affected Red Hat:openshift:4.14::el9 podman-remote-debuginfo
podman-tests affected Red Hat:openshift:4.14::el9 podman-tests
podman-tests affected Red Hat:openshift:4.14::el8 podman-tests
python3-automaton affected Red Hat:openshift_ironic:4.14::el9 python3-automaton
python3-cinderclient affected Red Hat:openshift_ironic:4.14::el9 python3-cinderclient
python3-cliff affected Red Hat:openshift_ironic:4.14::el9 python3-cliff
python3-cliff-tests affected Red Hat:openshift_ironic:4.14::el9 python3-cliff-tests
python3-debtcollector affected Red Hat:openshift_ironic:4.14::el9 python3-debtcollector
python3-decorator affected Red Hat:openshift_ironic:4.14::el9 python3-decorator
python3-dracclient affected Red Hat:openshift_ironic:4.14::el9 python3-dracclient
python3-fixtures affected Red Hat:openshift_ironic:4.14::el9 python3-fixtures
python3-futurist affected Red Hat:openshift_ironic:4.14::el9 python3-futurist
python3-glanceclient affected Red Hat:openshift_ironic:4.14::el9 python3-glanceclient
python3-hardware affected Red Hat:openshift_ironic:4.14::el9 python3-hardware
python3-hardware-detect affected Red Hat:openshift_ironic:4.14::el9 python3-hardware-detect
python3-ironic-inspector-tests affected Red Hat:openshift_ironic:4.14::el9 python3-ironic-inspector-tests
python3-ironic-lib affected Red Hat:openshift_ironic:4.14::el9 python3-ironic-lib
python3-ironic-prometheus-exporter affected Red Hat:openshift_ironic:4.14::el9 python3-ironic-prometheus-exporter
python3-ironic-python-agent affected Red Hat:openshift_ironic:4.14::el9 python3-ironic-python-agent
python3-ironic-python-agent-tests affected Red Hat:openshift_ironic:4.14::el9 python3-ironic-python-agent-tests
python3-ironic-tests affected Red Hat:openshift_ironic:4.14::el9 python3-ironic-tests
python3-keystoneauth1 affected Red Hat:openshift_ironic:4.14::el9 python3-keystoneauth1
python3-keystoneclient affected Red Hat:openshift_ironic:4.14::el9 python3-keystoneclient
python3-keystoneclient-tests affected Red Hat:openshift_ironic:4.14::el9 python3-keystoneclient-tests
python3-keystonemiddleware affected Red Hat:openshift_ironic:4.14::el9 python3-keystonemiddleware
python3-kuryr-kubernetes affected Red Hat:openshift:4.14::el8 python3-kuryr-kubernetes
python3-libnmstate affected Red Hat:openshift:4.14::el8 python3-libnmstate
python3-openstacksdk affected Red Hat:openshift_ironic:4.14::el9 python3-openstacksdk
python3-openstacksdk-tests affected Red Hat:openshift_ironic:4.14::el9 python3-openstacksdk-tests
python3-osc-lib affected Red Hat:openshift_ironic:4.14::el9 python3-osc-lib
python3-osc-lib-tests affected Red Hat:openshift_ironic:4.14::el9 python3-osc-lib-tests
python3-oslo-cache affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-cache
python3-oslo-cache-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-cache-tests
python3-oslo-concurrency affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-concurrency
python3-oslo-concurrency-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-concurrency-tests
python3-oslo-config affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-config
python3-oslo-context affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-context
python3-oslo-context-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-context-tests
python3-oslo-db affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-db
python3-oslo-db-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-db-tests
python3-oslo-i18n affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-i18n
python3-oslo-log affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-log
python3-oslo-log-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-log-tests
python3-oslo-messaging affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-messaging
python3-oslo-messaging-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-messaging-tests
python3-oslo-middleware affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-middleware
python3-oslo-middleware-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-middleware-tests
python3-oslo-policy affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-policy
python3-oslo-policy-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-policy-tests
python3-oslo-rootwrap affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-rootwrap
python3-oslo-rootwrap-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-rootwrap-tests
python3-oslo-serialization affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-serialization
python3-oslo-serialization-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-serialization-tests
python3-oslo-service affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-service
python3-oslo-service-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-service-tests
python3-oslo-upgradecheck affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-upgradecheck
python3-oslo-utils affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-utils
python3-oslo-utils-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-utils-tests
python3-oslo-versionedobjects affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-versionedobjects
python3-oslo-versionedobjects-tests affected Red Hat:openshift_ironic:4.14::el9 python3-oslo-versionedobjects-tests
python3-osprofiler affected Red Hat:openshift_ironic:4.14::el9 python3-osprofiler
python3-os-service-types affected Red Hat:openshift_ironic:4.14::el9 python3-os-service-types
python3-os-traits affected Red Hat:openshift_ironic:4.14::el9 python3-os-traits
python3-os-traits-tests affected Red Hat:openshift_ironic:4.14::el9 python3-os-traits-tests
python3-pbr affected Red Hat:openshift_ironic:4.14::el9 python3-pbr
python3-perf affected Red Hat:openshift:4.14::el9 python3-perf
python3-perf-debuginfo affected Red Hat:openshift:4.14::el9 python3-perf-debuginfo
python3-proliantutils affected Red Hat:openshift_ironic:4.14::el9 python3-proliantutils
python3-pycadf affected Red Hat:openshift_ironic:4.14::el9 python3-pycadf
python3-requestsexceptions affected Red Hat:openshift_ironic:4.14::el9 python3-requestsexceptions
python3-scciclient affected Red Hat:openshift_ironic:4.14::el9 python3-scciclient
python3-stevedore affected Red Hat:openshift_ironic:4.14::el9 python3-stevedore
python3-sushy affected Red Hat:openshift_ironic:4.14::el9 python3-sushy
python3-sushy-oem-idrac affected Red Hat:openshift_ironic:4.14::el9 python3-sushy-oem-idrac
python3-sushy-oem-idrac-tests affected Red Hat:openshift_ironic:4.14::el9 python3-sushy-oem-idrac-tests
python3-sushy-tests affected Red Hat:openshift_ironic:4.14::el9 python3-sushy-tests
python3-swiftclient affected Red Hat:openshift_ironic:4.14::el9 python3-swiftclient
python3-tenacity affected Red Hat:openshift_ironic:4.14::el9 python3-tenacity
python3-tooz affected Red Hat:openshift_ironic:4.14::el9 python3-tooz
python3-wrapt affected Red Hat:openshift_ironic:4.14::el9 python3-wrapt
python3-wrapt-debuginfo affected Red Hat:openshift_ironic:4.14::el9 python3-wrapt-debuginfo
python-automaton affected Red Hat:openshift_ironic:4.14::el9 python-automaton
python-cinderclient affected Red Hat:openshift_ironic:4.14::el9 python-cinderclient
python-cliff affected Red Hat:openshift_ironic:4.14::el9 python-cliff
python-debtcollector affected Red Hat:openshift_ironic:4.14::el9 python-debtcollector
python-decorator affected Red Hat:openshift_ironic:4.14::el9 python-decorator
python-dracclient affected Red Hat:openshift_ironic:4.14::el9 python-dracclient
python-fixtures affected Red Hat:openshift_ironic:4.14::el9 python-fixtures
python-futurist affected Red Hat:openshift_ironic:4.14::el9 python-futurist
python-glanceclient affected Red Hat:openshift_ironic:4.14::el9 python-glanceclient
python-hardware affected Red Hat:openshift_ironic:4.14::el9 python-hardware
python-ironic-lib affected Red Hat:openshift_ironic:4.14::el9 python-ironic-lib
python-ironic-prometheus-exporter affected Red Hat:openshift_ironic:4.14::el9 python-ironic-prometheus-exporter
python-keystoneauth1 affected Red Hat:openshift_ironic:4.14::el9 python-keystoneauth1
python-keystoneclient affected Red Hat:openshift_ironic:4.14::el9 python-keystoneclient
python-keystonemiddleware affected Red Hat:openshift_ironic:4.14::el9 python-keystonemiddleware
python-openstacksdk affected Red Hat:openshift_ironic:4.14::el9 python-openstacksdk
python-osc-lib affected Red Hat:openshift_ironic:4.14::el9 python-osc-lib
python-oslo-cache affected Red Hat:openshift_ironic:4.14::el9 python-oslo-cache
python-oslo-cache-lang affected Red Hat:openshift_ironic:4.14::el9 python-oslo-cache-lang
python-oslo-concurrency affected Red Hat:openshift_ironic:4.14::el9 python-oslo-concurrency
python-oslo-concurrency-lang affected Red Hat:openshift_ironic:4.14::el9 python-oslo-concurrency-lang
python-oslo-config affected Red Hat:openshift_ironic:4.14::el9 python-oslo-config
python-oslo-context affected Red Hat:openshift_ironic:4.14::el9 python-oslo-context
python-oslo-db affected Red Hat:openshift_ironic:4.14::el9 python-oslo-db
python-oslo-db-lang affected Red Hat:openshift_ironic:4.14::el9 python-oslo-db-lang
python-oslo-i18n affected Red Hat:openshift_ironic:4.14::el9 python-oslo-i18n
python-oslo-i18n-lang affected Red Hat:openshift_ironic:4.14::el9 python-oslo-i18n-lang
python-oslo-log affected Red Hat:openshift_ironic:4.14::el9 python-oslo-log
python-oslo-log-lang affected Red Hat:openshift_ironic:4.14::el9 python-oslo-log-lang
python-oslo-messaging affected Red Hat:openshift_ironic:4.14::el9 python-oslo-messaging
python-oslo-middleware affected Red Hat:openshift_ironic:4.14::el9 python-oslo-middleware
python-oslo-middleware-lang affected Red Hat:openshift_ironic:4.14::el9 python-oslo-middleware-lang
python-oslo-policy affected Red Hat:openshift_ironic:4.14::el9 python-oslo-policy
python-oslo-policy-lang affected Red Hat:openshift_ironic:4.14::el9 python-oslo-policy-lang
python-oslo-rootwrap affected Red Hat:openshift_ironic:4.14::el9 python-oslo-rootwrap
python-oslo-serialization affected Red Hat:openshift_ironic:4.14::el9 python-oslo-serialization
python-oslo-service affected Red Hat:openshift_ironic:4.14::el9 python-oslo-service
python-oslo-upgradecheck affected Red Hat:openshift_ironic:4.14::el9 python-oslo-upgradecheck
python-oslo-utils affected Red Hat:openshift_ironic:4.14::el9 python-oslo-utils
python-oslo-utils-lang affected Red Hat:openshift_ironic:4.14::el9 python-oslo-utils-lang
python-oslo-versionedobjects affected Red Hat:openshift_ironic:4.14::el9 python-oslo-versionedobjects
python-oslo-versionedobjects-lang affected Red Hat:openshift_ironic:4.14::el9 python-oslo-versionedobjects-lang
python-osprofiler affected Red Hat:openshift_ironic:4.14::el9 python-osprofiler
python-os-service-types affected Red Hat:openshift_ironic:4.14::el9 python-os-service-types
python-os-traits affected Red Hat:openshift_ironic:4.14::el9 python-os-traits
python-pbr affected Red Hat:openshift_ironic:4.14::el9 python-pbr
python-proliantutils affected Red Hat:openshift_ironic:4.14::el9 python-proliantutils
python-pycadf affected Red Hat:openshift_ironic:4.14::el9 python-pycadf
python-pycadf-common affected Red Hat:openshift_ironic:4.14::el9 python-pycadf-common
python-requestsexceptions affected Red Hat:openshift_ironic:4.14::el9 python-requestsexceptions
python-scciclient affected Red Hat:openshift_ironic:4.14::el9 python-scciclient
python-stevedore affected Red Hat:openshift_ironic:4.14::el9 python-stevedore
python-sushy affected Red Hat:openshift_ironic:4.14::el9 python-sushy
python-sushy-oem-idrac affected Red Hat:openshift_ironic:4.14::el9 python-sushy-oem-idrac
python-swiftclient affected Red Hat:openshift_ironic:4.14::el9 python-swiftclient
python-tenacity affected Red Hat:openshift_ironic:4.14::el9 python-tenacity
python-tooz affected Red Hat:openshift_ironic:4.14::el9 python-tooz
python-wrapt affected Red Hat:openshift_ironic:4.14::el9 python-wrapt
python-wrapt-debugsource affected Red Hat:openshift_ironic:4.14::el9 python-wrapt-debugsource
python-wrapt-doc affected Red Hat:openshift_ironic:4.14::el9 python-wrapt-doc
rtla affected Red Hat:openshift:4.14::el9 rtla
runc affected Red Hat:openshift:4.14::el9 runc
runc affected Red Hat:openshift:4.14::el8 runc
runc-debuginfo affected Red Hat:openshift:4.14::el8 runc-debuginfo
runc-debuginfo affected Red Hat:openshift:4.14::el9 runc-debuginfo
runc-debugsource affected Red Hat:openshift:4.14::el9 runc-debugsource
runc-debugsource affected Red Hat:openshift:4.14::el8 runc-debugsource
rust-afterburn affected Red Hat:openshift:4.14::el9 rust-afterburn
rust-afterburn-debugsource affected Red Hat:openshift:4.14::el9 rust-afterburn-debugsource
skopeo affected Red Hat:openshift:4.14::el8 skopeo
skopeo affected Red Hat:openshift:4.14::el9 skopeo
skopeo-debuginfo affected Red Hat:openshift:4.14::el9 skopeo-debuginfo
skopeo-debuginfo affected Red Hat:openshift:4.14::el8 skopeo-debuginfo
skopeo-debugsource affected Red Hat:openshift:4.14::el8 skopeo-debugsource
skopeo-debugsource affected Red Hat:openshift:4.14::el9 skopeo-debugsource
skopeo-tests affected Red Hat:openshift:4.14::el8 skopeo-tests
skopeo-tests affected Red Hat:openshift:4.14::el9 skopeo-tests
spdlog affected Red Hat:openshift:4.14::el9 spdlog
spdlog-debuginfo affected Red Hat:openshift:4.14::el9 spdlog-debuginfo
spdlog-debugsource affected Red Hat:openshift:4.14::el9 spdlog-debugsource
spdlog-devel affected Red Hat:openshift:4.14::el9 spdlog-devel
toolbox affected Red Hat:openshift:4.14::el9 toolbox
wasmedge affected Red Hat:openshift:4.14::el9 wasmedge
wasmedge-debuginfo affected Red Hat:openshift:4.14::el9 wasmedge-debuginfo
wasmedge-debugsource affected Red Hat:openshift:4.14::el9 wasmedge-debugsource
wasmedge-devel affected Red Hat:openshift:4.14::el9 wasmedge-devel
wasmedge-rt affected Red Hat:openshift:4.14::el9 wasmedge-rt
wasmedge-rt-debuginfo affected Red Hat:openshift:4.14::el9 wasmedge-rt-debuginfo
Upstream advisory

RLSA-2023:5721

Open SourceExploitedCISA KEV listedNONE2023-10-24

Important: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

RHSA-2023:5965

Open SourceExploitedCISA KEV listedHIGH2023-10-20

Red Hat Security Advisory: Red Hat OpenStack Platform 16.2.5 (collectd-libpod-stats, etcd) security update

Affected products

ProductStatusVendorPackageEcosystem
etcd affected Red Hat:openstack:16.2::el8 etcd
etcd-debuginfo affected Red Hat:openstack:16.2::el8 etcd-debuginfo
etcd-debugsource affected Red Hat:openstack:16.2::el8 etcd-debugsource
python3-octavia-tests-tempest affected Red Hat:openstack:16.2::el8 python3-octavia-tests-tempest
python3-octavia-tests-tempest-golang affected Red Hat:openstack:16.2::el8 python3-octavia-tests-tempest-golang
python3-octavia-tests-tempest-golang-debuginfo affected Red Hat:openstack:16.2::el8 python3-octavia-tests-tempest-golang-debuginfo
python-octavia-tests-tempest affected Red Hat:openstack:16.2::el8 python-octavia-tests-tempest
python-octavia-tests-tempest-debugsource affected Red Hat:openstack:16.2::el8 python-octavia-tests-tempest-debugsource
Upstream advisory

RHSA-2023:5967

Open SourceExploitedCISA KEV listedHIGH2023-10-20

Red Hat Security Advisory: Red Hat OpenStack Platform 16.1.9 (collectd-libpod-stats, etcd) security update

Affected products

ProductStatusVendorPackageEcosystem
collectd-libpod-stats affected Red Hat:openstack:16.1::el8 collectd-libpod-stats
etcd affected Red Hat:openstack:16.1::el8 etcd
etcd-debuginfo affected Red Hat:openstack:16.1::el8 etcd-debuginfo
etcd-debugsource affected Red Hat:openstack:16.1::el8 etcd-debugsource
python3-octavia-tests-tempest affected Red Hat:openstack:16.1::el8 python3-octavia-tests-tempest
python3-octavia-tests-tempest-golang affected Red Hat:openstack:16.1::el8 python3-octavia-tests-tempest-golang
python3-octavia-tests-tempest-golang-debuginfo affected Red Hat:openstack:16.1::el8 python3-octavia-tests-tempest-golang-debuginfo
python-octavia-tests-tempest affected Red Hat:openstack:16.1::el8 python-octavia-tests-tempest
python-octavia-tests-tempest-debugsource affected Red Hat:openstack:16.1::el8 python-octavia-tests-tempest-debugsource
Upstream advisory

RHSA-2023:5969

Open SourceExploitedCISA KEV listedHIGH2023-10-20

Red Hat Security Advisory: Red Hat OpenStack Platform 17.1.1 security update

Affected products

ProductStatusVendorPackageEcosystem
collectd-libpod-stats affected Red Hat:openstack:17.1::el9 collectd-libpod-stats
etcd affected Red Hat:openstack:17.1::el9 etcd
etcd-debuginfo affected Red Hat:openstack:17.1::el9 etcd-debuginfo
etcd-debugsource affected Red Hat:openstack:17.1::el9 etcd-debugsource
python3-octavia-tests-tempest affected Red Hat:openstack:17.1::el9 python3-octavia-tests-tempest
python3-octavia-tests-tempest-golang affected Red Hat:openstack:17.1::el9 python3-octavia-tests-tempest-golang
python3-octavia-tests-tempest-golang-debuginfo affected Red Hat:openstack:17.1::el9 python3-octavia-tests-tempest-golang-debuginfo
python-octavia-tests-tempest affected Red Hat:openstack:17.1::el9 python-octavia-tests-tempest
python-octavia-tests-tempest-debugsource affected Red Hat:openstack:17.1::el9 python-octavia-tests-tempest-debugsource
Upstream advisory

RHSA-2023:5738

Open SourceExploitedCISA KEV listedHIGH2023-10-16

Red Hat Security Advisory: go-toolset and golang security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:9::appstream golang
golang-bin affected Red Hat:enterprise_linux:9::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:9::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:9::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:9::appstream golang-race
golang-src affected Red Hat:enterprise_linux:9::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:9::appstream golang-tests
Upstream advisory

RHSA-2023:5721

Open SourceExploitedCISA KEV listedHIGH2023-10-16

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

RHSA-2023:5719

Open SourceExploitedCISA KEV listedHIGH2023-10-16

Red Hat Security Advisory: go-toolset-1.19 and go-toolset-1.19-golang security update

Affected products

ProductStatusVendorPackageEcosystem
go-toolset-1.19 affected Red Hat:devtools:2023::el7 go-toolset-1.19
go-toolset-1.19-build affected Red Hat:devtools:2023::el7 go-toolset-1.19-build
go-toolset-1.19-golang affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang
go-toolset-1.19-golang-bin affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-bin
go-toolset-1.19-golang-docs affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-docs
go-toolset-1.19-golang-misc affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-misc
go-toolset-1.19-golang-race affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-race
go-toolset-1.19-golang-src affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-src
go-toolset-1.19-golang-tests affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-tests
go-toolset-1.19-runtime affected Red Hat:devtools:2023::el7 go-toolset-1.19-runtime
go-toolset-1.19-scldevel affected Red Hat:devtools:2023::el7 go-toolset-1.19-scldevel
Upstream advisory

ALSA-2023:5721

Open SourceExploitedCISA KEV listedNONE2023-10-16

Important: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected AlmaLinux:8 delve
golang affected AlmaLinux:8 golang
golang-bin affected AlmaLinux:8 golang-bin
golang-docs affected AlmaLinux:8 golang-docs
golang-misc affected AlmaLinux:8 golang-misc
golang-race affected AlmaLinux:8 golang-race
golang-src affected AlmaLinux:8 golang-src
golang-tests affected AlmaLinux:8 golang-tests
go-toolset affected AlmaLinux:8 go-toolset
Upstream advisory

ALSA-2023:5738

Open SourceExploitedCISA KEV listedNONE2023-10-16

Important: go-toolset and golang security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
golang affected AlmaLinux:9 golang
golang-bin affected AlmaLinux:9 golang-bin
golang-docs affected AlmaLinux:9 golang-docs
golang-misc affected AlmaLinux:9 golang-misc
golang-race affected AlmaLinux:9 golang-race
golang-src affected AlmaLinux:9 golang-src
golang-tests affected AlmaLinux:9 golang-tests
go-toolset affected AlmaLinux:9 go-toolset
Upstream advisory

GO-2023-2102

Open SourceExploitedCISA KEV listedCRITICAL2023-10-11

HTTP/2 rapid reset can cause excessive work in net/http

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
amass affected chainguard amass
amass affected wolfi amass
apko affected chainguard apko
apko affected wolfi apko
atlantis affected wolfi atlantis
atlantis affected chainguard atlantis
atlantis-fips affected chainguard atlantis-fips
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults affected chainguard bank-vaults
bank-vaults affected wolfi bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bom affected chainguard bom
bom affected wolfi bom
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
caddy affected chainguard caddy
caddy affected wolfi caddy
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
configmap-reload-fips affected chainguard configmap-reload-fips
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
cosign affected wolfi cosign
cosign affected chainguard cosign
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure affected wolfi crossplane-provider-azure
cue affected wolfi cue
cue affected chainguard cue
dex affected chainguard dex
dex affected wolfi dex
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
dive affected chainguard dive
dive affected wolfi dive
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
flux affected chainguard flux
flux affected wolfi flux
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
frp affected chainguard frp
frp affected wolfi frp
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
git-lfs affected wolfi git-lfs
git-lfs affected chainguard git-lfs
gitness affected wolfi gitness
gitness affected chainguard gitness
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
go-1.20 affected chainguard go-1.20
go-1.20 affected wolfi go-1.20
go-1.21 affected chainguard go-1.21
go-1.21 affected wolfi go-1.21
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
gomplate affected wolfi gomplate
gomplate affected chainguard gomplate
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
haproxy-ingress affected chainguard haproxy-ingress
haproxy-ingress affected wolfi haproxy-ingress
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected wolfi helm-3
helm-3 affected chainguard helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
hey affected wolfi hey
hey affected chainguard hey
hugo affected chainguard hugo
hugo affected wolfi hugo
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k8sgpt-operator affected wolfi k8sgpt-operator
k8sgpt-operator affected chainguard k8sgpt-operator
kaf affected wolfi kaf
kaf affected chainguard kaf
kiam affected chainguard kiam
kind affected chainguard kind
kind affected wolfi kind
kots affected chainguard kots
kots affected wolfi kots
kpt affected wolfi kpt
kpt affected chainguard kpt
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kube-logging-operator affected wolfi kube-logging-operator
kube-logging-operator affected chainguard kube-logging-operator
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-ingress-defaultbackend affected chainguard kubernetes-ingress-defaultbackend
kubernetes-ingress-defaultbackend affected wolfi kubernetes-ingress-defaultbackend
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kube-state-metrics affected wolfi kube-state-metrics
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kubewatch affected chainguard kubewatch
kubewatch affected wolfi kubewatch
mc affected chainguard mc
mc affected wolfi mc
memcached-exporter affected wolfi memcached-exporter
memcached-exporter affected chainguard memcached-exporter
metacontroller affected wolfi metacontroller
metacontroller affected chainguard metacontroller
metrics-server affected chainguard metrics-server
metrics-server affected wolfi metrics-server
metrics-server-fips affected chainguard metrics-server-fips
minio affected chainguard minio
minio affected wolfi minio
nats affected wolfi nats
nats affected chainguard nats
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
nri-prometheus affected wolfi nri-prometheus
nri-prometheus affected chainguard nri-prometheus
oauth2-proxy affected chainguard oauth2-proxy
oauth2-proxy affected wolfi oauth2-proxy
ollama affected chainguard ollama
ollama affected wolfi ollama
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter-fips affected chainguard prometheus-elasticsearch-exporter-fips
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter-fips affected chainguard prometheus-mongodb-exporter-fips
prometheus-mongodb-exporter-fips-0.37 affected chainguard prometheus-mongodb-exporter-fips-0.37
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter-1.5 affected chainguard prometheus-node-exporter-1.5
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-operator affected wolfi prometheus-operator
prometheus-operator affected chainguard prometheus-operator
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-postgres-exporter-fips affected chainguard prometheus-postgres-exporter-fips
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
prometheus-pushgateway-fips-1.4 affected chainguard prometheus-pushgateway-fips-1.4
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter-fips affected chainguard prometheus-statsd-exporter-fips
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-yaml affected chainguard pulumi-language-yaml
pulumi-language-yaml affected wolfi pulumi-language-yaml
rqlite affected wolfi rqlite
rqlite affected chainguard rqlite
runc affected chainguard runc
runc affected wolfi runc
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
src affected chainguard src
src affected wolfi src
stakater-reloader affected chainguard stakater-reloader
stakater-reloader affected wolfi stakater-reloader
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
stdlib affected Go stdlib
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
thanos-operator affected wolfi thanos-operator
thanos-operator affected chainguard thanos-operator
timoni affected chainguard timoni
timoni affected wolfi timoni
tkn affected wolfi tkn
tkn affected chainguard tkn
trillian affected wolfi trillian
trillian affected chainguard trillian
trust-manager affected wolfi trust-manager
trust-manager affected chainguard trust-manager
up affected chainguard up
up affected wolfi up
vault-csi-provider affected chainguard vault-csi-provider
vault-k8s affected wolfi vault-k8s
vault-k8s affected chainguard vault-k8s
vault-k8s-fips affected chainguard vault-k8s-fips
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
weaviate affected wolfi weaviate
weaviate affected chainguard weaviate
wireguard-go affected wolfi wireguard-go
wireguard-go affected chainguard wireguard-go
x/net affected golang.org golang.org/x/net
yq affected wolfi yq
yq affected chainguard yq
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

GHSA-xpw8-rcwv-8f8p

GoogleExploitedCISA KEV listedHIGH2023-10-10

io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset Attack

Affected products

ProductStatusVendorPackageEcosystem
io.netty:netty-codec-http2 affected Maven io.netty:netty-codec-http2
Upstream advisory

GHSA-xpw8-rcwv-8f8p

Open SourceExploitedCISA KEV listedHIGH2023-10-10

io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset Attack

Affected products

ProductStatusVendorPackageEcosystem
cloudwatch-exporter affected wolfi cloudwatch-exporter
cloudwatch-exporter affected chainguard cloudwatch-exporter
docker-selenium-jre-bcfips affected chainguard docker-selenium-jre-bcfips
elasticsearch-8 affected chainguard elasticsearch-8
grpc-java-fips-1.56.0 affected chainguard grpc-java-fips-1.56.0
io.netty:netty-codec-http2 affected Maven io.netty:netty-codec-http2
spark-3.5.0-compat affected chainguard spark-3.5.0-compat
stargate affected chainguard stargate
trino affected wolfi trino
trino affected chainguard trino
wavefront-proxy affected wolfi wavefront-proxy
wavefront-proxy affected chainguard wavefront-proxy
Upstream advisory

GHSA-qppj-fm5r-hxr3

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

HTTP/2 Stream Cancellation Attack

Affected products

ProductStatusVendorPackageEcosystem
apple/swift-nio-http2 affected github.com github.com/apple/swift-nio-http2
com.typesafe.akka:akka-http-core affected Maven com.typesafe.akka:akka-http-core
com.typesafe.akka:akka-http-core_2.11 affected Maven com.typesafe.akka:akka-http-core_2.11
com.typesafe.akka:akka-http-core_2.12 affected Maven com.typesafe.akka:akka-http-core_2.12
com.typesafe.akka:akka-http-core_2.13 affected Maven com.typesafe.akka:akka-http-core_2.13
org.apache.tomcat.embed:tomcat-embed-core affected Maven org.apache.tomcat.embed:tomcat-embed-core
org.apache.tomcat:tomcat-coyote affected Maven org.apache.tomcat:tomcat-coyote
org.eclipse.jetty.http2:http2-common affected Maven org.eclipse.jetty.http2:http2-common
org.eclipse.jetty.http2:http2-server affected Maven org.eclipse.jetty.http2:http2-server
org.eclipse.jetty.http2:jetty-http2-common affected Maven org.eclipse.jetty.http2:jetty-http2-common
org.eclipse.jetty.http2:jetty-http2-server affected Maven org.eclipse.jetty.http2:jetty-http2-server
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-qppj-fm5r-hxr3

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

HTTP/2 Stream Cancellation Attack

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
amass affected chainguard amass
amass affected wolfi amass
apple/swift-nio-http2 affected github.com github.com/apple/swift-nio-http2
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.7 affected wolfi argo-cd-2.7
atlantis affected chainguard atlantis
atlantis affected wolfi atlantis
atlantis-fips affected chainguard atlantis-fips
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-efs-csi-driver-fips-1.6 affected chainguard aws-efs-csi-driver-fips-1.6
aws-load-balancer-controller-2.4.5 affected chainguard aws-load-balancer-controller-2.4.5
bank-vaults-fips affected chainguard bank-vaults-fips
bom affected wolfi bom
bom affected chainguard bom
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
calico affected chainguard calico
calico affected wolfi calico
calico-fips affected chainguard calico-fips
calico-fips-3.25 affected chainguard calico-fips-3.25
certificate-transparency affected wolfi certificate-transparency
certificate-transparency affected chainguard certificate-transparency
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-1.13 affected wolfi cert-manager-1.13
cilium-envoy affected wolfi cilium-envoy
cilium-envoy affected chainguard cilium-envoy
cluster-autoscaler-1.25 affected chainguard cluster-autoscaler-1.25
cluster-autoscaler-1.25 affected wolfi cluster-autoscaler-1.25
cluster-autoscaler-fips-1.25 affected chainguard cluster-autoscaler-fips-1.25
com.typesafe.akka:akka-http-core affected Maven com.typesafe.akka:akka-http-core
com.typesafe.akka:akka-http-core_2.11 affected Maven com.typesafe.akka:akka-http-core_2.11
com.typesafe.akka:akka-http-core_2.12 affected Maven com.typesafe.akka:akka-http-core_2.12
com.typesafe.akka:akka-http-core_2.13 affected Maven com.typesafe.akka:akka-http-core_2.13
configmap-reload-fips affected chainguard configmap-reload-fips
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
conftest affected wolfi conftest
conftest affected chainguard conftest
coredns affected chainguard coredns
coredns affected wolfi coredns
cortex affected wolfi cortex
cortex affected chainguard cortex
cosign affected wolfi cosign
cosign affected chainguard cosign
cue affected wolfi cue
cue affected chainguard cue
dex affected wolfi dex
dex affected chainguard dex
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
dotnet-6 affected chainguard dotnet-6
dotnet-6 affected wolfi dotnet-6
dotnet-7 affected chainguard dotnet-7
dotnet-7 affected wolfi dotnet-7
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
envoy-ratelimit affected wolfi envoy-ratelimit
envoy-ratelimit affected chainguard envoy-ratelimit
external-dns affected wolfi external-dns
external-dns affected chainguard external-dns
external-dns-fips affected chainguard external-dns-fips
external-secrets-0.7 affected chainguard external-secrets-0.7
falco affected wolfi falco
falco affected chainguard falco
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
flux-0 affected chainguard flux-0
flux-0.37 affected chainguard flux-0.37
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller-0 affected chainguard flux-helm-controller-0
flux-helm-controller-0.37 affected chainguard flux-helm-controller-0.37
flux-image-reflector-controller-0 affected chainguard flux-image-reflector-controller-0
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller-0 affected chainguard flux-kustomize-controller-0
flux-kustomize-controller-0.37 affected chainguard flux-kustomize-controller-0.37
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller-0 affected chainguard flux-notification-controller-0
flux-notification-controller-0.37 affected chainguard flux-notification-controller-0.37
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller-0 affected chainguard flux-source-controller-0
flux-source-controller-0.37 affected chainguard flux-source-controller-0.37
frp affected chainguard frp
frp affected wolfi frp
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
gatekeeper-3.12 affected wolfi gatekeeper-3.12
gatekeeper-3.12 affected chainguard gatekeeper-3.12
gatekeeper-3.14 affected chainguard gatekeeper-3.14
gatekeeper-3.14 affected wolfi gatekeeper-3.14
gatekeeper-fips-3.14 affected chainguard gatekeeper-fips-3.14
gitlab-pages affected wolfi gitlab-pages
gitlab-pages affected chainguard gitlab-pages
gitlab-runner affected wolfi gitlab-runner
gitlab-runner affected chainguard gitlab-runner
git-lfs affected wolfi git-lfs
git-lfs affected chainguard git-lfs
gitness affected chainguard gitness
gitness affected wolfi gitness
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
gomplate affected chainguard gomplate
gomplate affected wolfi gomplate
goreleaser-1.18 affected wolfi goreleaser-1.18
goreleaser-1.18 affected chainguard goreleaser-1.18
grafana-7 affected chainguard grafana-7
grafana-9.3 affected chainguard grafana-9.3
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
grype affected chainguard grype
grype affected wolfi grype
haproxy-ingress affected wolfi haproxy-ingress
haproxy-ingress affected chainguard haproxy-ingress
helm affected chainguard helm
helm affected wolfi helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
hey affected chainguard hey
hey affected wolfi hey
hugo affected chainguard hugo
hugo affected wolfi hugo
influxd affected chainguard influxd
influxd affected wolfi influxd
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller-fips affected chainguard ingress-nginx-controller-fips
ipfs affected chainguard ipfs
ipfs affected wolfi ipfs
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
istio-envoy-1.18 affected wolfi istio-envoy-1.18
istio-envoy-1.18 affected chainguard istio-envoy-1.18
istio-envoy-1.19 affected wolfi istio-envoy-1.19
istio-envoy-1.19 affected chainguard istio-envoy-1.19
k3d affected wolfi k3d
k3d affected chainguard k3d
kaf affected chainguard kaf
kaf affected wolfi kaf
karpenter-0.23 affected chainguard karpenter-0.23
keda affected chainguard keda
keda affected wolfi keda
keda-2.10 affected chainguard keda-2.10
keda-2.10 affected wolfi keda-2.10
keda-2.11 affected chainguard keda-2.11
keda-2.11 affected wolfi keda-2.11
kiam affected chainguard kiam
kind affected chainguard kind
kind affected wolfi kind
ko affected wolfi ko
ko affected chainguard ko
kots affected wolfi kots
kots affected chainguard kots
kpt affected chainguard kpt
kpt affected wolfi kpt
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-csi-external-attacher-4.3 affected chainguard kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.3 affected wolfi kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-fips-4.3 affected chainguard kubernetes-csi-external-attacher-fips-4.3
kubernetes-csi-external-resizer-fips-1.8 affected chainguard kubernetes-csi-external-resizer-fips-1.8
kubernetes-csi-external-snapshotter-6.0 affected chainguard kubernetes-csi-external-snapshotter-6.0
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-csi-node-driver-registrar-2.9 affected wolfi kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-2.9 affected chainguard kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-fips-2.8 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.8
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kubewatch affected wolfi kubewatch
kubewatch affected chainguard kubewatch
kyverno affected chainguard kyverno
kyverno affected wolfi kyverno
kyverno-policy-reporter-2.11 affected chainguard kyverno-policy-reporter-2.11
kyverno-policy-reporter-kyverno-plugin-1.5 affected chainguard kyverno-policy-reporter-kyverno-plugin-1.5
kyverno-policy-reporter-ui-1.7 affected chainguard kyverno-policy-reporter-ui-1.7
mc affected wolfi mc
mc affected chainguard mc
memcached-exporter affected chainguard memcached-exporter
memcached-exporter affected wolfi memcached-exporter
metacontroller affected wolfi metacontroller
metacontroller affected chainguard metacontroller
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
minio affected chainguard minio
minio affected wolfi minio
nats affected chainguard nats
nats affected wolfi nats
neuvector-agent affected chainguard neuvector-agent
neuvector-agent affected wolfi neuvector-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
nghttp2 affected wolfi nghttp2
nghttp2 affected chainguard nghttp2
nginx-mainline affected chainguard nginx-mainline
nginx-mainline affected wolfi nginx-mainline
nginx-stable affected chainguard nginx-stable
nginx-stable affected wolfi nginx-stable
nodejs-16 affected wolfi nodejs-16
nodejs-16 affected chainguard nodejs-16
nodejs-18 affected wolfi nodejs-18
nodejs-18 affected chainguard nodejs-18
nodejs-19 affected wolfi nodejs-19
nodejs-19 affected chainguard nodejs-19
nodejs-20 affected wolfi nodejs-20
nodejs-20 affected chainguard nodejs-20
node-problem-detector-0.8 affected wolfi node-problem-detector-0.8
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nri-prometheus affected wolfi nri-prometheus
nri-prometheus affected chainguard nri-prometheus
oauth2-proxy affected chainguard oauth2-proxy
oauth2-proxy affected wolfi oauth2-proxy
ollama affected chainguard ollama
ollama affected wolfi ollama
opentofu affected chainguard opentofu
opentofu affected wolfi opentofu
org.apache.tomcat.embed:tomcat-embed-core affected Maven org.apache.tomcat.embed:tomcat-embed-core
org.apache.tomcat:tomcat-coyote affected Maven org.apache.tomcat:tomcat-coyote
org.eclipse.jetty.http2:http2-common affected Maven org.eclipse.jetty.http2:http2-common
org.eclipse.jetty.http2:http2-server affected Maven org.eclipse.jetty.http2:http2-server
org.eclipse.jetty.http2:jetty-http2-common affected Maven org.eclipse.jetty.http2:jetty-http2-common
org.eclipse.jetty.http2:jetty-http2-server affected Maven org.eclipse.jetty.http2:jetty-http2-server
prometheus affected chainguard prometheus
prometheus affected wolfi prometheus
prometheus-2.38 affected chainguard prometheus-2.38
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-blackbox-exporter affected wolfi prometheus-blackbox-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected wolfi prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-redis-exporter-fips-1.44 affected chainguard prometheus-redis-exporter-fips-1.44
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
pulumi affected chainguard pulumi
pulumi affected wolfi pulumi
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-yaml affected chainguard pulumi-language-yaml
pulumi-language-yaml affected wolfi pulumi-language-yaml
rqlite affected wolfi rqlite
rqlite affected chainguard rqlite
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
skaffold affected wolfi skaffold
skaffold affected chainguard skaffold
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
src affected wolfi src
src affected chainguard src
stakater-reloader affected wolfi stakater-reloader
stakater-reloader affected chainguard stakater-reloader
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
tctl affected chainguard tctl
tctl affected wolfi tctl
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.26 affected wolfi telegraf-1.26
telegraf-1.27 affected wolfi telegraf-1.27
telegraf-1.27 affected chainguard telegraf-1.27
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-provider-aws affected wolfi terraform-provider-aws
terraform-provider-aws affected chainguard terraform-provider-aws
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
thanos-0.31 affected chainguard thanos-0.31
thanos-0.31 affected wolfi thanos-0.31
thanos-0.32 affected chainguard thanos-0.32
thanos-0.32 affected wolfi thanos-0.32
timestamp-authority-fips affected chainguard timestamp-authority-fips
tomcat-10 affected wolfi tomcat-10
tomcat-10 affected chainguard tomcat-10
tomcat-8 affected chainguard tomcat-8
tomcat-8 affected wolfi tomcat-8
tomcat-9 affected chainguard tomcat-9
tomcat-9 affected wolfi tomcat-9
traefik affected wolfi traefik
traefik affected chainguard traefik
up affected chainguard up
up affected wolfi up
vault-csi-provider affected chainguard vault-csi-provider
vault-csi-provider affected wolfi vault-csi-provider
vault-k8s-fips affected chainguard vault-k8s-fips
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
weaviate affected wolfi weaviate
weaviate affected chainguard weaviate
wireguard-go affected wolfi wireguard-go
wireguard-go affected chainguard wireguard-go
x/net affected golang.org golang.org/x/net
Upstream advisory

AZL-31291

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

CVE-2023-44487 affecting package application-gateway-kubernetes-ingress for versions less than 1.4.0-15

Affected products

ProductStatusVendorPackageEcosystem
application-gateway-kubernetes-ingress affected Azure Linux:2 application-gateway-kubernetes-ingress
Upstream advisory

AZL-31519

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

CVE-2023-44487 affecting package golang for versions less than 1.20.10

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-31520

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

CVE-2023-44487 affecting package grpc for versions less than 1.42.0-7

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Azure Linux:2 grpc
Upstream advisory

AZL-31693

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

CVE-2023-44487 affecting package kubernetes for versions less than 1.28.3-1

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:2 kubernetes
Upstream advisory

AZL-34545

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

CVE-2023-44487 affecting package application-gateway-kubernetes-ingress for versions less than 1.4.0-15

Affected products

ProductStatusVendorPackageEcosystem
application-gateway-kubernetes-ingress affected Azure Linux:3 application-gateway-kubernetes-ingress
Upstream advisory

AZL-34771

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

CVE-2023-44487 affecting package grpc for versions less than 1.42.0-7

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Azure Linux:3 grpc
Upstream advisory

AZL-34895

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

CVE-2023-44487 affecting package kubernetes for versions less than 1.28.3-1

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:3 kubernetes
Upstream advisory

AZL-37314

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

CVE-2023-44487 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37404

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

CVE-2023-44487 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

DEBIAN-CVE-2023-44487

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

DEBIAN-CVE-2023-44487

Affected products

ProductStatusVendorPackageEcosystem
dnsdist affected Debian:11 dnsdist
dnsdist affected Debian:12 dnsdist
dnsdist affected Debian:13 dnsdist
dnsdist affected Debian:14 dnsdist
grpc affected Debian:11 grpc
grpc affected Debian:12 grpc
grpc affected Debian:13 grpc
grpc affected Debian:14 grpc
h2o affected Debian:11 h2o
h2o affected Debian:12 h2o
haproxy affected Debian:11 haproxy
haproxy affected Debian:12 haproxy
haproxy affected Debian:13 haproxy
haproxy affected Debian:14 haproxy
jetty9 affected Debian:11 jetty9
jetty9 affected Debian:12 jetty9
jetty9 affected Debian:13 jetty9
jetty9 affected Debian:14 jetty9
netty affected Debian:11 netty
netty affected Debian:12 netty
netty affected Debian:13 netty
netty affected Debian:14 netty
nghttp2 affected Debian:11 nghttp2
nghttp2 affected Debian:12 nghttp2
nghttp2 affected Debian:13 nghttp2
nghttp2 affected Debian:14 nghttp2
nginx affected Debian:12 nginx
nginx affected Debian:13 nginx
nginx affected Debian:14 nginx
nginx affected Debian:11 nginx
tomcat10 affected Debian:13 tomcat10
tomcat10 affected Debian:14 tomcat10
tomcat10 affected Debian:12 tomcat10
tomcat9 affected Debian:12 tomcat9
tomcat9 affected Debian:13 tomcat9
tomcat9 affected Debian:14 tomcat9
tomcat9 affected Debian:11 tomcat9
trafficserver affected Debian:12 trafficserver
trafficserver affected Debian:11 trafficserver
varnish affected Debian:11 varnish
varnish affected Debian:12 varnish
varnish affected Debian:13 varnish
varnish affected Debian:14 varnish
Upstream advisory

BELL-CVE-2023-44487

Open SourceExploitedCISA KEV listedHIGH2023-10-10

BELL-CVE-2023-44487

Affected products

ProductStatusVendorPackageEcosystem
go affected BellSoft Hardened Containers:23 go
go affected BellSoft Hardened Containers:stream go
go affected Alpaquita:23 go
go affected Alpaquita:stream go
grpc affected Alpaquita:23 grpc
grpc affected Alpaquita:stream grpc
nghttp2 affected Alpaquita:stream nghttp2
nghttp2 affected Alpaquita:23 nghttp2
nghttp2 affected BellSoft Hardened Containers:23 nghttp2
nghttp2 affected BellSoft Hardened Containers:stream nghttp2
nginx affected Alpaquita:stream nginx
nginx affected Alpaquita:23 nginx
Upstream advisory

CVE-2023-44487

Open SourceExploitedCISA KEV listedMEDIUM2023-10-10

HTTP/2 Stream Cancellation Attack

CVEs:CVE-2023-44487

Affected products

ProductStatusVendorPackageEcosystem
apple/swift-nio-http2 affected github.com github.com/apple/swift-nio-http2
com.typesafe.akka:akka-http-core affected Maven com.typesafe.akka:akka-http-core
com.typesafe.akka:akka-http-core_2.11 affected Maven com.typesafe.akka:akka-http-core_2.11
com.typesafe.akka:akka-http-core_2.12 affected Maven com.typesafe.akka:akka-http-core_2.12
com.typesafe.akka:akka-http-core_2.13 affected Maven com.typesafe.akka:akka-http-core_2.13
org.apache.tomcat.embed:tomcat-embed-core affected Maven org.apache.tomcat.embed:tomcat-embed-core
org.apache.tomcat:tomcat-coyote affected Maven org.apache.tomcat:tomcat-coyote
org.eclipse.jetty.http2:http2-common affected Maven org.eclipse.jetty.http2:http2-common
org.eclipse.jetty.http2:http2-server affected Maven org.eclipse.jetty.http2:http2-server
org.eclipse.jetty.http2:jetty-http2-common affected Maven org.eclipse.jetty.http2:jetty-http2-common
org.eclipse.jetty.http2:jetty-http2-server affected Maven org.eclipse.jetty.http2:jetty-http2-server
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2023-44487

Open SourceExploitedCISA KEV listedCRITICAL2023-10-10

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVEs:CVE-2023-44487

Affected products

ProductStatusVendorPackageEcosystem
3scale_api_management_platform affected redhat
advanced_cluster_management_for_kubernetes affected redhat
advanced_cluster_security affected redhat
ansible_automation_platform affected redhat
apisix affected apache
armeria affected linecorp
asp.net_core affected microsoft
astra_control_center affected netapp
azure_kubernetes_service affected microsoft
big-ip_access_policy_manager affected f5
big-ip_advanced_firewall_manager affected f5
big-ip_advanced_web_application_firewall affected f5
big-ip_analytics affected f5
big-ip_application_acceleration_manager affected f5
big-ip_application_security_manager affected f5
big-ip_application_visibility_and_reporting affected f5
big-ip_carrier-grade_nat affected f5
big-ip_ddos_hybrid_defender affected f5
big-ip_domain_name_system affected f5
big-ip_fraud_protection_service affected f5
big-ip_global_traffic_manager affected f5
big-ip_link_controller affected f5
big-ip_local_traffic_manager affected f5
big-ip_next affected f5
big-ip_next_service_proxy_for_kubernetes affected f5
big-ip_policy_enforcement_manager affected f5
big-ip_ssl_orchestrator affected f5
big-ip_webaccelerator affected f5
big-ip_websafe affected f5
build_of_optaplanner affected redhat
build_of_quarkus affected redhat
business_process_automation affected cisco
caddy affected caddyserver
cbl-mariner affected microsoft
ceph_storage affected redhat
certification_for_red_hat_enterprise_linux affected redhat
cert-manager_operator_for_red_hat_openshift affected redhat
connected_mobile_experiences affected cisco
contour affected projectcontour
cost_management affected redhat
crosswork_data_gateway affected cisco
crosswork_situation_manager affected cisco
crosswork_zero_touch_provisioning affected cisco
cryostat affected redhat
data_center_network_manager affected cisco
debian_linux affected debian
decision_manager affected redhat
enterprise_chat_and_email affected cisco
enterprise_linux affected redhat
envoy affected envoyproxy
expressway affected cisco
fedora affected fedoraproject
fence_agents_remediation_operator affected redhat
firepower_threat_defense affected cisco
fog_director affected cisco
go affected golang
grpc affected grpc
h2o affected dena
http affected ietf
http2 affected kazu-yamamoto
http2 affected golang
http_server affected akka
integration_camel_for_spring_boot affected redhat
integration_camel_k affected redhat
integration_service_registry affected redhat
ios_xe affected cisco
ios_xr affected cisco
iot_field_network_director affected cisco
istio affected istio
jboss_a-mq affected redhat
jboss_a-mq_streams affected redhat
jboss_core_services affected redhat
jboss_data_grid affected redhat
jboss_enterprise_application_platform affected redhat
jboss_fuse affected redhat
jenkins affected jenkins
jetty affected eclipse
kong_gateway affected konghq
linkerd affected linkerd
logging_subsystem_for_red_hat_openshift affected redhat
machine_deletion_remediation_operator affected redhat
migration_toolkit_for_applications affected redhat
migration_toolkit_for_containers affected redhat
migration_toolkit_for_virtualization affected redhat
.net affected microsoft
netty affected netty
networking affected golang
network_observability_operator affected redhat
nghttp2 affected nghttp2
nginx affected f5
nginx_ingress_controller affected f5
nginx_plus affected f5
node_healthcheck_operator affected redhat
node.js affected nodejs
node_maintenance_operator affected redhat
nx-os affected cisco
oncommand_insight affected netapp
openresty affected openresty
opensearch_data_prepper affected amazon
openshift affected redhat
openshift_api_for_data_protection affected redhat
openshift_container_platform affected redhat
openshift_container_platform_assisted_installer affected redhat
openshift_data_science affected redhat
openshift_developer_tools_and_services affected redhat
openshift_dev_spaces affected redhat
openshift_distributed_tracing affected redhat
openshift_gitops affected redhat
openshift_pipelines affected redhat
openshift_sandboxed_containers affected redhat
openshift_secondary_scheduler_operator affected redhat
openshift_serverless affected redhat
openshift_service_mesh affected redhat
openshift_virtualization affected redhat
openstack_platform affected redhat
prime_access_registrar affected cisco
prime_cable_provisioning affected cisco
prime_infrastructure affected cisco
prime_network_registrar affected cisco
process_automation affected redhat
proxygen affected facebook
quay affected redhat
ruggedcom_ape1808_firmware affected siemens
run_once_duration_override_operator affected redhat
satellite affected redhat
secure_dynamic_attributes_connector affected cisco
secure_firewall_threat_defense affected cisco
secure_malware_analytics affected cisco
secure_web_appliance_firmware affected cisco
self_node_remediation_operator affected redhat
service_interconnect affected redhat
service_telemetry_framework affected redhat
simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware affected siemens
simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware affected siemens
sinec_ins affected siemens
sinec_nms affected siemens
single_sign-on affected redhat
siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware affected siemens
solr affected apache
st7_scadaconnect affected siemens
support_for_spring_boot affected redhat
swiftnio_http\/2 affected apple
telepresence_video_communication_server affected cisco
tomcat affected apache
traefik affected traefik
traffic_server affected apache
ultra_cloud_core_-_policy_control_function affected cisco
ultra_cloud_core_-_serving_gateway_function affected cisco
ultra_cloud_core_-_session_management_function affected cisco
unified_attendant_console_advanced affected cisco
unified_contact_center_domain_manager affected cisco
unified_contact_center_enterprise affected cisco
unified_contact_center_enterprise_-_live_data_server affected cisco
unified_contact_center_management_portal affected cisco
varnish_cache affected varnish_cache_project
visual_studio_2022 affected microsoft
web_terminal affected redhat
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

CVE-2023-44487

GoogleExploitedCISA KEV listed2023-10-10

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVEs:CVE-2023-44487

Upstream advisory

MGASA-2023-0283

Open SourceExploitedCISA KEV listedCRITICAL2023-10-03

Updated chromium-browser-stable package fixes bugs and vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

CVE-2023-22515

GoogleExploitedCISA KEV listedCRITICAL2023-10-04

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Conflu...

CVEs:CVE-2023-22515

Affected products

ProductStatusVendorPackageEcosystem
confluence_data_center affected atlassian
confluence_server affected atlassian
Upstream advisory

CVE-2023-22515

Project ZeroExploitedCISA KEV listed2023-10-04

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this

CVEs:CVE-2023-22515

Upstream advisory

CVE-2023-4211

GoogleExploitedCISA KEV listedMEDIUM2023-10-01

A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

CVEs:CVE-2023-4211

Affected products

ProductStatusVendorPackageEcosystem
5th_gen_gpu_architecture_kernel_driver affected arm
bifrost_gpu_kernel_driver affected arm
midgard_gpu_kernel_driver affected arm
valhall_gpu_kernel_driver affected arm
Upstream advisory

ASB-A-294605494

GoogleExploitedCISA KEV listed2023-10-01

ASB-A-294605494

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-42824

GoogleExploitedCISA KEV listedHIGH2023-10-04

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of...

CVEs:CVE-2023-42824

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-42824

Project ZeroExploitedCISA KEV listed2023-10-04

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6.

CVEs:CVE-2023-42824

Upstream advisory

GHSA-fp9f-44c2-cw27

Open SourceActive exploitation (sightings)HIGH2023-10-25

Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

GHSA-fp9f-44c2-cw27

Open SourceActive exploitation (sightings)HIGH2023-10-25

Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller-1.13 affected chainguard ingress-nginx-controller-1.13
ingress-nginx-controller-1.14 affected wolfi ingress-nginx-controller-1.14
ingress-nginx-controller-1.14 affected chainguard ingress-nginx-controller-1.14
ingress-nginx-controller-1.15 affected wolfi ingress-nginx-controller-1.15
ingress-nginx-controller-1.15 affected chainguard ingress-nginx-controller-1.15
ingress-nginx-controller-1.9 affected chainguard ingress-nginx-controller-1.9
ingress-nginx-controller-fips affected chainguard ingress-nginx-controller-fips
ingress-nginx-controller-fips-1.13 affected chainguard ingress-nginx-controller-fips-1.13
ingress-nginx-controller-fips-1.14 affected chainguard ingress-nginx-controller-fips-1.14
ingress-nginx-controller-fips-1.15 affected chainguard ingress-nginx-controller-fips-1.15
ingress-nginx-controller-fips-1.9 affected chainguard ingress-nginx-controller-fips-1.9
Upstream advisory

CVE-2023-5044

GoogleActive exploitation (sightings)HIGH2023-10-25

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

CVEs:CVE-2023-5044

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected kubernetes
Upstream advisory

CVE-2023-5044

Open SourceActive exploitation (sightings)HIGH2023-10-25

Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation

CVEs:CVE-2023-5044

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

CVE-2023-5482

GoogleActive exploitation (sightings)HIGH2023-10-31

Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5482

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5482

GoogleActive exploitation (sightings)2023-10-31

Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5482

Upstream advisory

GHSA-5wj4-wffq-3378

Open SourceActive exploitation (sightings)HIGH2023-10-25

Ingress nginx annotation injection causes arbitrary command execution

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

GHSA-5wj4-wffq-3378

Open SourceActive exploitation (sightings)HIGH2023-10-25

Ingress nginx annotation injection causes arbitrary command execution

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller-1.9 affected chainguard ingress-nginx-controller-1.9
ingress-nginx-controller-fips affected chainguard ingress-nginx-controller-fips
ingress-nginx-controller-fips-1.9 affected chainguard ingress-nginx-controller-fips-1.9
Upstream advisory

CVE-2023-5043

Open SourceActive exploitation (sightings)HIGH2023-10-25

Ingress nginx annotation injection causes arbitrary command execution

CVEs:CVE-2023-5043

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

CVE-2023-5043

GoogleActive exploitation (sightings)CRITICAL2023-10-25

Ingress nginx annotation injection causes arbitrary command execution.

CVEs:CVE-2023-5043

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected kubernetes
Upstream advisory

DEBIAN-CVE-2023-5346

Open SourceActive exploitation (sightings)HIGH2023-10-05

DEBIAN-CVE-2023-5346

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2023:0292-1

Open SourceActive exploitation (sightings)2023-10-05

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DSA-5515-1

Open SourceActive exploitation (sightings)2023-10-04

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2023-5346

GoogleActive exploitation (sightings)HIGH2023-10-03

Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5346

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2023-5346

GoogleActive exploitation (sightings)2023-10-03

Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5346

Upstream advisory

MGASA-2023-0289

Open SourceActive exploitation (sightings)CRITICAL2023-10-19

Updated chromium-browser-stable packages fix bugs and vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

openSUSE-SU-2023:0300-1

Open SourceActive exploitation (sightings)CRITICAL2023-10-13

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
Upstream advisory

DSA-5526-1

Open SourceActive exploitation (sightings)2023-10-12

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2023-5218

Open SourceActive exploitation (sightings)CRITICAL2023-10-11

DEBIAN-CVE-2023-5218

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5218

GoogleActive exploitation (sightings)2023-10-10

Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2023-5218

Upstream advisory

CVE-2023-5218

GoogleActive exploitation (sightings)CRITICAL2023-10-10

Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2023-5218

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5857

GoogleActive exploitation (sightings)CRITICAL2023-10-31

Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially execute arbitrary code via a malicious file. (Chromium security severity: Medium)

CVEs:CVE-2023-5857

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5849

GoogleActive exploitation (sightings)CRITICAL2023-10-31

Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5849

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-5484

Open SourceActive exploitation (sightings)MEDIUM2023-10-11

DEBIAN-CVE-2023-5484

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5484

GoogleActive exploitation (sightings)2023-10-10

Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-5484

Upstream advisory

CVE-2023-5484

GoogleActive exploitation (sightings)MEDIUM2023-10-10

Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-5484

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5854

GoogleActive exploitation (sightings)2023-10-31

Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

CVEs:CVE-2023-5854

Upstream advisory

CVE-2023-5854

GoogleActive exploitation (sightings)CRITICAL2023-10-31

Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

CVEs:CVE-2023-5854

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5480

GoogleActive exploitation (sightings)CRITICAL2023-10-31

Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)

CVEs:CVE-2023-5480

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5480

GoogleActive exploitation (sightings)2023-10-31

Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)

CVEs:CVE-2023-5480

Upstream advisory

CVE-2023-5852

GoogleActive exploitation (sightings)CRITICAL2023-10-31

Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

CVEs:CVE-2023-5852

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5855

GoogleActive exploitation (sightings)CRITICAL2023-10-31

Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

CVEs:CVE-2023-5855

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5855

GoogleActive exploitation (sightings)2023-10-31

Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

CVEs:CVE-2023-5855

Upstream advisory

CVE-2023-5850

GoogleActive exploitation (sightings)2023-10-31

Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)

CVEs:CVE-2023-5850

Upstream advisory

CVE-2023-5850

GoogleActive exploitation (sightings)MEDIUM2023-10-31

Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)

CVEs:CVE-2023-5850

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-5476

Open SourceActive exploitation (sightings)CRITICAL2023-10-11

DEBIAN-CVE-2023-5476

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5476

GoogleActive exploitation (sightings)CRITICAL2023-10-10

Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-5476

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2023-36559

Open SourceActive exploitation (sightings)MEDIUM2023-10-10

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2023-36559

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2023-5485

Open SourceActive exploitation (sightings)MEDIUM2023-10-11

DEBIAN-CVE-2023-5485

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5485

GoogleActive exploitation (sightings)MEDIUM2023-10-10

Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-5485

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2023-5859

GoogleActive exploitation (sightings)MEDIUM2023-10-31

Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-5859

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-40534

Open SourceActive exploitation (sightings)HIGH2023-10-10

When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate...

CVEs:CVE-2023-40534

Affected products

ProductStatusVendorPackageEcosystem
big-ip_access_policy_manager affected f5
big-ip_advanced_firewall_manager affected f5
big-ip_advanced_web_application_firewall affected f5
big-ip_analytics affected f5
big-ip_application_acceleration_manager affected f5
big-ip_application_security_manager affected f5
big-ip_application_visibility_and_reporting affected f5
big-ip_carrier-grade_nat affected f5
big-ip_ddos_hybrid_defender affected f5
big-ip_domain_name_system affected f5
big-ip_edge_gateway affected f5
big-ip_fraud_protection_service affected f5
big-ip_global_traffic_manager affected f5
big-ip_link_controller affected f5
big-ip_local_traffic_manager affected f5
big-ip_next_service_proxy_for_kubernetes affected f5
big-ip_policy_enforcement_manager affected f5
big-ip_ssl_orchestrator affected f5
big-ip_webaccelerator affected f5
big-ip_websafe affected f5
Upstream advisory

CVE-2023-21391

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21391

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21339

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21339

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45226

Open SourceActive exploitation (sightings)CRITICAL2023-10-10

The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those cont...

CVEs:CVE-2023-45226

Affected products

ProductStatusVendorPackageEcosystem
big-ip_next_service_proxy_for_kubernetes affected f5
Upstream advisory

CVE-2023-21353

Open SourceActive exploitation (sightings)HIGH2023-10-30

In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21353

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-46094

GoogleActive exploitation (sightings)CRITICAL2023-10-26

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin <= 6.5.3 versions.

CVEs:CVE-2023-46094

Affected products

ProductStatusVendorPackageEcosystem
google_analytics_integration_for_woocommerce affected conversios
Upstream advisory

CVE-2023-27448

GoogleActive exploitation (sightings)HIGH2023-10-06

Cross-Site Request Forgery (CSRF) vulnerability in MakeStories Team MakeStories (for Google Web Stories) plugin <= 2.8.0 versions.

CVEs:CVE-2023-27448

Affected products

ProductStatusVendorPackageEcosystem
makestories_\(for_google_web_stories\) affected makestories
Upstream advisory

CVE-2023-3254

GoogleActive exploitation (sightings)MEDIUM2023-10-18

The Widgets for Google Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.9. This is due to missing or incorrect nonce validation within setup_no_reg_header.php. This makes it possible for unau...

CVEs:CVE-2023-3254

Affected products

ProductStatusVendorPackageEcosystem
widgets_for_google_reviews affected trustedindex
Upstream advisory

CVE-2023-21395

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21395

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21392

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Bluetooth, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege when connecting to a Bluetooth device with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-21392

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21342

Open SourceActive exploitation (sightings)HIGH2023-10-30

In RemoteSpeechRecognitionService of RemoteSpeechRecognitionService.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution ...

CVEs:CVE-2023-21342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21356

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21356

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21315

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21315

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21351

Open SourceActive exploitation (sightings)HIGH2023-10-30

In multiple locations, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21351

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45780

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Print Service, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2023-45780

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21398

Open SourceActive exploitation (sightings)HIGH2023-10-30

In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21398

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21334

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In App Ops Service, there is a possible disclosure of information about installed packages due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2023-21334

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21343

Open SourceActive exploitation (sightings)HIGH2023-10-30

In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21343

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21344

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Job Scheduler, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...

CVEs:CVE-2023-21344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21332

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...

CVEs:CVE-2023-21332

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21333

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...

CVEs:CVE-2023-21333

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21393

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21393

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21331

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. Use...

CVEs:CVE-2023-21331

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21335

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User i...

CVEs:CVE-2023-21335

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21336

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. Us...

CVEs:CVE-2023-21336

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21329

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-21329

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21341

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2023-21341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21338

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. U...

CVEs:CVE-2023-21338

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21296

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Permission, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. Use...

CVEs:CVE-2023-21296

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21375

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21375

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21381

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Media Resource Manager, there is a possible local arbitrary code execution due to use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21381

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21370

Open SourceActive exploitation (sightings)HIGH2023-10-30

In the Security Element API, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21370

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21371

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Secure Element, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21371

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21306

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In ContentService, there is a possible way to read installed sync content providers due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2023-21306

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21303

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Content, here is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User int...

CVEs:CVE-2023-21303

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21328

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User ...

CVEs:CVE-2023-21328

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21377

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In SELinux Policy, there is a possible restriction bypass due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21377

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21355

Open SourceActive exploitation (sightings)HIGH2023-10-30

In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21355

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21360

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21360

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21326

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges...

CVEs:CVE-2023-21326

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21312

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In IntentResolver, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21312

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21320

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Device Policy, there is a possible way to verify if a particular admin app is registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User i...

CVEs:CVE-2023-21320

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21376

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21376

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21378

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2023-21378

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21367

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2023-21367

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21368

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21368

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21369

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissions bypass. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for...

CVEs:CVE-2023-21369

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21357

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21357

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21325

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User i...

CVEs:CVE-2023-21325

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21327

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Permission Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges need...

CVEs:CVE-2023-21327

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21307

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User...

CVEs:CVE-2023-21307

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21308

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Composer, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21308

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21316

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User in...

CVEs:CVE-2023-21316

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21318

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User in...

CVEs:CVE-2023-21318

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21319

Open SourceActive exploitation (sightings)HIGH2023-10-30

In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2023-21319

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21354

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges...

CVEs:CVE-2023-21354

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21359

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21359

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21364

Open SourceActive exploitation (sightings)HIGH2023-10-30

In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21364

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21350

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed...

CVEs:CVE-2023-21350

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21366

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2023-21366

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21321

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21321

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21348

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...

CVEs:CVE-2023-21348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21345

Open SourceActive exploitation (sightings)MEDIUM2023-10-30

In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ne...

CVEs:CVE-2023-21345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21365

Open SourceActive exploitation (sightings)HIGH2023-10-30

In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21365

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21358

Open SourceActive exploitation (sightings)HIGH2023-10-30

In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2023-21358

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

AZL-37886

Open SourcePoC exploitCRITICAL2023-10-18

CVE-2023-38545 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-7fxm-f474-hf8w

Open SourcePoC exploitCRITICAL2023-10-31

Kubernetes privilege escalation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-efs-csi-driver-fips-1.6 affected chainguard aws-efs-csi-driver-fips-1.6
calico-fips affected chainguard calico-fips
calico-fips-3.25 affected chainguard calico-fips-3.25
cluster-autoscaler-fips-1.25 affected chainguard cluster-autoscaler-fips-1.25
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
Upstream advisory

GHSA-7fxm-f474-hf8w

Open SourcePoC exploitCRITICAL2023-10-31

Kubernetes privilege escalation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

DEBIAN-CVE-2023-3676

Open SourcePoC exploitHIGH2023-10-31

DEBIAN-CVE-2023-3676

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

AZL-38099

Open SourcePoC exploitCRITICAL2023-10-18

CVE-2023-38546 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GO-2023-2113

Open SourcePoC exploitHIGH2023-10-16

Memory exhaustion in go.opentelemetry.io/contrib/instrumentation

Affected products

ProductStatusVendorPackageEcosystem
azure-container-networking affected chainguard azure-container-networking
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
caddy affected wolfi caddy
caddy affected chainguard caddy
contrib/instrumentation/github.com/emicklei/go-restful/otelrestful affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful
contrib/instrumentation/github.com/gin-gonic/gin/otelgin affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin
contrib/instrumentation/github.com/gorilla/mux/otelmux affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux
contrib/instrumentation/github.com/labstack/echo/otelecho affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho
contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron
contrib/instrumentation/net/http/httptrace/otelhttptrace affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace
contrib/instrumentation/net/http/otelhttp affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
k3s affected chainguard k3s
k3s affected wolfi k3s
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-1.32 affected chainguard kubernetes-1.32
kubernetes-1.32 affected wolfi kubernetes-1.32
kubernetes-1.33 affected chainguard kubernetes-1.33
kubernetes-1.33 affected wolfi kubernetes-1.33
kubernetes-fips-1.32 affected chainguard kubernetes-fips-1.32
kubernetes-fips-1.33 affected chainguard kubernetes-fips-1.33
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
rancher-webhook-0.4 affected chainguard rancher-webhook-0.4
rancher-webhook-fips-0.4 affected chainguard rancher-webhook-fips-0.4
up affected chainguard up
up affected wolfi up
Upstream advisory

GHSA-rcjv-mgp8-qvmr

GooglePoC exploitHIGH2023-10-16

OpenTelemetry-Go Contrib vulnerable to denial of service in otelhttp due to unbound cardinality metrics

Affected products

ProductStatusVendorPackageEcosystem
contrib/instrumentation/github.com/emicklei/go-restful/otelrestful affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful
contrib/instrumentation/github.com/gin-gonic/gin/otelgin affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin
contrib/instrumentation/github.com/gorilla/mux/otelmux affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux
contrib/instrumentation/github.com/labstack/echo/otelecho affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho
contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron
contrib/instrumentation/net/http/httptrace/otelhttptrace affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace
contrib/instrumentation/net/http/otelhttp affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
Upstream advisory

GHSA-rcjv-mgp8-qvmr

Open SourcePoC exploitHIGH2023-10-16

OpenTelemetry-Go Contrib vulnerable to denial of service in otelhttp due to unbound cardinality metrics

Affected products

ProductStatusVendorPackageEcosystem
azure-container-networking affected chainguard azure-container-networking
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
caddy affected chainguard caddy
caddy affected wolfi caddy
calico affected wolfi calico
calico affected chainguard calico
calico-fips affected chainguard calico-fips
cert-manager-1.11 affected wolfi cert-manager-1.11
cert-manager-1.11 affected chainguard cert-manager-1.11
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.13 affected wolfi cert-manager-1.13
cert-manager-1.13 affected chainguard cert-manager-1.13
cluster-autoscaler-fips-1.26 affected chainguard cluster-autoscaler-fips-1.26
cluster-autoscaler-fips-1.27 affected chainguard cluster-autoscaler-fips-1.27
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
contrib/instrumentation/github.com/emicklei/go-restful/otelrestful affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful
contrib/instrumentation/github.com/gin-gonic/gin/otelgin affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin
contrib/instrumentation/github.com/gorilla/mux/otelmux affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux
contrib/instrumentation/github.com/labstack/echo/otelecho affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho
contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron
contrib/instrumentation/net/http/httptrace/otelhttptrace affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace
contrib/instrumentation/net/http/otelhttp affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
gatekeeper-3.12 affected chainguard gatekeeper-3.12
gatekeeper-3.12 affected wolfi gatekeeper-3.12
gatekeeper-3.13 affected chainguard gatekeeper-3.13
gatekeeper-3.13 affected wolfi gatekeeper-3.13
gitlab-kas affected wolfi gitlab-kas
gitlab-kas affected chainguard gitlab-kas
ipfs affected wolfi ipfs
ipfs affected chainguard ipfs
k3s affected chainguard k3s
k3s affected wolfi k3s
keda affected chainguard keda
keda affected wolfi keda
keda-2.10 affected chainguard keda-2.10
keda-2.10 affected wolfi keda-2.10
keda-2.11 affected wolfi keda-2.11
keda-2.11 affected chainguard keda-2.11
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-1.32 affected wolfi kubernetes-1.32
kubernetes-1.32 affected chainguard kubernetes-1.32
kubernetes-1.33 affected chainguard kubernetes-1.33
kubernetes-1.33 affected wolfi kubernetes-1.33
kubernetes-fips-1.27 affected chainguard kubernetes-fips-1.27
kubernetes-fips-1.28 affected chainguard kubernetes-fips-1.28
kubernetes-fips-1.29 affected chainguard kubernetes-fips-1.29
kubernetes-fips-1.32 affected chainguard kubernetes-fips-1.32
kubernetes-fips-1.33 affected chainguard kubernetes-fips-1.33
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
prometheus affected wolfi prometheus
prometheus affected chainguard prometheus
prometheus-2.38 affected chainguard prometheus-2.38
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
rancher-webhook-0.4 affected chainguard rancher-webhook-0.4
rancher-webhook-fips-0.4 affected chainguard rancher-webhook-fips-0.4
thanos-0.31 affected wolfi thanos-0.31
thanos-0.31 affected chainguard thanos-0.31
thanos-0.32 affected chainguard thanos-0.32
thanos-0.32 affected wolfi thanos-0.32
up affected wolfi up
up affected chainguard up
Upstream advisory

AZL-31310

Open SourcePoC exploitCRITICAL2023-10-11

CVE-2023-39325 affecting package golang for versions less than 1.20.7-2

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-34544

Open SourcePoC exploitCRITICAL2023-10-11

CVE-2023-39325 affecting package application-gateway-kubernetes-ingress for versions less than 1.7.7-1

Affected products

ProductStatusVendorPackageEcosystem
application-gateway-kubernetes-ingress affected Azure Linux:3 application-gateway-kubernetes-ingress
Upstream advisory

AZL-34747

Open SourcePoC exploitCRITICAL2023-10-11

CVE-2023-39325 affecting package golang for versions less than 1.20.7-2

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-37440

Open SourcePoC exploitCRITICAL2023-10-11

CVE-2023-39325 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37478

Open SourcePoC exploitCRITICAL2023-10-11

CVE-2023-39325 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79060

Open SourcePoC exploitCRITICAL2023-10-11

CVE-2023-39325 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-39325

Open SourcePoC exploitCRITICAL2023-10-11

DEBIAN-CVE-2023-39325

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2023-39325

Open SourcePoC exploitHIGH2023-10-11

HTTP/2 rapid reset can cause excessive work in net/http

CVEs:CVE-2023-39325

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-4374-p667-p6c8

Open SourcePoC exploitCRITICAL2023-10-11

HTTP/2 rapid reset can cause excessive work in net/http

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
amass affected wolfi amass
amass affected chainguard amass
apko affected wolfi apko
apko affected chainguard apko
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.8 affected wolfi argo-cd-2.8
argo-cd-2.8 affected chainguard argo-cd-2.8
atlantis affected chainguard atlantis
atlantis affected wolfi atlantis
atlantis-fips affected chainguard atlantis-fips
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-efs-csi-driver-fips-1.6 affected chainguard aws-efs-csi-driver-fips-1.6
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller-2.4.5 affected chainguard aws-load-balancer-controller-2.4.5
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults affected chainguard bank-vaults
bank-vaults affected wolfi bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bom affected chainguard bom
bom affected wolfi bom
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
caddy affected wolfi caddy
caddy affected chainguard caddy
calico-fips affected chainguard calico-fips
calico-fips-3.25 affected chainguard calico-fips-3.25
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
cloud-sql-proxy affected wolfi cloud-sql-proxy
cloud-sql-proxy affected chainguard cloud-sql-proxy
cluster-autoscaler-1.25 affected wolfi cluster-autoscaler-1.25
cluster-autoscaler-1.25 affected chainguard cluster-autoscaler-1.25
cluster-autoscaler-fips-1.25 affected chainguard cluster-autoscaler-fips-1.25
cluster-autoscaler-fips-1.26 affected chainguard cluster-autoscaler-fips-1.26
cluster-autoscaler-fips-1.27 affected chainguard cluster-autoscaler-fips-1.27
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
configmap-reload-fips affected chainguard configmap-reload-fips
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
consul-1.15 affected wolfi consul-1.15
consul-1.15 affected chainguard consul-1.15
consul-1.16 affected chainguard consul-1.16
consul-1.16 affected wolfi consul-1.16
containerd affected chainguard containerd
containerd affected wolfi containerd
coredns affected wolfi coredns
coredns affected chainguard coredns
cosign affected chainguard cosign
cosign affected wolfi cosign
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-azure affected wolfi crossplane-provider-azure
crossplane-provider-azure affected chainguard crossplane-provider-azure
cue affected chainguard cue
cue affected wolfi cue
dex affected chainguard dex
dex affected wolfi dex
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
dive affected wolfi dive
dive affected chainguard dive
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
external-dns affected wolfi external-dns
external-dns affected chainguard external-dns
external-dns-fips affected chainguard external-dns-fips
external-secrets-0.7 affected chainguard external-secrets-0.7
external-secrets-operator affected chainguard external-secrets-operator
external-secrets-operator affected wolfi external-secrets-operator
falco affected chainguard falco
falco affected wolfi falco
falcoctl affected wolfi falcoctl
falcoctl affected chainguard falcoctl
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
flux affected chainguard flux
flux affected wolfi flux
flux-0 affected chainguard flux-0
flux-0.37 affected chainguard flux-0.37
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller-0 affected chainguard flux-helm-controller-0
flux-helm-controller-0.37 affected chainguard flux-helm-controller-0.37
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-image-reflector-controller-0 affected chainguard flux-image-reflector-controller-0
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller-0 affected chainguard flux-kustomize-controller-0
flux-kustomize-controller-0.37 affected chainguard flux-kustomize-controller-0.37
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller-0 affected chainguard flux-notification-controller-0
flux-notification-controller-0.37 affected chainguard flux-notification-controller-0.37
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller-0 affected chainguard flux-source-controller-0
flux-source-controller-0.37 affected chainguard flux-source-controller-0.37
frp affected wolfi frp
frp affected chainguard frp
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
gatekeeper-3.12 affected wolfi gatekeeper-3.12
gatekeeper-3.12 affected chainguard gatekeeper-3.12
gitlab-pages affected wolfi gitlab-pages
gitlab-pages affected chainguard gitlab-pages
gitlab-runner affected wolfi gitlab-runner
gitlab-runner affected chainguard gitlab-runner
git-lfs affected chainguard git-lfs
git-lfs affected wolfi git-lfs
gitness affected chainguard gitness
gitness affected wolfi gitness
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
go-1.20 affected wolfi go-1.20
go-1.20 affected chainguard go-1.20
go-1.21 affected wolfi go-1.21
go-1.21 affected chainguard go-1.21
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
gomplate affected wolfi gomplate
gomplate affected chainguard gomplate
goreleaser-1.18 affected wolfi goreleaser-1.18
goreleaser-1.18 affected chainguard goreleaser-1.18
grafana-9.3 affected chainguard grafana-9.3
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
haproxy-ingress affected wolfi haproxy-ingress
haproxy-ingress affected chainguard haproxy-ingress
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected wolfi helm-3
helm-3 affected chainguard helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
hey affected wolfi hey
hey affected chainguard hey
hugo affected wolfi hugo
hugo affected chainguard hugo
influxd affected wolfi influxd
influxd affected chainguard influxd
istio-cni-1.19 affected wolfi istio-cni-1.19
istio-cni-1.19 affected chainguard istio-cni-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-pilot-agent-1.18 affected wolfi istio-pilot-agent-1.18
istio-pilot-agent-1.18 affected chainguard istio-pilot-agent-1.18
istio-pilot-agent-1.19 affected wolfi istio-pilot-agent-1.19
istio-pilot-agent-1.19 affected chainguard istio-pilot-agent-1.19
istio-pilot-discovery-1.18 affected wolfi istio-pilot-discovery-1.18
istio-pilot-discovery-1.18 affected chainguard istio-pilot-discovery-1.18
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected wolfi k3s
k3s affected chainguard k3s
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k8sgpt-operator affected wolfi k8sgpt-operator
k8sgpt-operator affected chainguard k8sgpt-operator
kaf affected wolfi kaf
kaf affected chainguard kaf
karpenter affected chainguard karpenter
karpenter affected wolfi karpenter
karpenter-0.23 affected chainguard karpenter-0.23
keda affected chainguard keda
keda affected wolfi keda
keda-2.10 affected wolfi keda-2.10
keda-2.10 affected chainguard keda-2.10
keda-2.11 affected wolfi keda-2.11
keda-2.11 affected chainguard keda-2.11
keda-2.8 affected chainguard keda-2.8
keda-2.9 affected chainguard keda-2.9
kiam affected chainguard kiam
kind affected chainguard kind
kind affected wolfi kind
kots affected chainguard kots
kots affected wolfi kots
kpt affected wolfi kpt
kpt affected chainguard kpt
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kube-logging-operator affected wolfi kube-logging-operator
kube-logging-operator affected chainguard kube-logging-operator
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-1.19 affected chainguard kubernetes-1.19
kubernetes-1.20 affected chainguard kubernetes-1.20
kubernetes-1.21 affected chainguard kubernetes-1.21
kubernetes-1.22 affected chainguard kubernetes-1.22
kubernetes-1.23 affected chainguard kubernetes-1.23
kubernetes-1.24 affected chainguard kubernetes-1.24
kubernetes-1.24 affected wolfi kubernetes-1.24
kubernetes-csi-external-attacher-4.3 affected chainguard kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.3 affected wolfi kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.4 affected wolfi kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-attacher-4.4 affected chainguard kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-attacher-fips-4.3 affected chainguard kubernetes-csi-external-attacher-fips-4.3
kubernetes-csi-external-attacher-fips-4.4 affected chainguard kubernetes-csi-external-attacher-fips-4.4
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-csi-external-resizer-1.8 affected chainguard kubernetes-csi-external-resizer-1.8
kubernetes-csi-external-resizer-fips-1.8 affected chainguard kubernetes-csi-external-resizer-fips-1.8
kubernetes-csi-external-snapshotter affected wolfi kubernetes-csi-external-snapshotter
kubernetes-csi-external-snapshotter affected chainguard kubernetes-csi-external-snapshotter
kubernetes-csi-external-snapshotter-6.0 affected chainguard kubernetes-csi-external-snapshotter-6.0
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-node-driver-registrar-2.9 affected chainguard kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-2.9 affected wolfi kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-fips-2.8 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.8
kubernetes-csi-node-driver-registrar-fips-2.9 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.9
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
kubernetes-ingress-defaultbackend affected wolfi kubernetes-ingress-defaultbackend
kubernetes-ingress-defaultbackend affected chainguard kubernetes-ingress-defaultbackend
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kube-state-metrics affected wolfi kube-state-metrics
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics-2.2.0 affected chainguard kube-state-metrics-2.2.0
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kubewatch affected wolfi kubewatch
kubewatch affected chainguard kubewatch
kyverno affected wolfi kyverno
kyverno affected chainguard kyverno
kyverno-1.8 affected chainguard kyverno-1.8
kyverno-policy-reporter-2.11 affected chainguard kyverno-policy-reporter-2.11
kyverno-policy-reporter-kyverno-plugin-1.5 affected chainguard kyverno-policy-reporter-kyverno-plugin-1.5
kyverno-policy-reporter-ui-1.7 affected chainguard kyverno-policy-reporter-ui-1.7
mc affected chainguard mc
mc affected wolfi mc
memcached-exporter affected chainguard memcached-exporter
memcached-exporter affected wolfi memcached-exporter
metacontroller affected chainguard metacontroller
metacontroller affected wolfi metacontroller
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
minio affected wolfi minio
minio affected chainguard minio
nats affected chainguard nats
nats affected wolfi nats
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
node-problem-detector-0.8 affected wolfi node-problem-detector-0.8
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nri-prometheus affected wolfi nri-prometheus
nri-prometheus affected chainguard nri-prometheus
oauth2-proxy affected wolfi oauth2-proxy
oauth2-proxy affected chainguard oauth2-proxy
ollama affected chainguard ollama
ollama affected wolfi ollama
opentofu affected wolfi opentofu
opentofu affected chainguard opentofu
prometheus affected chainguard prometheus
prometheus affected wolfi prometheus
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-blackbox-exporter affected wolfi prometheus-blackbox-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter affected wolfi prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter-fips affected chainguard prometheus-elasticsearch-exporter-fips
prometheus-fips affected chainguard prometheus-fips
prometheus-fips-2.38 affected chainguard prometheus-fips-2.38
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter affected wolfi prometheus-mongodb-exporter
prometheus-mongodb-exporter-fips affected chainguard prometheus-mongodb-exporter-fips
prometheus-mongodb-exporter-fips-0.37 affected chainguard prometheus-mongodb-exporter-fips-0.37
prometheus-mysqld-exporter affected wolfi prometheus-mysqld-exporter
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter affected wolfi prometheus-node-exporter
prometheus-node-exporter-1.5 affected chainguard prometheus-node-exporter-1.5
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-operator affected wolfi prometheus-operator
prometheus-operator affected chainguard prometheus-operator
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-postgres-exporter affected wolfi prometheus-postgres-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-postgres-exporter-fips affected chainguard prometheus-postgres-exporter-fips
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
prometheus-pushgateway-fips-1.4 affected chainguard prometheus-pushgateway-fips-1.4
prometheus-redis-exporter-fips-1.44 affected chainguard prometheus-redis-exporter-fips-1.44
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter affected wolfi prometheus-statsd-exporter
prometheus-statsd-exporter-fips affected chainguard prometheus-statsd-exporter-fips
pulumi affected chainguard pulumi
pulumi affected wolfi pulumi
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-yaml affected wolfi pulumi-language-yaml
pulumi-language-yaml affected chainguard pulumi-language-yaml
rqlite affected chainguard rqlite
rqlite affected wolfi rqlite
runc affected chainguard runc
runc affected wolfi runc
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
src affected wolfi src
src affected chainguard src
stakater-reloader affected wolfi stakater-reloader
stakater-reloader affected chainguard stakater-reloader
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
tctl affected wolfi tctl
tctl affected chainguard tctl
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.26 affected wolfi telegraf-1.26
telegraf-1.27 affected chainguard telegraf-1.27
telegraf-1.27 affected wolfi telegraf-1.27
terraform affected chainguard terraform
terraform affected wolfi terraform
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
thanos-0.31 affected wolfi thanos-0.31
thanos-0.31 affected chainguard thanos-0.31
thanos-0.32 affected chainguard thanos-0.32
thanos-0.32 affected wolfi thanos-0.32
thanos-operator affected wolfi thanos-operator
thanos-operator affected chainguard thanos-operator
timoni affected wolfi timoni
timoni affected chainguard timoni
tkn affected wolfi tkn
tkn affected chainguard tkn
trillian affected chainguard trillian
trillian affected wolfi trillian
trust-manager affected wolfi trust-manager
trust-manager affected chainguard trust-manager
up affected chainguard up
up affected wolfi up
vault-1.13 affected chainguard vault-1.13
vault-1.13 affected wolfi vault-1.13
vault-csi-provider affected chainguard vault-csi-provider
vault-csi-provider affected wolfi vault-csi-provider
vault-k8s affected chainguard vault-k8s
vault-k8s affected wolfi vault-k8s
vault-k8s-fips affected chainguard vault-k8s-fips
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
weaviate affected chainguard weaviate
weaviate affected wolfi weaviate
wireguard-go affected chainguard wireguard-go
wireguard-go affected wolfi wireguard-go
x/net affected golang.org golang.org/x/net
x/net affected golang.org
yq affected chainguard yq
yq affected wolfi yq
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

GHSA-4374-p667-p6c8

Open SourcePoC exploitCRITICAL2023-10-11

HTTP/2 rapid reset can cause excessive work in net/http

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2023-39325

Open SourcePoC exploitHIGH2023-10-11

HTTP/2 rapid reset can cause excessive work in net/http

CVEs:CVE-2023-39325

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2023-39325

GooglePoC exploitCRITICAL2023-10-11

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progre...

CVEs:CVE-2023-39325

Affected products

ProductStatusVendorPackageEcosystem
astra_trident affected netapp
astra_trident_autosupport affected netapp
fedora affected fedoraproject
go affected golang
http2 affected golang
Upstream advisory

GHSA-q78c-gwqw-jcmc

Open SourcePoC exploitCRITICAL2023-10-31

Kubernetes privilege escalation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.8 affected wolfi argo-cd-2.8
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-efs-csi-driver-fips-1.6 affected chainguard aws-efs-csi-driver-fips-1.6
calico affected chainguard calico
calico affected wolfi calico
calico-fips affected chainguard calico-fips
calico-fips-3.25 affected chainguard calico-fips-3.25
cluster-autoscaler-1.25 affected chainguard cluster-autoscaler-1.25
cluster-autoscaler-1.25 affected wolfi cluster-autoscaler-1.25
cluster-autoscaler-fips-1.25 affected chainguard cluster-autoscaler-fips-1.25
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver-fips affected chainguard secrets-store-csi-driver-fips
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
Upstream advisory

GHSA-q78c-gwqw-jcmc

Open SourcePoC exploitCRITICAL2023-10-31

Kubernetes privilege escalation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

DEBIAN-CVE-2023-3955

Open SourcePoC exploitHIGH2023-10-31

DEBIAN-CVE-2023-3955

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CLSA-2023-1696537500

Open SourcePoC exploitCRITICAL2023-10-05

Fix CVE(s): CVE-2022-48560

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

ASB-A-296463357

GooglePoC exploit2023-10-01

ASB-A-296463357

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

AZL-34900

Open SourcePoC exploitHIGH2023-10-12

CVE-2023-45142 affecting package kubernetes for versions less than 1.29.1-2

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:3 kubernetes
Upstream advisory

CLSA-2023-1697556743

Open SourcePoC exploit2023-10-17

Fix CVE(s): CVE-2022-48566

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

CLSA-2023-1697463705

Open SourcePoC exploit2023-10-16

Fix CVE(s): CVE-2022-48566

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

CLSA-2023-1697463155

Open SourcePoC exploit2023-10-16

Fix CVE(s): CVE-2022-48566

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:18.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:18.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:18.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:18.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:18.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:18.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:18.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:18.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:18.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:18.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:18.04 python2.7-minimal
Upstream advisory

CLSA-2023-1697462566

Open SourcePoC exploit2023-10-16

Fix CVE(s): CVE-2022-48566

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.6 affected TuxCare:Ubuntu:18.04 idle-python3.6
libpython3.6 affected TuxCare:Ubuntu:18.04 libpython3.6
libpython3.6-dev affected TuxCare:Ubuntu:18.04 libpython3.6-dev
libpython3.6-minimal affected TuxCare:Ubuntu:18.04 libpython3.6-minimal
libpython3.6-stdlib affected TuxCare:Ubuntu:18.04 libpython3.6-stdlib
libpython3.6-testsuite affected TuxCare:Ubuntu:18.04 libpython3.6-testsuite
python3.6 affected TuxCare:Ubuntu:18.04 python3.6
python3.6-dev affected TuxCare:Ubuntu:18.04 python3.6-dev
python3.6-doc affected TuxCare:Ubuntu:18.04 python3.6-doc
python3.6-examples affected TuxCare:Ubuntu:18.04 python3.6-examples
python3.6-minimal affected TuxCare:Ubuntu:18.04 python3.6-minimal
python3.6-venv affected TuxCare:Ubuntu:18.04 python3.6-venv
Upstream advisory

GHSA-v845-jxx5-vc9f

Open SourcePoC exploitHIGH2023-10-02

`Cookie` HTTP header isn't stripped on cross-origin redirects

Affected products

ProductStatusVendorPackageEcosystem
dask-gateway affected wolfi dask-gateway
dask-gateway affected chainguard dask-gateway
k8s-sidecar affected wolfi k8s-sidecar
k8s-sidecar affected chainguard k8s-sidecar
kube-downscaler affected chainguard kube-downscaler
kube-downscaler affected wolfi kube-downscaler
kubeflow-jupyter-web-app affected chainguard kubeflow-jupyter-web-app
kubeflow-jupyter-web-app affected wolfi kubeflow-jupyter-web-app
kubeflow-volumes-web-app affected wolfi kubeflow-volumes-web-app
kubeflow-volumes-web-app affected chainguard kubeflow-volumes-web-app
py3.13-scanner-test-libraries affected chainguard py3.13-scanner-test-libraries
py3-urllib3 affected chainguard py3-urllib3
py3-urllib3 affected wolfi py3-urllib3
py3-urllib3-1 affected chainguard py3-urllib3-1
py3-urllib3-1 affected wolfi py3-urllib3-1
urllib3 affected PyPI urllib3
urllib3 affected PyPI urllib3
Upstream advisory

GHSA-v845-jxx5-vc9f

GooglePoC exploitHIGH2023-10-02

`Cookie` HTTP header isn't stripped on cross-origin redirects

Affected products

ProductStatusVendorPackageEcosystem
urllib3 affected PyPI urllib3
Upstream advisory

GHSA-hrfv-mqp8-q5rw

GooglePoC exploitCRITICAL2023-10-25

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

Affected products

ProductStatusVendorPackageEcosystem
werkzeug affected PyPI werkzeug
Upstream advisory

GHSA-hrfv-mqp8-q5rw

Open SourcePoC exploitCRITICAL2023-10-25

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

Affected products

ProductStatusVendorPackageEcosystem
airflow-2 affected chainguard airflow-2
airflow-3 affected wolfi airflow-3
airflow-3 affected chainguard airflow-3
airflow-core-2 affected chainguard airflow-core-2
kubeflow-jupyter-web-app affected chainguard kubeflow-jupyter-web-app
kubeflow-jupyter-web-app affected wolfi kubeflow-jupyter-web-app
kubeflow-pipelines-visualization-server affected chainguard kubeflow-pipelines-visualization-server
kubeflow-pipelines-visualization-server affected wolfi kubeflow-pipelines-visualization-server
kubeflow-volumes-web-app affected wolfi kubeflow-volumes-web-app
kubeflow-volumes-web-app affected chainguard kubeflow-volumes-web-app
py3-tensorflow-serving-api affected wolfi py3-tensorflow-serving-api
py3-tensorflow-serving-api affected chainguard py3-tensorflow-serving-api
py3-werkzeug affected chainguard py3-werkzeug
py3-werkzeug affected wolfi py3-werkzeug
werkzeug affected PyPI werkzeug
werkzeug affected PyPI werkzeug
Werkzeug affected PyPI Werkzeug
Werkzeug affected PyPI
Upstream advisory

OESA-2023-1726

Open SourcePoC exploitCRITICAL2023-10-13

grpc security update

Affected products

ProductStatusVendorPackageEcosystem
grpc affected openEuler:20.03-LTS-SP1 grpc
Upstream advisory

GHSA-g4mx-q9vg-27p4

GooglePoC exploitHIGH2023-10-17

urllib3's request body not stripped after redirect from 303 status changes request method to GET

Affected products

ProductStatusVendorPackageEcosystem
urllib3 affected PyPI urllib3
Upstream advisory

GHSA-g4mx-q9vg-27p4

Open SourcePoC exploitHIGH2023-10-17

urllib3's request body not stripped after redirect from 303 status changes request method to GET

Affected products

ProductStatusVendorPackageEcosystem
az affected wolfi az
az affected chainguard az
jwt-tool affected chainguard jwt-tool
jwt-tool affected wolfi jwt-tool
k8s-sidecar-1.22 affected chainguard k8s-sidecar-1.22
kubeflow-jupyter-web-app affected wolfi kubeflow-jupyter-web-app
kubeflow-jupyter-web-app affected chainguard kubeflow-jupyter-web-app
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-volumes-web-app affected chainguard kubeflow-volumes-web-app
kubeflow-volumes-web-app affected wolfi kubeflow-volumes-web-app
nvidia-nsight-compute-13.1 affected chainguard nvidia-nsight-compute-13.1
nvidia-nsight-compute-13.2 affected chainguard nvidia-nsight-compute-13.2
py3.11-pytorch-cuda-12.3 affected chainguard py3.11-pytorch-cuda-12.3
py3.11-torchaudio-cuda-12.3 affected chainguard py3.11-torchaudio-cuda-12.3
py3.11-torchvision-cuda-11.8 affected chainguard py3.11-torchvision-cuda-11.8
py3.11-torchvision-cuda-12.3 affected chainguard py3.11-torchvision-cuda-12.3
py3.13-scanner-test-libraries affected chainguard py3.13-scanner-test-libraries
py3-cassandra-medusa affected wolfi py3-cassandra-medusa
py3-cassandra-medusa affected chainguard py3-cassandra-medusa
py3-pipenv affected chainguard py3-pipenv
py3-pipenv affected wolfi py3-pipenv
py3-tensorflow-serving-api affected chainguard py3-tensorflow-serving-api
py3-tensorflow-serving-api affected wolfi py3-tensorflow-serving-api
py3-torchvision-cuda-11.8 affected chainguard py3-torchvision-cuda-11.8
py3-urllib3-1 affected chainguard py3-urllib3-1
py3-urllib3-1 affected wolfi py3-urllib3-1
request-1276 affected chainguard request-1276
urllib3 affected PyPI urllib3
urllib3 affected PyPI urllib3
Upstream advisory

BELL-CVE-2023-32732

Open SourcePoC exploitMEDIUM2023-10-18

BELL-CVE-2023-32732

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Alpaquita:23 grpc
Upstream advisory

BELL-CVE-2023-32731

Open SourcePoC exploitHIGH2023-10-18

BELL-CVE-2023-32731

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Alpaquita:23 grpc
Upstream advisory

BELL-CVE-2023-33953

Open SourcePoC exploitHIGH2023-10-18

BELL-CVE-2023-33953

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Alpaquita:23 grpc
grpc affected Alpaquita:stream grpc
Upstream advisory

GHSA-mq26-g339-26xf

Open SourcePoC exploitCRITICAL2023-10-25

Command Injection in pip when used with Mercurial

Affected products

ProductStatusVendorPackageEcosystem
jwt-tool affected chainguard jwt-tool
jwt-tool affected wolfi jwt-tool
k8s-sidecar-1.22 affected chainguard k8s-sidecar-1.22
pip affected PyPI pip
pip affected PyPI pip
Upstream advisory

GHSA-mq26-g339-26xf

GooglePoC exploitCRITICAL2023-10-25

Command Injection in pip when used with Mercurial

Affected products

ProductStatusVendorPackageEcosystem
pip affected PyPI pip
Upstream advisory

CVE-2023-35649

Open SourcePoC exploitHIGH2023-10-11

In several functions of Exynos modem files, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35649

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-276971478

GooglePoC exploitHIGH2023-10-01

PUB-A-276971478

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-35646

Open SourcePoC exploitCRITICAL2023-10-11

In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35646

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-276972140

GooglePoC exploitHIGH2023-10-01

PUB-A-276972140

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

BELL-CVE-2023-1428

Open SourcePoC exploitHIGH2023-10-18

BELL-CVE-2023-1428

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Alpaquita:23 grpc
Upstream advisory

CVE-2023-32820

GooglePoC exploit2023-10-02

In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.

CVEs:CVE-2023-32820

Upstream advisory

CVE-2023-32820

Open SourcePoC exploitHIGH2023-10-02

In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637...

CVEs:CVE-2023-32820

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

ASB-A-294781433

GooglePoC exploit2023-10-01

ASB-A-294781433

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-35648

Open SourcePoC exploitCRITICAL2023-10-11

In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction...

CVEs:CVE-2023-35648

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-286373897

GooglePoC exploitMEDIUM2023-10-01

PUB-A-286373897

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-287627703

GooglePoC exploit2023-10-01

ASB-A-287627703

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-35656

Open SourcePoC exploitHIGH2023-10-11

In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2023-35656

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35663

Open SourcePoC exploitHIGH2023-10-11

In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-35663

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-286537026

GooglePoC exploitHIGH2023-10-01

PUB-A-286537026

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-286718842

GooglePoC exploitNONE2023-10-01

PUB-A-286718842

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-40140

Open SourcePoC exploitHIGH2023-10-03

In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2023-40140

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40127

Open SourcePoC exploitMEDIUM2023-10-03

In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40127

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40133

Open SourcePoC exploitMEDIUM2023-10-03

In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2023-40133

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-240605080

GooglePoC exploit2023-10-01

PUB-A-240605080

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-253296923

GooglePoC exploit2023-10-01

PUB-A-253296923

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21266

Open SourcePoC exploitHIGH2023-10-03

In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2023-21266

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40130

Open SourcePoC exploitHIGH2023-10-03

In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User i...

CVEs:CVE-2023-40130

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-290061916

GooglePoC exploit2023-10-01

ASB-A-290061916

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-290061247

GooglePoC exploit2023-10-01

ASB-A-290061247

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-276762572

GooglePoC exploit2023-10-01

PUB-A-276762572

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21291

Open SourcePoC exploitMEDIUM2023-10-03

In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not need...

CVEs:CVE-2023-21291

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40117

Open SourcePoC exploitHIGH2023-10-03

In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2023-40117

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40116

Open SourcePoC exploitHIGH2023-10-03

In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. Use...

CVEs:CVE-2023-40116

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40128

Open SourcePoC exploitHIGH2023-10-03

In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40128

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40120

Open SourcePoC exploitHIGH2023-10-03

In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2023-40120

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40125

Open SourcePoC exploitHIGH2023-10-03

In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2023-40125

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35654

Open SourcePoC exploitMEDIUM2023-10-11

In ctrl_roi of stmvl53l1_module.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35654

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35660

Open SourcePoC exploitHIGH2023-10-11

In lwis_transaction_client_cleanup of lwis_transaction.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2023-35660

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40141

Open SourcePoC exploitHIGH2023-10-11

In temp_residency_name_store of thermal_metrics.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2023-40141

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-239873016

GooglePoC exploitHIGH2023-10-01

PUB-A-239873016

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-272492131

GooglePoC exploitNONE2023-10-01

PUB-A-272492131

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-274446016

GooglePoC exploitHIGH2023-10-01

PUB-A-274446016

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-35653

Open SourcePoC exploitMEDIUM2023-10-11

In TBD of TBD, there is a possible way to access location information due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35653

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32819

Open SourcePoC exploitMEDIUM2023-10-02

In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issu...

CVEs:CVE-2023-32819

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-294779649

GooglePoC exploit2023-10-01

ASB-A-294779649

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-272281209

GooglePoC exploitMEDIUM2023-10-01

PUB-A-272281209

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-40638

Open SourcePoC exploitHIGH2023-10-03

In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-40638

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-296491611

GooglePoC exploit2023-10-01

ASB-A-296491611

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-3781

Open SourcePoC exploitHIGH2023-10-11

there is a possible use-after-free write due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-3781

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-289470723

GooglePoC exploitHIGH2023-10-01

PUB-A-289470723

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

AZL-31107

Open SourceCoalition ESS < 30%CRITICAL2023-10-05

CVE-2023-39323 affecting package golang for versions less than 1.20.10-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37358

Open SourceCoalition ESS < 30%CRITICAL2023-10-05

CVE-2023-39323 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37389

Open SourceCoalition ESS < 30%CRITICAL2023-10-05

CVE-2023-39323 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-52845

Open SourceCoalition ESS < 30%CRITICAL2023-10-05

CVE-2023-39323 affecting package golang for versions less than 1.20.10-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-78984

Open SourceCoalition ESS < 30%CRITICAL2023-10-05

CVE-2023-39323 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-39323

Open SourceCoalition ESS < 30%CRITICAL2023-10-05

DEBIAN-CVE-2023-39323

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GHSA-gvrm-w2f9-f77q

Open SourceCoalition ESS < 30%HIGH2023-10-25

Ingress-nginx path sanitization can be bypassed

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller-1.9 affected chainguard ingress-nginx-controller-1.9
ingress-nginx-controller-fips affected chainguard ingress-nginx-controller-fips
ingress-nginx-controller-fips-1.9 affected chainguard ingress-nginx-controller-fips-1.9
Upstream advisory

GHSA-gvrm-w2f9-f77q

Open SourceCoalition ESS < 30%HIGH2023-10-25

Ingress-nginx path sanitization can be bypassed

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

CVE-2022-4886

GoogleCoalition ESS < 30%HIGH2023-10-25

Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.

CVEs:CVE-2022-4886

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected kubernetes
Upstream advisory

CVE-2022-4886

Open SourceCoalition ESS < 30%HIGH2023-10-25

Ingress-nginx path sanitization can be bypassed

CVEs:CVE-2022-4886

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

CVE-2023-45886

Open SourceCoalition ESS < 30%HIGH2023-10-25

The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute.

CVEs:CVE-2023-45886

Affected products

ProductStatusVendorPackageEcosystem
big-ip_global_traffic_manager affected f5
big-ip_local_traffic_manager affected f5
big-ip_next affected f5
big-ip_next_cloud-native_network_functions affected f5
big-ip_next_service_proxy_for_kubernetes affected f5
zebos affected ipinfusion
Upstream advisory

CVE-2023-44323

Open SourceCoalition ESS < 30%HIGH2023-10-29

Adobe Acrobat for Edge version 118.0.2088.46 (and earlier) is affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Expl...

CVEs:CVE-2023-44323

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

MGASA-2023-0306

Open SourceCoalition ESS < 30%CRITICAL2023-10-30

Updated chromium-browser-stable packages fix bugs including security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

openSUSE-SU-2023:0325-1

Open SourceCoalition ESS < 30%CRITICAL2023-10-26

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DSA-5536-1

Open SourceCoalition ESS < 30%2023-10-26

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-5472

Open SourceCoalition ESS < 30%CRITICAL2023-10-25

DEBIAN-CVE-2023-5472

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5472

GoogleCoalition ESS < 30%CRITICAL2023-10-24

Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5472

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5472

GoogleCoalition ESS < 30%2023-10-24

Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5472

Upstream advisory

CVE-2023-5856

GoogleCoalition ESS < 30%CRITICAL2023-10-31

Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-5856

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5851

GoogleCoalition ESS < 30%MEDIUM2023-10-31

Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-5851

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

GHSA-35c7-w35f-xwgh

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

Kube-proxy may unintentionally forward traffic

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
Upstream advisory

GHSA-35c7-w35f-xwgh

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

Kube-proxy may unintentionally forward traffic

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2023-36409

Open SourceCoalition ESS < 30%HIGH2023-10-10

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVEs:CVE-2023-36409

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2023-5474

Open SourceCoalition ESS < 30%HIGH2023-10-11

DEBIAN-CVE-2023-5474

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5474

GoogleCoalition ESS < 30%HIGH2023-10-10

Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

CVEs:CVE-2023-5474

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2023-5483

Open SourceCoalition ESS < 30%MEDIUM2023-10-11

DEBIAN-CVE-2023-5483

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5483

GoogleCoalition ESS < 30%2023-10-10

Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-5483

Upstream advisory

CVE-2023-5483

GoogleCoalition ESS < 30%MEDIUM2023-10-10

Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-5483

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2023-5478

Open SourceCoalition ESS < 30%MEDIUM2023-10-11

DEBIAN-CVE-2023-5478

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5478

GoogleCoalition ESS < 30%MEDIUM2023-10-10

Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-5478

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2023-5481

Open SourceCoalition ESS < 30%MEDIUM2023-10-11

DEBIAN-CVE-2023-5481

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5481

GoogleCoalition ESS < 30%MEDIUM2023-10-10

Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-5481

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2023-5473

Open SourceCoalition ESS < 30%CRITICAL2023-10-11

DEBIAN-CVE-2023-5473

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5473

GoogleCoalition ESS < 30%CRITICAL2023-10-10

Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-5473

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2023-5486

Open SourceCoalition ESS < 30%MEDIUM2023-10-11

DEBIAN-CVE-2023-5486

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5486

GoogleCoalition ESS < 30%MEDIUM2023-10-10

Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-5486

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2023-5853

GoogleCoalition ESS < 30%MEDIUM2023-10-31

Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-5853

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5858

GoogleCoalition ESS < 30%MEDIUM2023-10-31

Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-5858

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

ASB-A-294779648

GoogleCoalition ESS < 30%2023-10-01

ASB-A-294779648

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2023-5487

Open SourceCoalition ESS < 30%MEDIUM2023-10-11

DEBIAN-CVE-2023-5487

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5487

GoogleCoalition ESS < 30%MEDIUM2023-10-10

Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: ...

CVEs:CVE-2023-5487

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2023-5744

GoogleCoalition ESS < 30%HIGH2023-10-24

The Very Simple Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vsgmap' shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attr...

CVEs:CVE-2023-5744

Affected products

ProductStatusVendorPackageEcosystem
very_simple_google_maps affected very_simple_google_maps_project
Upstream advisory

DEBIAN-CVE-2023-5479

Open SourceCoalition ESS < 30%MEDIUM2023-10-11

DEBIAN-CVE-2023-5479

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5479

GoogleCoalition ESS < 30%MEDIUM2023-10-10

Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-5479

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2023-5475

Open SourceCoalition ESS < 30%MEDIUM2023-10-11

DEBIAN-CVE-2023-5475

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5475

GoogleCoalition ESS < 30%2023-10-10

Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)

CVEs:CVE-2023-5475

Upstream advisory

CVE-2023-5475

GoogleCoalition ESS < 30%MEDIUM2023-10-10

Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severit...

CVEs:CVE-2023-5475

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

GHSA-8gwj-m6vh-2g6j

Open SourceCoalition ESS < 30%CRITICAL2023-10-12

kOps privilege escalation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
kops affected k8s.io k8s.io/kops
Upstream advisory

GHSA-8gwj-m6vh-2g6j

Open SourceCoalition ESS < 30%CRITICAL2023-10-12

kOps privilege escalation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
kops affected k8s.io k8s.io/kops
Upstream advisory

CVE-2023-5315

GoogleCoalition ESS < 30%HIGH2023-10-30

The Google Maps made Simple plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exist...

CVEs:CVE-2023-5315

Affected products

ProductStatusVendorPackageEcosystem
google_maps_made_simple affected matthewschwartz
Upstream advisory

CVE-2022-4943

GoogleCoalition ESS < 30%HIGH2023-10-20

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attacke...

CVEs:CVE-2022-4943

Affected products

ProductStatusVendorPackageEcosystem
google_authenticator affected miniorange
Upstream advisory

DEBIAN-CVE-2023-5477

Open SourceCoalition ESS < 30%MEDIUM2023-10-11

DEBIAN-CVE-2023-5477

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5477

GoogleCoalition ESS < 30%MEDIUM2023-10-10

Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)

CVEs:CVE-2023-5477

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2023-35662

Open SourceCoalition ESS < 30%CRITICAL2023-10-11

there is a possible out of bounds write due to buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35662

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-276971805

GoogleCoalition ESS < 30%HIGH2023-10-01

PUB-A-276971805

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-3248

Open SourceCoalition ESS < 30%CRITICAL2023-10-05

A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.

CVEs:CVE-2022-3248

Affected products

ProductStatusVendorPackageEcosystem
advanced_cluster_management_for_kubernetes affected redhat
openshift_container_platform affected redhat
Upstream advisory

CVE-2023-40632

Open SourceCoalition ESS < 30%CRITICAL2023-10-08

In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure no additional execution privileges needed

CVEs:CVE-2023-40632

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-37x5-qpm8-53rq

GoogleCoalition ESS < 30%CRITICAL2023-10-16

Google Sheets data source plugin for Grafana information disclosure vulnerability

Affected products

ProductStatusVendorPackageEcosystem
grafana/google-sheets-datasource affected github.com github.com/grafana/google-sheets-datasource
Upstream advisory

GHSA-37x5-qpm8-53rq

GoogleCoalition ESS < 30%CRITICAL2023-10-16

Google Sheets data source plugin for Grafana information disclosure vulnerability

Affected products

ProductStatusVendorPackageEcosystem
grafana/google-sheets-datasource affected github.com github.com/grafana/google-sheets-datasource
Upstream advisory

CVE-2023-4457

GoogleCoalition ESS < 30%MEDIUM2023-10-16

Google Sheets data source plugin for Grafana information disclosure vulnerability

CVEs:CVE-2023-4457

Affected products

ProductStatusVendorPackageEcosystem
grafana/google-sheets-datasource affected github.com github.com/grafana/google-sheets-datasource
Upstream advisory

CVE-2023-4457

GoogleCoalition ESS < 30%CRITICAL2023-10-16

Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messa...

CVEs:CVE-2023-4457

Affected products

ProductStatusVendorPackageEcosystem
google_sheets affected grafana
Upstream advisory

CVE-2023-4457

GoogleCoalition ESS < 30%MEDIUM2023-10-16

Google Sheets data source plugin for Grafana information disclosure vulnerability

CVEs:CVE-2023-4457

Affected products

ProductStatusVendorPackageEcosystem
grafana/google-sheets-datasource affected github.com github.com/grafana/google-sheets-datasource
Upstream advisory

DEBIAN-CVE-2023-46129

Open SourceCoalition ESS < 30%CRITICAL2023-10-31

DEBIAN-CVE-2023-46129

Affected products

ProductStatusVendorPackageEcosystem
golang-github-nats-io-nkeys affected Debian:13 golang-github-nats-io-nkeys
golang-github-nats-io-nkeys affected Debian:14 golang-github-nats-io-nkeys
nats-server affected Debian:13 nats-server
nats-server affected Debian:14 nats-server
Upstream advisory

PUB-A-271904738

GoogleCoalition ESS < 30%2023-10-01

PUB-A-271904738

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21347

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35661

Open SourceCoalition ESS < 30%HIGH2023-10-11

In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2023-35661

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-254938063

GoogleCoalition ESS < 30%MEDIUM2023-10-01

PUB-A-254938063

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-35647

Open SourceCoalition ESS < 30%CRITICAL2023-10-11

In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction...

CVEs:CVE-2023-35647

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-278109661

GoogleCoalition ESS < 30%MEDIUM2023-10-01

PUB-A-278109661

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-35652

Open SourceCoalition ESS < 30%HIGH2023-10-11

In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction...

CVEs:CVE-2023-35652

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-278108845

GoogleCoalition ESS < 30%MEDIUM2023-10-01

PUB-A-278108845

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-287624919

GoogleCoalition ESS < 30%2023-10-01

ASB-A-287624919

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-296461583

GoogleCoalition ESS < 30%2023-10-01

ASB-A-296461583

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-38396

GoogleCoalition ESS < 30%HIGH2023-10-03

Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez plugin <= 3.1.2 versions.

CVEs:CVE-2023-38396

Affected products

ProductStatusVendorPackageEcosystem
google-map-shortcode affected web-argument
Upstream advisory

CVE-2023-40561

GoogleCoalition ESS < 30%HIGH2023-10-04

Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugin <= 3.7.1 versions.

CVEs:CVE-2023-40561

Affected products

ProductStatusVendorPackageEcosystem
enhanced_ecommerce_google_analytics_for_woocommerce affected multidots
Upstream advisory

CVE-2023-40129

Open SourceCoalition ESS < 30%HIGH2023-10-03

In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2023-40129

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45273

GoogleCoalition ESS < 30%HIGH2023-10-16

Cross-Site Request Forgery (CSRF) vulnerability in Matt McKenny Stout Google Calendar plugin <= 1.2.3 versions.

CVEs:CVE-2023-45273

Affected products

ProductStatusVendorPackageEcosystem
stout_google_calendar affected mattmckenny
Upstream advisory

CVE-2023-40121

Open SourceCoalition ESS < 30%HIGH2023-10-03

In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40121

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45831

GoogleCoalition ESS < 30%HIGH2023-10-16

Cross-Site Request Forgery (CSRF) vulnerability in Pixelative, Mohsin Rafique AMP WP – Google AMP For WordPress plugin <= 1.5.15 versions.

CVEs:CVE-2023-45831

Affected products

ProductStatusVendorPackageEcosystem
google_amp affected pixelative
Upstream advisory

CVE-2023-21361

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Bluetooth, there is a possibility of code-execution due to a use after free. This could lead to paired device escalation of privilege in the privileged Bluetooth process with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2023-21361

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21253

Open SourceCoalition ESS < 30%HIGH2023-10-03

In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21253

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40101

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In collapse of canonicalize_md.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40101

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21244

Open SourceCoalition ESS < 30%MEDIUM2023-10-03

In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2023-21244

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21337

Open SourceCoalition ESS < 30%HIGH2023-10-30

In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. Us...

CVEs:CVE-2023-21337

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-253297595

GoogleCoalition ESS < 30%2023-10-01

PUB-A-253297595

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39810

Open SourceCoalition ESS < 30%HIGH2023-10-30

In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no add...

CVEs:CVE-2021-39810

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-261492822

GoogleCoalition ESS < 30%2023-10-01

PUB-A-261492822

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-290060972

GoogleCoalition ESS < 30%2023-10-01

ASB-A-290060972

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2023-21252

Open SourceCoalition ESS < 30%MEDIUM2023-10-03

In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction ...

CVEs:CVE-2023-21252

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21396

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21396

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20264

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges need...

CVEs:CVE-2022-20264

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21295

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In SliceManagerService, there is a possible way to check if a content provider is installed due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-21295

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21293

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges n...

CVEs:CVE-2023-21293

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21387

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not n...

CVEs:CVE-2023-21387

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21397

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21397

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21330

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Overlay Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....

CVEs:CVE-2023-21330

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21388

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21388

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21389

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21389

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21390

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21390

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21340

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21340

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40142

Open SourceCoalition ESS < 30%HIGH2023-10-11

In TBD of TBD, there is a possible way to bypass carrier restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40142

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-279767668

GoogleCoalition ESS < 30%NONE2023-10-01

PUB-A-279767668

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21310

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21310

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21394

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User inter...

CVEs:CVE-2023-21394

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21383

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Settings, there is a possible way for the user to unintentionally send extra data due to an unclear prompt. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2023-21383

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21372

Open SourceCoalition ESS < 30%HIGH2023-10-30

In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21372

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21324

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges need...

CVEs:CVE-2023-21324

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21294

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21294

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21380

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21380

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21302

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....

CVEs:CVE-2023-21302

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21298

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Slice, there is a possible disclosure of installed applications due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2023-21298

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21304

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Content Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....

CVEs:CVE-2023-21304

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21299

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....

CVEs:CVE-2023-21299

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21300

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...

CVEs:CVE-2023-21300

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40137

Open SourceCoalition ESS < 30%MEDIUM2023-10-03

In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2023-40137

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40138

Open SourceCoalition ESS < 30%MEDIUM2023-10-03

In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40138

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21374

Open SourceCoalition ESS < 30%HIGH2023-10-30

In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21374

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21384

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Package Manager, there is a possible possible permissions bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21384

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21305

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User in...

CVEs:CVE-2023-21305

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40123

Open SourceCoalition ESS < 30%MEDIUM2023-10-03

In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2023-40123

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40135

Open SourceCoalition ESS < 30%MEDIUM2023-10-03

In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2023-40135

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40139

Open SourceCoalition ESS < 30%MEDIUM2023-10-03

In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40139

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32830

Open SourceCoalition ESS < 30%HIGH2023-10-02

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03802522; Issue ID:...

CVEs:CVE-2023-32830

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32828

Open SourceCoalition ESS < 30%HIGH2023-10-02

In vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767817; Issue ID: ALP...

CVEs:CVE-2023-32828

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
Upstream advisory

CVE-2023-32827

Open SourceCoalition ESS < 30%HIGH2023-10-02

In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07...

CVEs:CVE-2023-32827

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32826

Open SourceCoalition ESS < 30%HIGH2023-10-02

In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07...

CVEs:CVE-2023-32826

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21379

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21379

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21385

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21385

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21314

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21314

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21317

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In ContentService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...

CVEs:CVE-2023-21317

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40134

Open SourceCoalition ESS < 30%MEDIUM2023-10-03

In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2023-40134

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40136

Open SourceCoalition ESS < 30%MEDIUM2023-10-03

In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2023-40136

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32821

Open SourceCoalition ESS < 30%HIGH2023-10-02

In video, there is a possible out of bounds write due to a permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08013430; Issue ID: ...

CVEs:CVE-2023-32821

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32829

Open SourceCoalition ESS < 30%HIGH2023-10-02

In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07713478; Issue ID: ...

CVEs:CVE-2023-32829

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
yocto affected linuxfoundation
Upstream advisory

CVE-2023-32822

Open SourceCoalition ESS < 30%HIGH2023-10-02

In ftm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07994229; Issue ID: ...

CVEs:CVE-2023-32822

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21301

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In ActivityManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges...

CVEs:CVE-2023-21301

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21323

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Activity Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed...

CVEs:CVE-2023-21323

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21297

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In SEPolicy, there is a possible way to access the factory MAC address due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21297

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21352

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21352

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21309

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In libcore, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21309

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21313

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21313

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40131

Open SourceCoalition ESS < 30%HIGH2023-10-03

In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40131

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32824

Open SourceCoalition ESS < 30%HIGH2023-10-02

In rpmb , there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07912966; Issue ID: ALPS07912961.

CVEs:CVE-2023-32824

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32823

Open SourceCoalition ESS < 30%HIGH2023-10-02

In rpmb , there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07912966; Issue ID: ...

CVEs:CVE-2023-32823

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21373

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2023-21373

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21349

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....

CVEs:CVE-2023-21349

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21311

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-21311

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40651

Open SourceCoalition ESS < 30%CRITICAL2023-10-08

In urild service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-40651

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21346

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile...

CVEs:CVE-2023-21346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40654

Open SourceCoalition ESS < 30%MEDIUM2023-10-08

In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed

CVEs:CVE-2023-40654

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40636

Open SourceCoalition ESS < 30%HIGH2023-10-08

In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with System execution privileges needed

CVEs:CVE-2023-40636

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21382

Open SourceCoalition ESS < 30%MEDIUM2023-10-30

In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User in...

CVEs:CVE-2023-21382

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40652

Open SourceCoalition ESS < 30%CRITICAL2023-10-08

In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-40652

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40653

Open SourceCoalition ESS < 30%MEDIUM2023-10-08

In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed

CVEs:CVE-2023-40653

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40631

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

CVEs:CVE-2023-40631

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21362

Open SourceCoalition ESS < 30%HIGH2023-10-30

In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21362

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40634

Open SourceCoalition ESS < 30%CRITICAL2023-10-08

In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-40634

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40635

Open SourceCoalition ESS < 30%HIGH2023-10-08

In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-40635

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40641

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40641

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40642

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40642

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40643

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40643

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40644

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40644

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40645

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40645

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40646

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40646

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40647

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40647

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40648

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40648

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40649

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40649

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40650

Open SourceCoalition ESS < 30%HIGH2023-10-08

In Telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40650

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40633

Open SourceCoalition ESS < 30%HIGH2023-10-08

In phasecheckserver, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-40633

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40637

Open SourceCoalition ESS < 30%HIGH2023-10-08

In telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-40637

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40639

Open SourceCoalition ESS < 30%HIGH2023-10-08

In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-40639

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40640

Open SourceCoalition ESS < 30%HIGH2023-10-08

In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-40640

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35645

Open SourceCoalition ESS < 30%HIGH2023-10-11

In tbd of tbd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35645

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-283787360

GoogleCoalition ESS < 30%HIGH2023-10-01

PUB-A-283787360

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-23651

GoogleEPSS <= 49%CRITICAL2023-10-12

Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.

CVEs:CVE-2023-23651

Affected products

ProductStatusVendorPackageEcosystem
mainwp_google_analytics_extension affected mainwp
Upstream advisory

CVE-2023-30727

Open SourceEPSS <= 49%HIGH2023-10-03

Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi and connect arbitrary Wi-Fi without User Interaction.

CVEs:CVE-2023-30727

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30731

Open SourceEPSS <= 49%MEDIUM2023-10-03

Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.

CVEs:CVE-2023-30731

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30692

Open SourceEPSS <= 49%HIGH2023-10-03

Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2023-30692

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30690

Open SourceEPSS <= 49%HIGH2023-10-03

Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2023-30690

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30733

Open SourceEPSS <= 49%HIGH2023-10-03

Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attackers to perform code execution.

CVEs:CVE-2023-30733

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30732

Open SourceEPSS <= 49%MEDIUM2023-10-03

Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.

CVEs:CVE-2023-30732

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

PUB-A-245789946

GoogleEPSS <= 49%2023-10-01

PUB-A-245789946

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-35655

Open SourceEPSS <= 49%HIGH2023-10-11

In CanConvertPadV2Op of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-35655

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-264509020

GoogleEPSS <= 49%HIGH2023-10-01

PUB-A-264509020

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-jq35-85cj-fj4p

Open SourceAll remainingNONE2023-10-30

/sys/devices/virtual/powercap accessible by default to containers

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
apko affected chainguard apko
apko affected wolfi apko
argo-workflows affected chainguard argo-workflows
argo-workflows affected wolfi argo-workflows
bom affected chainguard bom
bom affected wolfi bom
cert-manager-1.11 affected wolfi cert-manager-1.11
cert-manager-1.11 affected chainguard cert-manager-1.11
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-1.13 affected wolfi cert-manager-1.13
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
conftest affected wolfi conftest
conftest affected chainguard conftest
conftest-fips affected chainguard conftest-fips
cosign affected chainguard cosign
cosign affected wolfi cosign
ctop affected chainguard ctop
ctop affected wolfi ctop
docker affected wolfi docker
docker affected chainguard docker
docker/docker affected github.com github.com/docker/docker
docker/docker affected github.com github.com/docker/docker
falco affected wolfi falco
falco affected chainguard falco
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
flux affected wolfi flux
flux affected chainguard flux
flux-0 affected chainguard flux-0
flux-0.37 affected chainguard flux-0.37
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller-0 affected chainguard flux-helm-controller-0
flux-helm-controller-0.37 affected chainguard flux-helm-controller-0.37
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller-0 affected chainguard flux-image-reflector-controller-0
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller-0 affected chainguard flux-source-controller-0
flux-source-controller-0.37 affected chainguard flux-source-controller-0.37
flux-source-controller-2.0 affected chainguard flux-source-controller-2.0
github.com/docker/docker affected Go github.com/docker/docker
gitlab-runner-fips-17.0 affected chainguard gitlab-runner-fips-17.0
goreleaser-1.18 affected wolfi goreleaser-1.18
goreleaser-1.18 affected chainguard goreleaser-1.18
grype affected chainguard grype
grype affected wolfi grype
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected wolfi helm-3
helm-3 affected chainguard helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-fips-1.19 affected chainguard istio-operator-fips-1.19
istio-pilot-agent-1.19 affected chainguard istio-pilot-agent-1.19
istio-pilot-agent-1.19 affected wolfi istio-pilot-agent-1.19
istio-pilot-agent-fips-1.19 affected chainguard istio-pilot-agent-fips-1.19
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
istio-pilot-discovery-fips-1.19 affected chainguard istio-pilot-discovery-fips-1.19
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
ko affected chainguard ko
ko affected wolfi ko
kots affected chainguard kots
kots affected wolfi kots
kpt affected wolfi kpt
kpt affected chainguard kpt
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kyverno affected chainguard kyverno
kyverno affected wolfi kyverno
kyverno-1.8 affected chainguard kyverno-1.8
loki affected wolfi loki
loki affected chainguard loki
melange affected chainguard melange
melange affected wolfi melange
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent-1.43 affected chainguard newrelic-infrastructure-agent-1.43
paranoia affected wolfi paranoia
paranoia affected chainguard paranoia
prometheus affected chainguard prometheus
prometheus affected wolfi prometheus
prometheus-2.38 affected chainguard prometheus-2.38
prometheus-2.45 affected wolfi prometheus-2.45
prometheus-2.45 affected chainguard prometheus-2.45
prometheus-fips affected chainguard prometheus-fips
rancher-agent-2.8 affected chainguard rancher-agent-2.8
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
spire-server affected chainguard spire-server
spire-server affected wolfi spire-server
spire-server-fips affected chainguard spire-server-fips
tekton-chains affected chainguard tekton-chains
tekton-chains affected wolfi tekton-chains
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.26 affected wolfi telegraf-1.26
telegraf-1.27 affected wolfi telegraf-1.27
telegraf-1.27 affected chainguard telegraf-1.27
traefik affected chainguard traefik
traefik affected wolfi traefik
up affected chainguard up
up affected wolfi up
Upstream advisory

GHSA-jq35-85cj-fj4p

GoogleAll remainingNONE2023-10-30

/sys/devices/virtual/powercap accessible by default to containers

Affected products

ProductStatusVendorPackageEcosystem
docker/docker affected github.com github.com/docker/docker
Upstream advisory

GHSA-m425-mq94-257g

Open SourceAll remainingCRITICAL2023-10-25

gRPC-Go HTTP/2 Rapid Reset vulnerability

Affected products

ProductStatusVendorPackageEcosystem
grpc affected google.golang.org google.golang.org/grpc
Upstream advisory

GHSA-m425-mq94-257g

Open SourceAll remainingCRITICAL2023-10-25

gRPC-Go HTTP/2 Rapid Reset vulnerability

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-efs-csi-driver-fips-1.6 affected chainguard aws-efs-csi-driver-fips-1.6
bank-vaults-fips affected chainguard bank-vaults-fips
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
calico-fips affected chainguard calico-fips
calico-fips-3.25 affected chainguard calico-fips-3.25
cluster-autoscaler-fips-1.25 affected chainguard cluster-autoscaler-fips-1.25
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
conftest-fips affected chainguard conftest-fips
cortex affected chainguard cortex
cortex affected wolfi cortex
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
falco affected chainguard falco
falco affected wolfi falco
falcoctl-fips affected chainguard falcoctl-fips
flux-source-controller-0 affected chainguard flux-source-controller-0
flux-source-controller-0.37 affected chainguard flux-source-controller-0.37
gatekeeper-fips-3.14 affected chainguard gatekeeper-fips-3.14
goreleaser-1.18 affected chainguard goreleaser-1.18
goreleaser-1.18 affected wolfi goreleaser-1.18
grafana-7 affected chainguard grafana-7
grafana-8 affected chainguard grafana-8
grafana-9.3 affected chainguard grafana-9.3
grpc affected google.golang.org google.golang.org/grpc
grpc affected google.golang.org google.golang.org/grpc
ipfs affected chainguard ipfs
ipfs affected wolfi ipfs
k3d affected chainguard k3d
k3d affected wolfi k3d
kiam affected chainguard kiam
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-csi-external-attacher-4.3 affected wolfi kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.3 affected chainguard kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-fips-4.3 affected chainguard kubernetes-csi-external-attacher-fips-4.3
kubernetes-csi-external-resizer-1.8 affected chainguard kubernetes-csi-external-resizer-1.8
kubernetes-csi-external-resizer-fips-1.8 affected chainguard kubernetes-csi-external-resizer-fips-1.8
kubernetes-csi-external-snapshotter-6.0 affected chainguard kubernetes-csi-external-snapshotter-6.0
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-csi-node-driver-registrar-fips-2.8 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.8
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
metrics-server-fips affected chainguard metrics-server-fips
neuvector-agent affected wolfi neuvector-agent
neuvector-agent affected chainguard neuvector-agent
plutono affected chainguard plutono
plutono-fips affected chainguard plutono-fips
prometheus-2.38 affected chainguard prometheus-2.38
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-blackbox-exporter affected wolfi prometheus-blackbox-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
src affected wolfi src
src affected chainguard src
terraform-fips-1.5 affected chainguard terraform-fips-1.5
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
timestamp-authority-fips affected chainguard timestamp-authority-fips
up affected wolfi up
up affected chainguard up
vault-csi-provider affected wolfi vault-csi-provider
vault-csi-provider affected chainguard vault-csi-provider
volcano affected chainguard volcano
volcano-fips affected chainguard volcano-fips
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
Upstream advisory

openSUSE-SU-2023:0308-1

Open SourceAll remaining2023-10-20

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.