Google Security Advisories · November 2023 — Google Security Advisories
337 advisories 194 CVEs 27 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2023-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 27 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

GO-2023-2153

Open SourceExploitedCISA KEV listedCRITICAL2023-11-01

Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
bank-vaults-fips affected chainguard bank-vaults-fips
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
conftest-fips affected chainguard conftest-fips
cortex affected wolfi cortex
cortex affected chainguard cortex
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
falcoctl-fips affected chainguard falcoctl-fips
grpc affected google.golang.org google.golang.org/grpc
k3d affected chainguard k3d
k3d affected wolfi k3d
kiam affected chainguard kiam
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
metrics-server-fips affected chainguard metrics-server-fips
plutono affected chainguard plutono
plutono-fips affected chainguard plutono-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
src affected chainguard src
src affected wolfi src
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
timestamp-authority-fips affected chainguard timestamp-authority-fips
up affected chainguard up
up affected wolfi up
vault-csi-provider affected chainguard vault-csi-provider
volcano affected chainguard volcano
volcano-fips affected chainguard volcano-fips
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
Upstream advisory

CVE-2023-36036

GoogleExploitedCISA KEV listedCRITICAL2023-11-14

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVEs:CVE-2023-36036

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_11_23h2 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

openSUSE-SU-2023:0387-1

Open SourceExploitedCISA KEV listedCRITICAL2023-11-30

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.5 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5569-1

Open SourceExploitedCISA KEV listed2023-11-30

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-6345

Open SourceExploitedCISA KEV listedCRITICAL2023-11-29

DEBIAN-CVE-2023-6345

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6345

Project ZeroExploitedCISA KEV listed2023-11-28

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVEs:CVE-2023-6345

Upstream advisory

CVE-2023-6345

Open SourceExploitedCISA KEV listedCRITICAL2023-11-28

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVEs:CVE-2023-6345

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2023-6345

GoogleExploitedCISA KEV listed2023-11-28

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVEs:CVE-2023-6345

Upstream advisory

CVE-2023-36033

GoogleExploitedCISA KEV listedCRITICAL2023-11-14

Windows DWM Core Library Elevation of Privilege Vulnerability

CVEs:CVE-2023-36033

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_11_23h2 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_2022_23h2 affected microsoft
Upstream advisory

CVE-2023-42917

GoogleExploitedCISA KEV listedCRITICAL2023-11-30

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that...

CVEs:CVE-2023-42917

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
fedora affected fedoraproject
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
webkitgtk\+ affected webkitgtk
Upstream advisory

CVE-2023-42917

GoogleExploitedCISA KEV listed2023-11-30

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

CVEs:CVE-2023-42917

Upstream advisory

CVE-2023-42917

Project ZeroExploitedCISA KEV listed2023-11-30

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

CVEs:CVE-2023-42917

Upstream advisory

CVE-2023-33106

GoogleExploitedCISA KEV listedCRITICAL2023-11-06

Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

CVEs:CVE-2023-33106

Affected products

ProductStatusVendorPackageEcosystem
ar8035_firmware affected qualcomm
csra6620_firmware affected qualcomm
csra6640_firmware affected qualcomm
fastconnect_6200_firmware affected qualcomm
fastconnect_6700_firmware affected qualcomm
fastconnect_6800_firmware affected qualcomm
fastconnect_6900_firmware affected qualcomm
fastconnect_7800_firmware affected qualcomm
flight_rb5_5g_platform_firmware affected qualcomm
qam8255p_firmware affected qualcomm
qam8295p_firmware affected qualcomm
qam8650p_firmware affected qualcomm
qam8775p_firmware affected qualcomm
qca6174a_firmware affected qualcomm
qca6391_firmware affected qualcomm
qca6426_firmware affected qualcomm
qca6436_firmware affected qualcomm
qca6574a_firmware affected qualcomm
qca6574au_firmware affected qualcomm
qca6574_firmware affected qualcomm
qca6595au_firmware affected qualcomm
qca6595_firmware affected qualcomm
qca6696_firmware affected qualcomm
qca6698aq_firmware affected qualcomm
qca6797aq_firmware affected qualcomm
qca8081_firmware affected qualcomm
qca8337_firmware affected qualcomm
qca9377_firmware affected qualcomm
qcm2290_firmware affected qualcomm
qcm4290_firmware affected qualcomm
qcm4325_firmware affected qualcomm
qcm4490_firmware affected qualcomm
qcm5430_firmware affected qualcomm
qcm6490_firmware affected qualcomm
qcm8550_firmware affected qualcomm
qcn6024_firmware affected qualcomm
qcn9011_firmware affected qualcomm
qcn9012_firmware affected qualcomm
qcn9024_firmware affected qualcomm
qcs2290_firmware affected qualcomm
qcs410_firmware affected qualcomm
qcs4290_firmware affected qualcomm
qcs4490_firmware affected qualcomm
qcs5430_firmware affected qualcomm
qcs610_firmware affected qualcomm
qcs6490_firmware affected qualcomm
qcs7230_firmware affected qualcomm
qcs8250_firmware affected qualcomm
qcs8550_firmware affected qualcomm
qrb5165m_firmware affected qualcomm
qrb5165n_firmware affected qualcomm
qualcomm_215_mobile_platform_firmware affected qualcomm
robotics_rb5_platform_firmware affected qualcomm
sa4150p_firmware affected qualcomm
sa4155p_firmware affected qualcomm
sa6145p_firmware affected qualcomm
sa6150p_firmware affected qualcomm
sa6155p_firmware affected qualcomm
sa8145p_firmware affected qualcomm
sa8150p_firmware affected qualcomm
sa8155p_firmware affected qualcomm
sa8195p_firmware affected qualcomm
sa8255p_firmware affected qualcomm
sa8295p_firmware affected qualcomm
sa8770p_firmware affected qualcomm
sa8775p_firmware affected qualcomm
sa9000p_firmware affected qualcomm
sd660_firmware affected qualcomm
sd865_5g_firmware affected qualcomm
sd888_firmware affected qualcomm
sd_8_gen1_5g_firmware affected qualcomm
sg4150p_firmware affected qualcomm
sg8275p_firmware affected qualcomm
sm4125_firmware affected qualcomm
sm7250p_firmware affected qualcomm
sm7315_firmware affected qualcomm
sm7325p_firmware affected qualcomm
sm8550p_firmware affected qualcomm
smart_audio_400_platform_firmware affected qualcomm
snapdragon_439_mobile_platform_firmware affected qualcomm
snapdragon_460_mobile_platform_firmware affected qualcomm
snapdragon_480_5g_mobile_platform_firmware affected qualcomm
snapdragon_480\+_5g_mobile_platform_firmware affected qualcomm
snapdragon_4_gen_1_mobile_platform_firmware affected qualcomm
snapdragon_4_gen_2_mobile_platform_firmware affected qualcomm
snapdragon_660_mobile_platform_firmware affected qualcomm
snapdragon_662_mobile_platform_firmware affected qualcomm
snapdragon_680_4g_mobile_platform_firmware affected qualcomm
snapdragon_685_4g_mobile_platform_firmware affected qualcomm
snapdragon_690_5g_mobile_platform_firmware affected qualcomm
snapdragon_695_5g_mobile_platform_firmware affected qualcomm
snapdragon_750g_5g_mobile_platform_firmware affected qualcomm
snapdragon_765_5g_mobile_platform_firmware affected qualcomm
snapdragon_765g_5g_mobile_platform_firmware affected qualcomm
snapdragon_768g_5g_mobile_platform_firmware affected qualcomm
snapdragon_778g_5g_mobile_platform_firmware affected qualcomm
snapdragon_778g\+_5g_mobile_platform_firmware affected qualcomm
snapdragon_780g_5g_mobile_platform_firmware affected qualcomm
snapdragon_782g_mobile_platform_firmware affected qualcomm
snapdragon_7c\+_gen_3_compute_firmware affected qualcomm
snapdragon_865_5g_mobile_platform_firmware affected qualcomm
snapdragon_865\+_5g_mobile_platform_firmware affected qualcomm
snapdragon_870_5g_mobile_platform_firmware affected qualcomm
snapdragon_888_5g_mobile_platform_firmware affected qualcomm
snapdragon_888\+_5g_mobile_platform_firmware affected qualcomm
snapdragon_8_gen_1_mobile_platform_firmware affected qualcomm
snapdragon_8\+_gen_1_mobile_platform_firmware affected qualcomm
snapdragon_8_gen_2_mobile_platform_firmware affected qualcomm
snapdragon_8\+_gen_2_mobile_platform_firmware affected qualcomm
snapdragon_ar2_gen_1_platform_firmware affected qualcomm
snapdragon_auto_5g_modem-rf_firmware affected qualcomm
snapdragon_w5\+_gen_1_wearable_platform_firmware affected qualcomm
snapdragon_x12_lte_modem_firmware affected qualcomm
snapdragon_x55_5g_modem-rf_system_firmware affected qualcomm
snapdragon_x65_5g_modem-rf_system_firmware affected qualcomm
snapdragon_xr2_5g_platform_firmware affected qualcomm
snapdragon_xr2\+_gen_1_platform_firmware affected qualcomm
ssg2115p_firmware affected qualcomm
ssg2125p_firmware affected qualcomm
sw5100_firmware affected qualcomm
sw5100p_firmware affected qualcomm
sxr1230p_firmware affected qualcomm
sxr2130_firmware affected qualcomm
sxr2230p_firmware affected qualcomm
video_collaboration_vc1_platform_firmware affected qualcomm
video_collaboration_vc3_platform_firmware affected qualcomm
video_collaboration_vc5_platform_firmware affected qualcomm
wcd9326_firmware affected qualcomm
wcd9335_firmware affected qualcomm
wcd9341_firmware affected qualcomm
wcd9370_firmware affected qualcomm
wcd9375_firmware affected qualcomm
wcd9380_firmware affected qualcomm
wcd9385_firmware affected qualcomm
wcd9390_firmware affected qualcomm
wcd9395_firmware affected qualcomm
wcn3615_firmware affected qualcomm
wcn3660b_firmware affected qualcomm
wcn3680b_firmware affected qualcomm
wcn3910_firmware affected qualcomm
wcn3950_firmware affected qualcomm
wcn3980_firmware affected qualcomm
wcn3988_firmware affected qualcomm
wcn3990_firmware affected qualcomm
wcn6740_firmware affected qualcomm
wsa8810_firmware affected qualcomm
wsa8815_firmware affected qualcomm
wsa8830_firmware affected qualcomm
wsa8832_firmware affected qualcomm
wsa8835_firmware affected qualcomm
wsa8840_firmware affected qualcomm
wsa8845_firmware affected qualcomm
wsa8845h_firmware affected qualcomm
Upstream advisory

CVE-2023-33107

GoogleExploitedCISA KEV listedCRITICAL2023-11-06

Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

CVEs:CVE-2023-33107

Affected products

ProductStatusVendorPackageEcosystem
315_5g_iot_modem_firmware affected qualcomm
apq8017_firmware affected qualcomm
apq8064au_firmware affected qualcomm
aqt1000_firmware affected qualcomm
ar8031_firmware affected qualcomm
ar8035_firmware affected qualcomm
csra6620_firmware affected qualcomm
csra6640_firmware affected qualcomm
csrb31024_firmware affected qualcomm
c-v2x_9150_firmware affected qualcomm
fastconnect_6200_firmware affected qualcomm
fastconnect_6700_firmware affected qualcomm
fastconnect_6800_firmware affected qualcomm
fastconnect_6900_firmware affected qualcomm
fastconnect_7800_firmware affected qualcomm
flight_rb5_5g_platform_firmware affected qualcomm
mdm9250_firmware affected qualcomm
mdm9650_firmware affected qualcomm
msm8108_firmware affected qualcomm
msm8209_firmware affected qualcomm
msm8608_firmware affected qualcomm
msm8909w_firmware affected qualcomm
msm8996au_firmware affected qualcomm
qam8255p_firmware affected qualcomm
qam8295p_firmware affected qualcomm
qam8650p_firmware affected qualcomm
qam8775p_firmware affected qualcomm
qca6174a_firmware affected qualcomm
qca6310_firmware affected qualcomm
qca6320_firmware affected qualcomm
qca6335_firmware affected qualcomm
qca6391_firmware affected qualcomm
qca6420_firmware affected qualcomm
qca6421_firmware affected qualcomm
qca6426_firmware affected qualcomm
qca6430_firmware affected qualcomm
qca6431_firmware affected qualcomm
qca6436_firmware affected qualcomm
qca6564a_firmware affected qualcomm
qca6564au_firmware affected qualcomm
qca6564_firmware affected qualcomm
qca6574a_firmware affected qualcomm
qca6574au_firmware affected qualcomm
qca6574_firmware affected qualcomm
qca6595au_firmware affected qualcomm
qca6595_firmware affected qualcomm
qca6696_firmware affected qualcomm
qca6698aq_firmware affected qualcomm
qca6797aq_firmware affected qualcomm
qca8081_firmware affected qualcomm
qca8337_firmware affected qualcomm
qca9377_firmware affected qualcomm
qcm2290_firmware affected qualcomm
qcm4290_firmware affected qualcomm
qcm4325_firmware affected qualcomm
qcm4490_firmware affected qualcomm
qcm5430_firmware affected qualcomm
qcm6125_firmware affected qualcomm
qcm6490_firmware affected qualcomm
qcm8550_firmware affected qualcomm
qcn6024_firmware affected qualcomm
qcn9011_firmware affected qualcomm
qcn9012_firmware affected qualcomm
qcn9024_firmware affected qualcomm
qcn9074_firmware affected qualcomm
qcs2290_firmware affected qualcomm
qcs410_firmware affected qualcomm
qcs4290_firmware affected qualcomm
qcs4490_firmware affected qualcomm
qcs5430_firmware affected qualcomm
qcs610_firmware affected qualcomm
qcs6125_firmware affected qualcomm
qcs6490_firmware affected qualcomm
qcs7230_firmware affected qualcomm
qcs8155_firmware affected qualcomm
qcs8250_firmware affected qualcomm
qcs8550_firmware affected qualcomm
qrb5165m_firmware affected qualcomm
qrb5165n_firmware affected qualcomm
qsm8250_firmware affected qualcomm
qualcomm_205_mobile_platform_firmware affected qualcomm
qualcomm_215_mobile_platform_firmware affected qualcomm
robotics_rb3_platform_firmware affected qualcomm
robotics_rb5_platform_firmware affected qualcomm
sa4150p_firmware affected qualcomm
sa4155p_firmware affected qualcomm
sa6145p_firmware affected qualcomm
sa6150p_firmware affected qualcomm
sa6155_firmware affected qualcomm
sa6155p_firmware affected qualcomm
sa8145p_firmware affected qualcomm
sa8150p_firmware affected qualcomm
sa8155_firmware affected qualcomm
sa8155p_firmware affected qualcomm
sa8195p_firmware affected qualcomm
sa8255p_firmware affected qualcomm
sa8295p_firmware affected qualcomm
sa8770p_firmware affected qualcomm
sa8775p_firmware affected qualcomm
sa9000p_firmware affected qualcomm
sd626_firmware affected qualcomm
sd660_firmware affected qualcomm
sd670_firmware affected qualcomm
sd_675_firmware affected qualcomm
sd675_firmware affected qualcomm
sd730_firmware affected qualcomm
sd835_firmware affected qualcomm
sd855_firmware affected qualcomm
sd865_5g_firmware affected qualcomm
sd888_firmware affected qualcomm
sd_8_gen1_5g_firmware affected qualcomm
sdm429w_firmware affected qualcomm
sdx20m_firmware affected qualcomm
sdx55_firmware affected qualcomm
sg4150p_firmware affected qualcomm
sg8275p_firmware affected qualcomm
sm4125_firmware affected qualcomm
sm6250_firmware affected qualcomm
sm7250p_firmware affected qualcomm
sm7315_firmware affected qualcomm
sm7325p_firmware affected qualcomm
sm8550p_firmware affected qualcomm
smart_audio_200_platform_firmware affected qualcomm
smart_audio_400_platform_firmware affected qualcomm
smart_display_200_platform_firmware affected qualcomm
snapdragon_208_processor_firmware affected qualcomm
snapdragon_210_processor_firmware affected qualcomm
snapdragon_212_mobile_platform_firmware affected qualcomm
snapdragon_425_mobile_platform_firmware affected qualcomm
snapdragon_429_mobile_platform_firmware affected qualcomm
snapdragon_439_mobile_platform_firmware affected qualcomm
snapdragon_460_mobile_platform_firmware affected qualcomm
snapdragon_480_5g_mobile_platform_firmware affected qualcomm
snapdragon_480\+_5g_mobile_platform_firmware affected qualcomm
snapdragon_4_gen_1_mobile_platform_firmware affected qualcomm
snapdragon_4_gen_2_mobile_platform_firmware affected qualcomm
snapdragon_625_mobile_platform_firmware affected qualcomm
snapdragon_626_mobile_platform_firmware affected qualcomm
snapdragon_630_mobile_platform_firmware affected qualcomm
snapdragon_632_mobile_platform_firmware affected qualcomm
snapdragon_636_mobile_platform_firmware affected qualcomm
snapdragon_660_mobile_platform_firmware affected qualcomm
snapdragon_662_mobile_platform_firmware affected qualcomm
snapdragon_665_mobile_platform_firmware affected qualcomm
snapdragon_670_mobile_platform_firmware affected qualcomm
snapdragon_675_mobile_platform_firmware affected qualcomm
snapdragon_678_mobile_platform_firmware affected qualcomm
snapdragon_680_4g_mobile_platform_firmware affected qualcomm
snapdragon_685_4g_mobile_platform_firmware affected qualcomm
snapdragon_690_5g_mobile_platform_firmware affected qualcomm
snapdragon_695_5g_mobile_platform_firmware affected qualcomm
snapdragon_710_mobile_platform_firmware affected qualcomm
snapdragon_720g_mobile_platform_firmware affected qualcomm
snapdragon_730g_mobile_platform_firmware affected qualcomm
snapdragon_730_mobile_platform_firmware affected qualcomm
snapdragon_732g_mobile_platform_firmware affected qualcomm
snapdragon_750g_5g_mobile_platform_firmware affected qualcomm
snapdragon_765_5g_mobile_platform_firmware affected qualcomm
snapdragon_765g_5g_mobile_platform_firmware affected qualcomm
snapdragon_768g_5g_mobile_platform_firmware affected qualcomm
snapdragon_778g_5g_mobile_platform_firmware affected qualcomm
snapdragon_778g\+_5g_mobile_platform_firmware affected qualcomm
snapdragon_780g_5g_mobile_platform_firmware affected qualcomm
snapdragon_782g_mobile_platform_firmware affected qualcomm
snapdragon_7c\+_gen_3_compute_firmware affected qualcomm
snapdragon_820_automotive_platform_firmware affected qualcomm
snapdragon_835_mobile_pc_platform_firmware affected qualcomm
snapdragon_845_mobile_platform_firmware affected qualcomm
snapdragon_855\+\/860_mobile_platform_firmware affected qualcomm
snapdragon_855_mobile_platform_firmware affected qualcomm
snapdragon_865_5g_mobile_platform_firmware affected qualcomm
snapdragon_865\+_5g_mobile_platform_firmware affected qualcomm
snapdragon_870_5g_mobile_platform_firmware affected qualcomm
snapdragon_888_5g_mobile_platform_firmware affected qualcomm
snapdragon_888\+_5g_mobile_platform_firmware affected qualcomm
snapdragon_8_gen_1_mobile_platform_firmware affected qualcomm
snapdragon_8\+_gen_1_mobile_platform_firmware affected qualcomm
snapdragon_8_gen_2_mobile_platform_firmware affected qualcomm
snapdragon_8\+_gen_2_mobile_platform_firmware affected qualcomm
snapdragon_ar2_gen_1_platform_firmware affected qualcomm
snapdragon_auto_4g_modem_firmware affected qualcomm
snapdragon_auto_5g_modem-rf_firmware affected qualcomm
snapdragon_w5\+_gen_1_wearable_platform_firmware affected qualcomm
snapdragon_wear_2100_platform_firmware affected qualcomm
snapdragon_wear_2500_platform_firmware affected qualcomm
snapdragon_wear_3100_platform_firmware affected qualcomm
snapdragon_wear_4100\+_platform_firmware affected qualcomm
snapdragon_x12_lte_modem_firmware affected qualcomm
snapdragon_x20_lte_modem_firmware affected qualcomm
snapdragon_x24_lte_modem_firmware affected qualcomm
snapdragon_x50_5g_modem-rf_system_firmware affected qualcomm
snapdragon_x55_5g_modem-rf_system_firmware affected qualcomm
snapdragon_x65_5g_modem-rf_system_firmware affected qualcomm
snapdragon_xr1_platform_firmware affected qualcomm
snapdragon_xr2_5g_platform_firmware affected qualcomm
snapdragon_xr2\+_gen_1_platform_firmware affected qualcomm
ssg2115p_firmware affected qualcomm
ssg2125p_firmware affected qualcomm
sw5100_firmware affected qualcomm
sw5100p_firmware affected qualcomm
sxr1120_firmware affected qualcomm
sxr1230p_firmware affected qualcomm
sxr2130_firmware affected qualcomm
sxr2230p_firmware affected qualcomm
video_collaboration_vc1_platform_firmware affected qualcomm
video_collaboration_vc3_platform_firmware affected qualcomm
video_collaboration_vc5_platform_firmware affected qualcomm
vision_intelligence_100_platform_firmware affected qualcomm
vision_intelligence_200_platform_firmware affected qualcomm
vision_intelligence_300_platform_firmware affected qualcomm
vision_intelligence_400_platform_firmware affected qualcomm
wcd9326_firmware affected qualcomm
wcd9335_firmware affected qualcomm
wcd9340_firmware affected qualcomm
wcd9341_firmware affected qualcomm
wcd9370_firmware affected qualcomm
wcd9371_firmware affected qualcomm
wcd9375_firmware affected qualcomm
wcd9380_firmware affected qualcomm
wcd9385_firmware affected qualcomm
wcd9390_firmware affected qualcomm
wcd9395_firmware affected qualcomm
wcn3610_firmware affected qualcomm
wcn3615_firmware affected qualcomm
wcn3620_firmware affected qualcomm
wcn3660b_firmware affected qualcomm
wcn3680b_firmware affected qualcomm
wcn3680_firmware affected qualcomm
wcn3910_firmware affected qualcomm
wcn3950_firmware affected qualcomm
wcn3980_firmware affected qualcomm
wcn3988_firmware affected qualcomm
wcn3990_firmware affected qualcomm
wcn6740_firmware affected qualcomm
wsa8810_firmware affected qualcomm
wsa8815_firmware affected qualcomm
wsa8830_firmware affected qualcomm
wsa8832_firmware affected qualcomm
wsa8835_firmware affected qualcomm
wsa8840_firmware affected qualcomm
wsa8845_firmware affected qualcomm
wsa8845h_firmware affected qualcomm
Upstream advisory

CVE-2023-33063

GoogleExploitedCISA KEV listedCRITICAL2023-11-06

Memory corruption in DSP Services during a remote call from HLOS to DSP.

CVEs:CVE-2023-33063

Affected products

ProductStatusVendorPackageEcosystem
315_5g_iot_modem_firmware affected qualcomm
8098_firmware affected qualcomm
8953pro_firmware affected qualcomm
8998_firmware affected qualcomm
apq5053-aa_firmware affected qualcomm
apq8009_firmware affected qualcomm
apq8017_firmware affected qualcomm
apq8053-aa_firmware affected qualcomm
apq8053-ac_firmware affected qualcomm
aqt1000_firmware affected qualcomm
ar8031_firmware affected qualcomm
ar8035_firmware affected qualcomm
ar9380_firmware affected qualcomm
csr8811_firmware affected qualcomm
csra6620_firmware affected qualcomm
csra6640_firmware affected qualcomm
csrb31024_firmware affected qualcomm
c-v2x_9150_firmware affected qualcomm
flight_rb5_5g_platform_firmware affected qualcomm
immersive_home_214_platform_firmware affected qualcomm
immersive_home_216_platform_firmware affected qualcomm
immersive_home_316_platform_firmware affected qualcomm
immersive_home_318_platform_firmware affected qualcomm
ipq4018_firmware affected qualcomm
ipq4019_firmware affected qualcomm
ipq4028_firmware affected qualcomm
ipq4029_firmware affected qualcomm
ipq5010_firmware affected qualcomm
ipq6010_firmware affected qualcomm
ipq6018_firmware affected qualcomm
ipq6028_firmware affected qualcomm
ipq8064_firmware affected qualcomm
ipq8065_firmware affected qualcomm
ipq8068_firmware affected qualcomm
ipq8070a_firmware affected qualcomm
ipq8070_firmware affected qualcomm
ipq8071a_firmware affected qualcomm
ipq8072a_firmware affected qualcomm
ipq8074a_firmware affected qualcomm
ipq8076a_firmware affected qualcomm
ipq8076_firmware affected qualcomm
ipq8078a_firmware affected qualcomm
ipq8078_firmware affected qualcomm
ipq8173_firmware affected qualcomm
ipq8174_firmware affected qualcomm
mdm9650_firmware affected qualcomm
msm8905_firmware affected qualcomm
qam8255p_firmware affected qualcomm
qam8295p_firmware affected qualcomm
qam8650p_firmware affected qualcomm
qam8775p_firmware affected qualcomm
qca4024_firmware affected qualcomm
qca6174a_firmware affected qualcomm
qca6310_firmware affected qualcomm
qca6320_firmware affected qualcomm
qca6335_firmware affected qualcomm
qca6390_firmware affected qualcomm
qca6391_firmware affected qualcomm
qca6420_firmware affected qualcomm
qca6421_firmware affected qualcomm
qca6426_firmware affected qualcomm
qca6430_firmware affected qualcomm
qca6431_firmware affected qualcomm
qca6436_firmware affected qualcomm
qca6564au_firmware affected qualcomm
qca6564_firmware affected qualcomm
qca6574a_firmware affected qualcomm
qca6574au_firmware affected qualcomm
qca6574_firmware affected qualcomm
qca6595au_firmware affected qualcomm
qca6595_firmware affected qualcomm
qca6696_firmware affected qualcomm
qca6698aq_firmware affected qualcomm
qca6797aq_firmware affected qualcomm
qca7500_firmware affected qualcomm
qca8075_firmware affected qualcomm
qca8081_firmware affected qualcomm
qca8337_firmware affected qualcomm
qca9377_firmware affected qualcomm
qca9880_firmware affected qualcomm
qca9886_firmware affected qualcomm
qca9888_firmware affected qualcomm
qca9889_firmware affected qualcomm
qca9898_firmware affected qualcomm
qca9980_firmware affected qualcomm
qca9984_firmware affected qualcomm
qca9985_firmware affected qualcomm
qca9990_firmware affected qualcomm
qca9992_firmware affected qualcomm
qca9994_firmware affected qualcomm
qcm2290_firmware affected qualcomm
qcm4290_firmware affected qualcomm
qcm4325_firmware affected qualcomm
qcm4490_firmware affected qualcomm
qcm5430_firmware affected qualcomm
qcm6125_firmware affected qualcomm
qcm6490_firmware affected qualcomm
qcn5022_firmware affected qualcomm
qcn5024_firmware affected qualcomm
qcn5052_firmware affected qualcomm
qcn5122_firmware affected qualcomm
qcn5124_firmware affected qualcomm
qcn5152_firmware affected qualcomm
qcn5154_firmware affected qualcomm
qcn5164_firmware affected qualcomm
qcn6023_firmware affected qualcomm
qcn6024_firmware affected qualcomm
qcn9000_firmware affected qualcomm
qcn9011_firmware affected qualcomm
qcn9012_firmware affected qualcomm
qcn9022_firmware affected qualcomm
qcn9024_firmware affected qualcomm
qcn9070_firmware affected qualcomm
qcn9072_firmware affected qualcomm
qcn9074_firmware affected qualcomm
qcn9100_firmware affected qualcomm
qcs2290_firmware affected qualcomm
qcs410_firmware affected qualcomm
qcs4290_firmware affected qualcomm
qcs4490_firmware affected qualcomm
qcs5430_firmware affected qualcomm
qcs610_firmware affected qualcomm
qcs6125_firmware affected qualcomm
qcs6490_firmware affected qualcomm
qcs7230_firmware affected qualcomm
qcs8155_firmware affected qualcomm
qcs8250_firmware affected qualcomm
qcs8550_firmware affected qualcomm
qm215_firmware affected qualcomm
qrb5165_firmware affected qualcomm
qrb5165m_firmware affected qualcomm
qrb5165n_firmware affected qualcomm
qsm8250_firmware affected qualcomm
s820a_firmware affected qualcomm
sa4150p_firmware affected qualcomm
sa4155p_firmware affected qualcomm
sa6145p_firmware affected qualcomm
sa6150p_firmware affected qualcomm
sa6155_firmware affected qualcomm
sa6155p_firmware affected qualcomm
sa8145p_firmware affected qualcomm
sa8150p_firmware affected qualcomm
sa8155_firmware affected qualcomm
sa8155p_firmware affected qualcomm
sa8195p_firmware affected qualcomm
sa8255p_firmware affected qualcomm
sa8295p_firmware affected qualcomm
sa8770p_firmware affected qualcomm
sa8775p_firmware affected qualcomm
sa9000p_firmware affected qualcomm
sd626_firmware affected qualcomm
sd660_firmware affected qualcomm
sd670_firmware affected qualcomm
sd_675_firmware affected qualcomm
sd675_firmware affected qualcomm
sd730_firmware affected qualcomm
sd835_firmware affected qualcomm
sd855_firmware affected qualcomm
sd865_5g_firmware affected qualcomm
sd888_firmware affected qualcomm
sda845_firmware affected qualcomm
sdm429w_firmware affected qualcomm
sdm660_firmware affected qualcomm
sdm845_firmware affected qualcomm
sdx55_firmware affected qualcomm
sg4150p_firmware affected qualcomm
sg8275p_firmware affected qualcomm
sm4125_firmware affected qualcomm
sm4250-aa_firmware affected qualcomm
sm4350-ac_firmware affected qualcomm
sm4350_firmware affected qualcomm
sm4375_firmware affected qualcomm
sm6125_firmware affected qualcomm
sm6150-ac_firmware affected qualcomm
sm6225-ad_firmware affected qualcomm
sm6225_firmware affected qualcomm
sm6250_firmware affected qualcomm
sm6350_firmware affected qualcomm
sm6375_firmware affected qualcomm
sm7125_firmware affected qualcomm
sm7150-aa_firmware affected qualcomm
sm7150-ab_firmware affected qualcomm
sm7150-ac_firmware affected qualcomm
sm7225_firmware affected qualcomm
sm7250-aa_firmware affected qualcomm
sm7250-ab_firmware affected qualcomm
sm7250-ac_firmware affected qualcomm
sm7250p_firmware affected qualcomm
sm7315_firmware affected qualcomm
sm7325-ae_firmware affected qualcomm
sm7325-af_firmware affected qualcomm
sm7325_firmware affected qualcomm
sm7325p_firmware affected qualcomm
sm7350-ab_firmware affected qualcomm
sm8150-ac_firmware affected qualcomm
sm8150_firmware affected qualcomm
sm8250-ab_firmware affected qualcomm
sm8250-ac_firmware affected qualcomm
sm8350-ac_firmware affected qualcomm
sm8350_firmware affected qualcomm
sm8450_firmware affected qualcomm
sm8475_firmware affected qualcomm
sm8550p_firmware affected qualcomm
snapdragon_210_processor_firmware affected qualcomm
snapdragon_212_mobile_platform_firmware affected qualcomm
snapdragon_425_mobile_platform_firmware affected qualcomm
snapdragon_429_mobile_platform_firmware affected qualcomm
snapdragon_439_mobile_platform_firmware affected qualcomm
snapdragon_4_gen_2_mobile_platform_firmware affected qualcomm
snapdragon_625_mobile_platform_firmware affected qualcomm
snapdragon_632_mobile_platform_firmware affected qualcomm
snapdragon_662_mobile_platform_firmware affected qualcomm
snapdragon_675_mobile_platform_firmware affected qualcomm
snapdragon_7c\+_gen_3_compute_firmware affected qualcomm
snapdragon_8_gen_2_mobile_platform_firmware affected qualcomm
snapdragon_8\+_gen_2_mobile_platform_firmware affected qualcomm
snapdragon_ar2_gen_1_platform_firmware affected qualcomm
snapdragon_auto_4g_modem_firmware affected qualcomm
snapdragon_auto_5g_modem-rf_firmware affected qualcomm
snapdragon_w5\+_gen_1_wearable_platform_firmware affected qualcomm
snapdragon_wear_4100\+_platform_firmware affected qualcomm
snapdragon_x12_lte_modem_firmware affected qualcomm
snapdragon_x24_lte_modem_firmware affected qualcomm
snapdragon_x50_5g_modem-rf_system_firmware affected qualcomm
snapdragon_x55_5g_modem-rf_system_firmware affected qualcomm
snapdragon_x65_5g_modem-rf_system_firmware affected qualcomm
snapdragon_xr1_platform_firmware affected qualcomm
snapdragon_xr2_5g_platform_firmware affected qualcomm
snapdragon_xr2\+_gen_1_platform_firmware affected qualcomm
ssg2115p_firmware affected qualcomm
ssg2125p_firmware affected qualcomm
sw5100_firmware affected qualcomm
sw5100p_firmware affected qualcomm
sxr1120_firmware affected qualcomm
sxr1230p_firmware affected qualcomm
sxr2130_firmware affected qualcomm
sxr2230p_firmware affected qualcomm
video_collaboration_vc1_platform_firmware affected qualcomm
video_collaboration_vc3_platform_firmware affected qualcomm
video_collaboration_vc5_platform_firmware affected qualcomm
vision_intelligence_300_platform_firmware affected qualcomm
vision_intelligence_400_platform_firmware affected qualcomm
wcd9326_firmware affected qualcomm
wcd9335_firmware affected qualcomm
wcd9340_firmware affected qualcomm
wcd9341_firmware affected qualcomm
wcd9360_firmware affected qualcomm
wcd9370_firmware affected qualcomm
wcd9371_firmware affected qualcomm
wcd9375_firmware affected qualcomm
wcd9380_firmware affected qualcomm
wcd9385_firmware affected qualcomm
wcd9390_firmware affected qualcomm
wcd9395_firmware affected qualcomm
wcn3610_firmware affected qualcomm
wcn3615_firmware affected qualcomm
wcn3620_firmware affected qualcomm
wcn3660b_firmware affected qualcomm
wcn3680b_firmware affected qualcomm
wcn3680_firmware affected qualcomm
wcn3910_firmware affected qualcomm
wcn3950_firmware affected qualcomm
wcn3980_firmware affected qualcomm
wcn3988_firmware affected qualcomm
wcn3990_firmware affected qualcomm
wcn3991_firmware affected qualcomm
wcn3998_firmware affected qualcomm
wcn6740_firmware affected qualcomm
wcn6750_firmware affected qualcomm
wcn685x-1_firmware affected qualcomm
wcn685x-5_firmware affected qualcomm
wcn785x-1_firmware affected qualcomm
wcn785x-5_firmware affected qualcomm
wsa8810_firmware affected qualcomm
wsa8815_firmware affected qualcomm
wsa8830_firmware affected qualcomm
wsa8832_firmware affected qualcomm
wsa8835_firmware affected qualcomm
wsa8840_firmware affected qualcomm
wsa8845_firmware affected qualcomm
wsa8845h_firmware affected qualcomm
Upstream advisory

MGASA-2023-0322

Open SourceActive exploitation (sightings)CRITICAL2023-11-20

Updated chromium-browser-stable packages fix bugs and vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

openSUSE-SU-2023:0368-1

Open SourceActive exploitation (sightings)CRITICAL2023-11-14

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.5 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
gn affected openSUSE:Leap 15.5 gn
gn affected SUSE:Package Hub 15 SP4 gn
gn affected SUSE:Package Hub 15 SP5 gn
gn affected openSUSE:Leap 15.4 gn
Upstream advisory

DSA-5546-1

Open SourceActive exploitation (sightings)2023-11-02

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-5482

Open SourceActive exploitation (sightings)HIGH2023-11-01

DEBIAN-CVE-2023-5482

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-hq6q-c2x6-hmch

Open SourceActive exploitation (sightings)HIGH2023-11-14

Kubernetes Improper Input Validation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-hq6q-c2x6-hmch

Open SourceActive exploitation (sightings)HIGH2023-11-14

Kubernetes Improper Input Validation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.8 affected wolfi argo-cd-2.8
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.9 affected wolfi argo-cd-2.9
argo-cd-2.9 affected chainguard argo-cd-2.9
argo-cd-fips-2.8 affected chainguard argo-cd-fips-2.8
argo-cd-fips-2.9 affected chainguard argo-cd-fips-2.9
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-efs-csi-driver-fips-1.6 affected chainguard aws-efs-csi-driver-fips-1.6
calico affected wolfi calico
calico affected chainguard calico
calico-fips affected chainguard calico-fips
calico-fips-3.25 affected chainguard calico-fips-3.25
cluster-autoscaler-1.25 affected chainguard cluster-autoscaler-1.25
cluster-autoscaler-1.25 affected wolfi cluster-autoscaler-1.25
cluster-autoscaler-fips-1.25 affected chainguard cluster-autoscaler-fips-1.25
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
Upstream advisory

AZL-32005

Open SourceActive exploitation (sightings)HIGH2023-11-14

CVE-2023-5528 affecting package kubernetes for versions less than 1.28.4-1

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:2 kubernetes
Upstream advisory

AZL-34894

Open SourceActive exploitation (sightings)HIGH2023-11-14

CVE-2023-5528 affecting package kubernetes for versions less than 1.28.7-2

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:3 kubernetes
Upstream advisory

CVE-2023-5528

GoogleActive exploitation (sightings)2023-11-14

A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes.

CVEs:CVE-2023-5528

Upstream advisory

CVE-2023-5528

Open SourceActive exploitation (sightings)HIGH2023-11-14

A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree stora...

CVEs:CVE-2023-5528

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
kubernetes affected kubernetes
Upstream advisory

CVE-2023-5528

Open SourceActive exploitation (sightings)HIGH2023-11-14

Kubernetes Improper Input Validation vulnerability

CVEs:CVE-2023-5528

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2023-36034

Open SourceActive exploitation (sightings)CRITICAL2023-11-02

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2023-36034

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-r6cc-7wj7-gfx2

Open SourceActive exploitation (sightings)CRITICAL2023-11-03

Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-csi/csi-proxy affected github.com github.com/kubernetes-csi/csi-proxy
kubernetes-csi/csi-proxy/v2 affected github.com github.com/kubernetes-csi/csi-proxy/v2
Upstream advisory

GHSA-r6cc-7wj7-gfx2

Open SourceActive exploitation (sightings)CRITICAL2023-11-03

Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-csi/csi-proxy affected github.com github.com/kubernetes-csi/csi-proxy
kubernetes-csi/csi-proxy/v2 affected github.com github.com/kubernetes-csi/csi-proxy/v2
Upstream advisory

DEBIAN-CVE-2023-3893

Open SourceActive exploitation (sightings)HIGH2023-11-03

DEBIAN-CVE-2023-3893

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
kubernetes affected Debian:12 kubernetes
Upstream advisory

CVE-2023-36014

Open SourceActive exploitation (sightings)CRITICAL2023-11-09

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2023-36014

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2023-6350

Open SourceActive exploitation (sightings)CRITICAL2023-11-29

DEBIAN-CVE-2023-6350

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6350

GoogleActive exploitation (sightings)2023-11-28

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

CVEs:CVE-2023-6350

Upstream advisory

CVE-2023-6350

GoogleActive exploitation (sightings)CRITICAL2023-11-28

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

CVEs:CVE-2023-6350

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-5857

Open SourceActive exploitation (sightings)CRITICAL2023-11-01

DEBIAN-CVE-2023-5857

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-5849

Open SourceActive exploitation (sightings)CRITICAL2023-11-01

DEBIAN-CVE-2023-5849

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-36022

Open SourceActive exploitation (sightings)CRITICAL2023-11-02

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2023-36022

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2023-6347

Open SourceActive exploitation (sightings)CRITICAL2023-11-29

DEBIAN-CVE-2023-6347

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6347

GoogleActive exploitation (sightings)2023-11-28

Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6347

Upstream advisory

CVE-2023-6347

GoogleActive exploitation (sightings)CRITICAL2023-11-28

Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6347

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-5854

Open SourceActive exploitation (sightings)CRITICAL2023-11-01

DEBIAN-CVE-2023-5854

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-5480

Open SourceActive exploitation (sightings)CRITICAL2023-11-01

DEBIAN-CVE-2023-5480

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

ASB-A-298879043

GoogleActive exploitation (sightings)2023-11-01

ASB-A-298879043

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2023-6348

Open SourceActive exploitation (sightings)HIGH2023-11-29

DEBIAN-CVE-2023-6348

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6348

GoogleActive exploitation (sightings)2023-11-28

Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6348

Upstream advisory

CVE-2023-6348

GoogleActive exploitation (sightings)HIGH2023-11-28

Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6348

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-5852

Open SourceActive exploitation (sightings)CRITICAL2023-11-01

DEBIAN-CVE-2023-5852

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-5855

Open SourceActive exploitation (sightings)CRITICAL2023-11-01

DEBIAN-CVE-2023-5855

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-6346

Open SourceActive exploitation (sightings)CRITICAL2023-11-29

DEBIAN-CVE-2023-6346

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6346

GoogleActive exploitation (sightings)CRITICAL2023-11-28

Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6346

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-5850

Open SourceActive exploitation (sightings)MEDIUM2023-11-01

DEBIAN-CVE-2023-5850

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-6351

Open SourceActive exploitation (sightings)CRITICAL2023-11-29

DEBIAN-CVE-2023-6351

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6351

GoogleActive exploitation (sightings)CRITICAL2023-11-28

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

CVEs:CVE-2023-6351

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-5859

Open SourceActive exploitation (sightings)MEDIUM2023-11-01

DEBIAN-CVE-2023-5859

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-pgpj-83g3-mfr2

GoogleActive exploitation (sightings)MEDIUM2023-11-29

Jenkins Google Compute Engine Plugin has incorrect permission checks

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

GHSA-pgpj-83g3-mfr2

GoogleActive exploitation (sightings)MEDIUM2023-11-29

Jenkins Google Compute Engine Plugin has incorrect permission checks

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

CVE-2023-49652

GoogleActive exploitation (sightings)MEDIUM2023-11-29

Jenkins Google Compute Engine Plugin has incorrect permission checks

CVEs:CVE-2023-49652

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

CVE-2023-49652

GoogleActive exploitation (sightings)LOW2023-11-29

Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped cred...

CVEs:CVE-2023-49652

Affected products

ProductStatusVendorPackageEcosystem
google_compute_engine affected jenkins
Upstream advisory

CVE-2023-49652

GoogleActive exploitation (sightings)2023-11-29

Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials stored in Jenkins and to connect to Google Cloud Platform using attacker-specified credentials IDs obtained through another method, to obtain information about existing projects. This fix has been backported to 4.3.17.1.

CVEs:CVE-2023-49652

Upstream advisory

CVE-2023-5823

GoogleActive exploitation (sightings)HIGH2023-11-06

Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions.

CVEs:CVE-2023-5823

Affected products

ProductStatusVendorPackageEcosystem
tk_google_fonts_gdpr_compliant affected themekraft
Upstream advisory

CVE-2023-42531

Open SourceActive exploitation (sightings)HIGH2023-11-06

Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.

CVEs:CVE-2023-42531

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-32837

Open SourceActive exploitation (sightings)HIGH2023-11-06

In video, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08235273; I...

CVEs:CVE-2023-32837

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-298879037

GoogleActive exploitation (sightings)2023-11-01

ASB-A-298879037

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-32832

Open SourceActive exploitation (sightings)HIGH2023-11-06

In video, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08235273; Issue ID:...

CVEs:CVE-2023-32832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-298879091

GoogleActive exploitation (sightings)2023-11-01

ASB-A-298879091

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-32839

Open SourceActive exploitation (sightings)HIGH2023-11-06

In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07262576; Is...

CVEs:CVE-2023-32839

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32835

Open SourceActive exploitation (sightings)HIGH2023-11-06

In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08157918; Issue ID: ALP...

CVEs:CVE-2023-32835

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-298881373

GoogleActive exploitation (sightings)2023-11-01

ASB-A-298881373

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-32838

Open SourceActive exploitation (sightings)HIGH2023-11-06

In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310805; Is...

CVEs:CVE-2023-32838

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32836

Open SourceActive exploitation (sightings)HIGH2023-11-06

In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08126725; Issue ID:...

CVEs:CVE-2023-32836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32834

Open SourceActive exploitation (sightings)HIGH2023-11-06

In secmem, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08161762; Issue ID: ALPS081...

CVEs:CVE-2023-32834

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-298879096

GoogleActive exploitation (sightings)2023-11-01

ASB-A-298879096

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-298879097

GoogleActive exploitation (sightings)2023-11-01

ASB-A-298879097

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-32825

Open SourceActive exploitation (sightings)MEDIUM2023-11-06

In bluethooth service, there is a possible out of bounds reads due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ...

CVEs:CVE-2023-32825

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ALSA-2023:6363

GooglePoC exploitCRITICAL2023-11-07

Moderate: skopeo security update

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
skopeo affected AlmaLinux:9 skopeo
skopeo affected AlmaLinux
skopeo-tests affected AlmaLinux:9 skopeo-tests
Upstream advisory

OESA-2023-1789

Open SourcePoC exploitCRITICAL2023-11-03

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS golang
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:22.03-LTS-SP1 golang
golang affected openEuler:22.03-LTS-SP2 golang
golang affected openEuler:20.03-LTS-SP3 golang
Upstream advisory

GHSA-vvjp-q62m-2vph

Open SourcePoC exploitHIGH2023-11-09

GHSA-vvjp-q62m-2vph

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller affected wolfi actions-runner-controller
amass affected wolfi amass
amass affected chainguard amass
amazon-corretto-crypto-provider affected chainguard amazon-corretto-crypto-provider
amazon-corretto-crypto-provider affected wolfi amazon-corretto-crypto-provider
apko affected chainguard apko
apko affected wolfi apko
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.8 affected wolfi argo-cd-2.8
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-workflows affected chainguard argo-workflows
argo-workflows affected wolfi argo-workflows
atlantis affected chainguard atlantis
atlantis affected wolfi atlantis
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
bom affected chainguard bom
bom affected wolfi bom
boring-registry affected wolfi boring-registry
boring-registry affected chainguard boring-registry
buf affected wolfi buf
buf affected chainguard buf
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
caddy affected wolfi caddy
caddy affected chainguard caddy
calico affected chainguard calico
calico affected wolfi calico
capslock affected chainguard capslock
capslock affected wolfi capslock
certificate-transparency affected wolfi certificate-transparency
certificate-transparency affected chainguard certificate-transparency
cert-manager-1.11 affected wolfi cert-manager-1.11
cert-manager-1.11 affected chainguard cert-manager-1.11
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-1.13 affected wolfi cert-manager-1.13
cfssl affected chainguard cfssl
cfssl affected wolfi cfssl
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
cilium-envoy affected chainguard cilium-envoy
cilium-envoy affected wolfi cilium-envoy
cloudflared affected chainguard cloudflared
cloudflared affected wolfi cloudflared
cloud-sql-proxy affected chainguard cloud-sql-proxy
cloud-sql-proxy affected wolfi cloud-sql-proxy
cluster-autoscaler-1.25 affected wolfi cluster-autoscaler-1.25
cluster-autoscaler-1.25 affected chainguard cluster-autoscaler-1.25
cluster-proportional-autoscaler affected chainguard cluster-proportional-autoscaler
cluster-proportional-autoscaler affected wolfi cluster-proportional-autoscaler
cni-plugins affected wolfi cni-plugins
cni-plugins affected chainguard cni-plugins
configmap-reload affected wolfi configmap-reload
configmap-reload affected chainguard configmap-reload
conftest affected chainguard conftest
conftest affected wolfi conftest
consul-1.15 affected wolfi consul-1.15
consul-1.15 affected chainguard consul-1.15
consul-1.16 affected wolfi consul-1.16
consul-1.16 affected chainguard consul-1.16
containerd affected chainguard containerd
containerd affected wolfi containerd
coredns affected wolfi coredns
coredns affected chainguard coredns
cortex affected chainguard cortex
cortex affected wolfi cortex
cosign affected chainguard cosign
cosign affected wolfi cosign
crane affected wolfi crane
crane affected chainguard crane
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
croc affected wolfi croc
croc affected chainguard croc
crossplane affected chainguard crossplane
crossplane affected wolfi crossplane
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure affected wolfi crossplane-provider-azure
ctop affected chainguard ctop
ctop affected wolfi ctop
cue affected chainguard cue
cue affected wolfi cue
dask-gateway affected wolfi dask-gateway
dask-gateway affected chainguard dask-gateway
dataplaneapi affected wolfi dataplaneapi
dataplaneapi affected chainguard dataplaneapi
delve affected wolfi delve
delve affected chainguard delve
dex affected chainguard dex
dex affected wolfi dex
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
dive affected chainguard dive
dive affected wolfi dive
docker-credential-acr-env affected wolfi docker-credential-acr-env
docker-credential-acr-env affected chainguard docker-credential-acr-env
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-gcr affected wolfi docker-credential-gcr
docker-credential-gcr affected chainguard docker-credential-gcr
dockerize affected wolfi dockerize
dockerize affected chainguard dockerize
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
envoy-ratelimit affected chainguard envoy-ratelimit
envoy-ratelimit affected wolfi envoy-ratelimit
esbuild affected wolfi esbuild
esbuild affected chainguard esbuild
etcd-3.5 affected chainguard etcd-3.5
etcd-3.5 affected wolfi etcd-3.5
external-dns affected wolfi external-dns
external-dns affected chainguard external-dns
external-secrets-operator affected chainguard external-secrets-operator
external-secrets-operator affected wolfi external-secrets-operator
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
ferretdb affected chainguard ferretdb
ferretdb affected wolfi ferretdb
flannel affected chainguard flannel
flannel affected wolfi flannel
flannel-cni-plugin affected chainguard flannel-cni-plugin
flannel-cni-plugin affected wolfi flannel-cni-plugin
flux affected wolfi flux
flux affected chainguard flux
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
fq affected chainguard fq
fq affected wolfi fq
frp affected wolfi frp
frp affected chainguard frp
fulcio affected wolfi fulcio
fulcio affected chainguard fulcio
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
fzf affected chainguard fzf
fzf affected wolfi fzf
gatekeeper-3.12 affected chainguard gatekeeper-3.12
gatekeeper-3.12 affected wolfi gatekeeper-3.12
gatekeeper-3.13 affected chainguard gatekeeper-3.13
gatekeeper-3.13 affected wolfi gatekeeper-3.13
gatekeeper-3.14 affected wolfi gatekeeper-3.14
gatekeeper-3.14 affected chainguard gatekeeper-3.14
gcsfuse affected wolfi gcsfuse
gcsfuse affected chainguard gcsfuse
gitlab-kas affected chainguard gitlab-kas
gitlab-kas affected wolfi gitlab-kas
gitlab-pages affected chainguard gitlab-pages
gitlab-pages affected wolfi gitlab-pages
gitlab-runner affected wolfi gitlab-runner
gitlab-runner affected chainguard gitlab-runner
git-lfs affected chainguard git-lfs
git-lfs affected wolfi git-lfs
gitness affected wolfi gitness
gitness affected chainguard gitness
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
glab affected chainguard glab
glab affected wolfi glab
go-1.20 affected wolfi go-1.20
go-1.20 affected chainguard go-1.20
go-1.21 affected chainguard go-1.21
go-1.21 affected wolfi go-1.21
go-bindata affected wolfi go-bindata
go-bindata affected chainguard go-bindata
gobuster affected wolfi gobuster
gobuster affected chainguard gobuster
golangci-lint affected wolfi golangci-lint
golangci-lint affected chainguard golangci-lint
go-licenses affected wolfi go-licenses
go-licenses affected chainguard go-licenses
go-md2man affected chainguard go-md2man
go-md2man affected wolfi go-md2man
gops affected wolfi gops
gops affected chainguard gops
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
goreleaser-1.18 affected wolfi goreleaser-1.18
goreleaser-1.18 affected chainguard goreleaser-1.18
gosu affected chainguard gosu
gosu affected wolfi gosu
govulncheck affected wolfi govulncheck
govulncheck affected chainguard govulncheck
grafana affected chainguard grafana
grafana affected wolfi grafana
grpc-health-probe affected wolfi grpc-health-probe
grpc-health-probe affected chainguard grpc-health-probe
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
grype affected chainguard grype
grype affected wolfi grype
guac affected chainguard guac
guac affected wolfi guac
haproxy-ingress affected wolfi haproxy-ingress
haproxy-ingress affected chainguard haproxy-ingress
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
hey affected chainguard hey
hey affected wolfi hey
http-echo affected wolfi http-echo
http-echo affected chainguard http-echo
hubble affected chainguard hubble
hubble affected wolfi hubble
hubble-ui affected wolfi hubble-ui
hubble-ui affected chainguard hubble-ui
hugo affected chainguard hugo
hugo affected wolfi hugo
hugo-extended affected chainguard hugo-extended
hugo-extended affected wolfi hugo-extended
influx affected chainguard influx
influx affected wolfi influx
influxd affected wolfi influxd
influxd affected chainguard influxd
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller affected wolfi ingress-nginx-controller
ipfs affected chainguard ipfs
ipfs affected wolfi ipfs
ip-masq-agent affected chainguard ip-masq-agent
ip-masq-agent affected wolfi ip-masq-agent
istio-cni-1.19 affected chainguard istio-cni-1.19
istio-cni-1.19 affected wolfi istio-cni-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-pilot-agent-1.18 affected chainguard istio-pilot-agent-1.18
istio-pilot-agent-1.18 affected wolfi istio-pilot-agent-1.18
istio-pilot-agent-1.19 affected wolfi istio-pilot-agent-1.19
istio-pilot-agent-1.19 affected chainguard istio-pilot-agent-1.19
istio-pilot-discovery-1.18 affected chainguard istio-pilot-discovery-1.18
istio-pilot-discovery-1.18 affected wolfi istio-pilot-discovery-1.18
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
k3d affected wolfi k3d
k3d affected chainguard k3d
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
k8sgpt-operator affected wolfi k8sgpt-operator
k8sgpt-operator affected chainguard k8sgpt-operator
kaf affected wolfi kaf
kaf affected chainguard kaf
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
kargo affected wolfi kargo
kargo affected chainguard kargo
karpenter affected wolfi karpenter
karpenter affected chainguard karpenter
keda affected chainguard keda
keda affected wolfi keda
keda-2.10 affected wolfi keda-2.10
keda-2.10 affected chainguard keda-2.10
keda-2.11 affected chainguard keda-2.11
keda-2.11 affected wolfi keda-2.11
kind affected wolfi kind
kind affected chainguard kind
kine affected wolfi kine
kine affected chainguard kine
ko affected chainguard ko
ko affected wolfi ko
kor affected wolfi kor
kor affected chainguard kor
kots affected wolfi kots
kots affected chainguard kots
kpt affected chainguard kpt
kpt affected wolfi kpt
kube-bench affected chainguard kube-bench
kube-bench affected wolfi kube-bench
kubebuilder affected chainguard kubebuilder
kubebuilder affected wolfi kubebuilder
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-logging-operator affected chainguard kube-logging-operator
kube-logging-operator affected wolfi kube-logging-operator
kubernetes-1.26 affected wolfi kubernetes-1.26
kubernetes-1.26 affected chainguard kubernetes-1.26
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-csi-external-attacher-4.3 affected chainguard kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.3 affected wolfi kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.4 affected chainguard kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-attacher-4.4 affected wolfi kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-csi-external-snapshotter affected chainguard kubernetes-csi-external-snapshotter
kubernetes-csi-external-snapshotter affected wolfi kubernetes-csi-external-snapshotter
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-node-driver-registrar-2.9 affected wolfi kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-2.9 affected chainguard kubernetes-csi-node-driver-registrar-2.9
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-ingress-defaultbackend affected wolfi kubernetes-ingress-defaultbackend
kubernetes-ingress-defaultbackend affected chainguard kubernetes-ingress-defaultbackend
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kubewatch affected wolfi kubewatch
kubewatch affected chainguard kubewatch
kustomize affected chainguard kustomize
kustomize affected wolfi kustomize
kyverno affected chainguard kyverno
kyverno affected wolfi kyverno
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
kyverno-policy-reporter-kyverno-plugin affected chainguard kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-kyverno-plugin affected wolfi kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-ui affected chainguard kyverno-policy-reporter-ui
kyverno-policy-reporter-ui affected wolfi kyverno-policy-reporter-ui
litefs affected wolfi litefs
litefs affected chainguard litefs
local-path-provisioner affected wolfi local-path-provisioner
local-path-provisioner affected chainguard local-path-provisioner
loki affected chainguard loki
loki affected wolfi loki
mage affected wolfi mage
mage affected chainguard mage
mc affected wolfi mc
mc affected chainguard mc
melange affected wolfi melange
melange affected chainguard melange
memcached-exporter affected wolfi memcached-exporter
memcached-exporter affected chainguard memcached-exporter
metacontroller affected wolfi metacontroller
metacontroller affected chainguard metacontroller
metallb affected wolfi metallb
metallb affected chainguard metallb
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
minify affected chainguard minify
minify affected wolfi minify
minio affected chainguard minio
minio affected wolfi minio
mongo-tools affected chainguard mongo-tools
mongo-tools affected wolfi mongo-tools
nats affected wolfi nats
nats affected chainguard nats
nats-server affected wolfi nats-server
nats-server affected chainguard nats-server
nerdctl affected wolfi nerdctl
nerdctl affected chainguard nerdctl
newrelic-fluent-bit-output affected wolfi newrelic-fluent-bit-output
newrelic-fluent-bit-output affected chainguard newrelic-fluent-bit-output
newrelic-infra-operator affected wolfi newrelic-infra-operator
newrelic-infra-operator affected chainguard newrelic-infra-operator
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-bundle affected wolfi newrelic-infrastructure-bundle
newrelic-infrastructure-bundle affected chainguard newrelic-infrastructure-bundle
newrelic-nri-kube-events affected wolfi newrelic-nri-kube-events
newrelic-nri-kube-events affected chainguard newrelic-nri-kube-events
newrelic-prometheus-configurator affected wolfi newrelic-prometheus-configurator
newrelic-prometheus-configurator affected chainguard newrelic-prometheus-configurator
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
node-problem-detector-0.8 affected wolfi node-problem-detector-0.8
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nri-apache affected wolfi nri-apache
nri-apache affected chainguard nri-apache
nri-cassandra affected wolfi nri-cassandra
nri-cassandra affected chainguard nri-cassandra
nri-consul affected chainguard nri-consul
nri-consul affected wolfi nri-consul
nri-couchbase affected chainguard nri-couchbase
nri-couchbase affected wolfi nri-couchbase
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-elasticsearch affected chainguard nri-elasticsearch
nri-elasticsearch affected wolfi nri-elasticsearch
nri-f5 affected chainguard nri-f5
nri-f5 affected wolfi nri-f5
nri-haproxy affected chainguard nri-haproxy
nri-haproxy affected wolfi nri-haproxy
nri-jmx affected chainguard nri-jmx
nri-jmx affected wolfi nri-jmx
nri-kafka affected wolfi nri-kafka
nri-kafka affected chainguard nri-kafka
nri-kubernetes affected wolfi nri-kubernetes
nri-kubernetes affected chainguard nri-kubernetes
nri-memcached affected wolfi nri-memcached
nri-memcached affected chainguard nri-memcached
nri-mongodb affected chainguard nri-mongodb
nri-mongodb affected wolfi nri-mongodb
nri-mssql affected chainguard nri-mssql
nri-mssql affected wolfi nri-mssql
nri-mysql affected chainguard nri-mysql
nri-mysql affected wolfi nri-mysql
nri-nagios affected wolfi nri-nagios
nri-nagios affected chainguard nri-nagios
nri-nginx affected chainguard nri-nginx
nri-nginx affected wolfi nri-nginx
nri-postgresql affected wolfi nri-postgresql
nri-postgresql affected chainguard nri-postgresql
nri-prometheus affected chainguard nri-prometheus
nri-prometheus affected wolfi nri-prometheus
nri-rabbitmq affected wolfi nri-rabbitmq
nri-rabbitmq affected chainguard nri-rabbitmq
nri-redis affected wolfi nri-redis
nri-redis affected chainguard nri-redis
nsc affected wolfi nsc
nsc affected chainguard nsc
nuclei affected wolfi nuclei
nuclei affected chainguard nuclei
oauth2-proxy affected chainguard oauth2-proxy
oauth2-proxy affected wolfi oauth2-proxy
ollama affected chainguard ollama
ollama affected wolfi ollama
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentofu affected chainguard opentofu
opentofu affected wolfi opentofu
oras affected wolfi oras
oras affected chainguard oras
osv-scanner affected chainguard osv-scanner
osv-scanner affected wolfi osv-scanner
paranoia affected chainguard paranoia
paranoia affected wolfi paranoia
petname affected wolfi petname
petname affected chainguard petname
policy-controller affected wolfi policy-controller
policy-controller affected chainguard policy-controller
prometheus affected wolfi prometheus
prometheus affected chainguard prometheus
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-blackbox-exporter affected wolfi prometheus-blackbox-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter affected wolfi prometheus-elasticsearch-exporter
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter affected wolfi prometheus-mongodb-exporter
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-mysqld-exporter affected wolfi prometheus-mysqld-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-nats-exporter affected wolfi prometheus-nats-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter affected wolfi prometheus-node-exporter
prometheus-operator affected chainguard prometheus-operator
prometheus-operator affected wolfi prometheus-operator
prometheus-postgres-exporter affected wolfi prometheus-postgres-exporter
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-redis-exporter affected chainguard prometheus-redis-exporter
prometheus-redis-exporter affected wolfi prometheus-redis-exporter
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter affected wolfi prometheus-statsd-exporter
protoc-gen-go affected wolfi protoc-gen-go
protoc-gen-go affected chainguard protoc-gen-go
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
pulumi affected chainguard pulumi
pulumi affected wolfi pulumi
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-yaml affected wolfi pulumi-language-yaml
pulumi-language-yaml affected chainguard pulumi-language-yaml
q affected chainguard q
q affected wolfi q
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
rclone affected wolfi rclone
rclone affected chainguard rclone
regclient affected chainguard regclient
regclient affected wolfi regclient
rekor affected chainguard rekor
rekor affected wolfi rekor
render-template affected chainguard render-template
render-template affected wolfi render-template
restic affected chainguard restic
restic affected wolfi restic
rootlesskit affected wolfi rootlesskit
rootlesskit affected chainguard rootlesskit
rqlite affected chainguard rqlite
rqlite affected wolfi rqlite
runc affected chainguard runc
runc affected wolfi runc
sbomqs affected chainguard sbomqs
sbomqs affected wolfi sbomqs
sbom-scorecard affected wolfi sbom-scorecard
sbom-scorecard affected chainguard sbom-scorecard
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
skaffold affected wolfi skaffold
skaffold affected chainguard skaffold
skopeo affected chainguard skopeo
skopeo affected wolfi skopeo
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager affected chainguard smarter-device-manager
sonobuoy affected chainguard sonobuoy
sonobuoy affected wolfi sonobuoy
sops affected wolfi sops
sops affected chainguard sops
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
spicedb affected wolfi spicedb
spicedb affected chainguard spicedb
spire-server affected chainguard spire-server
spire-server affected wolfi spire-server
src affected wolfi src
src affected chainguard src
src-fingerprint affected chainguard src-fingerprint
src-fingerprint affected wolfi src-fingerprint
stakater-reloader affected chainguard stakater-reloader
stakater-reloader affected wolfi stakater-reloader
step affected wolfi step
step affected chainguard step
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
supercronic affected chainguard supercronic
supercronic affected wolfi supercronic
syft affected chainguard syft
syft affected wolfi syft
tailscale affected chainguard tailscale
tailscale affected wolfi tailscale
task affected chainguard task
task affected wolfi task
tctl affected chainguard tctl
tctl affected wolfi tctl
tekton-chains affected chainguard tekton-chains
tekton-chains affected wolfi tekton-chains
tekton-pipelines affected chainguard tekton-pipelines
tekton-pipelines affected wolfi tekton-pipelines
telegraf-1.26 affected wolfi telegraf-1.26
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.27 affected chainguard telegraf-1.27
telegraf-1.27 affected wolfi telegraf-1.27
temporal affected wolfi temporal
temporal affected chainguard temporal
temporal-fips affected chainguard temporal-fips
temporal-server affected chainguard temporal-server
temporal-server affected wolfi temporal-server
temporal-server-fips affected chainguard temporal-server-fips
temporal-ui-server affected wolfi temporal-ui-server
temporal-ui-server affected chainguard temporal-ui-server
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-provider-aws affected wolfi terraform-provider-aws
terraform-provider-aws affected chainguard terraform-provider-aws
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terragrunt affected wolfi terragrunt
terragrunt affected chainguard terragrunt
tflint affected chainguard tflint
tflint affected wolfi tflint
thanos-0.31 affected chainguard thanos-0.31
thanos-0.31 affected wolfi thanos-0.31
thanos-0.32 affected wolfi thanos-0.32
thanos-0.32 affected chainguard thanos-0.32
thanos-operator affected wolfi thanos-operator
thanos-operator affected chainguard thanos-operator
tigera-operator-1.30 affected wolfi tigera-operator-1.30
tigera-operator-1.30 affected chainguard tigera-operator-1.30
tigera-operator-1.31 affected chainguard tigera-operator-1.31
tigera-operator-1.31 affected wolfi tigera-operator-1.31
timestamp-authority affected chainguard timestamp-authority
timestamp-authority affected wolfi timestamp-authority
timoni affected wolfi timoni
timoni affected chainguard timoni
tkn affected wolfi tkn
tkn affected chainguard tkn
traefik affected chainguard traefik
traefik affected wolfi traefik
trillian affected wolfi trillian
trillian affected chainguard trillian
trivy affected chainguard trivy
trivy affected wolfi trivy
trust-manager affected chainguard trust-manager
trust-manager affected wolfi trust-manager
up affected chainguard up
up affected wolfi up
vault-1.13 affected wolfi vault-1.13
vault-1.13 affected chainguard vault-1.13
vault-csi-provider affected wolfi vault-csi-provider
vault-csi-provider affected chainguard vault-csi-provider
vault-k8s affected wolfi vault-k8s
vault-k8s affected chainguard vault-k8s
velero affected chainguard velero
velero affected wolfi velero
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vexctl affected wolfi vexctl
vexctl affected chainguard vexctl
volume-modifier-for-k8s affected wolfi volume-modifier-for-k8s
volume-modifier-for-k8s affected chainguard volume-modifier-for-k8s
vt-cli affected wolfi vt-cli
vt-cli affected chainguard vt-cli
wait-for-port affected wolfi wait-for-port
wait-for-port affected chainguard wait-for-port
wazero affected chainguard wazero
wazero affected wolfi wazero
weaviate affected wolfi weaviate
weaviate affected chainguard weaviate
wire-go affected wolfi wire-go
wire-go affected chainguard wire-go
wireguard-go affected chainguard wireguard-go
wireguard-go affected wolfi wireguard-go
wolfictl affected wolfi wolfictl
wolfictl affected chainguard wolfictl
yq affected chainguard yq
yq affected wolfi yq
ytt affected wolfi ytt
ytt affected chainguard ytt
zarf affected chainguard zarf
zarf affected wolfi zarf
Upstream advisory

AZL-31897

Open SourcePoC exploitHIGH2023-11-09

CVE-2023-45283 affecting package msft-golang for versions less than 1.20.11-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37397

Open SourcePoC exploitHIGH2023-11-09

CVE-2023-45283 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37444

Open SourcePoC exploitHIGH2023-11-09

CVE-2023-45283 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79034

Open SourcePoC exploitHIGH2023-11-09

CVE-2023-45283 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-45283

Open SourcePoC exploitHIGH2023-11-09

DEBIAN-CVE-2023-45283

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GO-2023-2185

Open SourcePoC exploitHIGH2023-11-08

Insecure parsing of Windows paths with a \??\ prefix in path/filepath

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller affected wolfi actions-runner-controller
amass affected wolfi amass
amass affected chainguard amass
apko affected wolfi apko
apko affected chainguard apko
argo-workflows affected chainguard argo-workflows
argo-workflows affected wolfi argo-workflows
atlantis affected chainguard atlantis
atlantis affected wolfi atlantis
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
bank-vaults affected chainguard bank-vaults
bank-vaults affected wolfi bank-vaults
bom affected wolfi bom
bom affected chainguard bom
boring-registry affected chainguard boring-registry
boring-registry affected wolfi boring-registry
buf affected wolfi buf
buf affected chainguard buf
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
caddy affected wolfi caddy
caddy affected chainguard caddy
capslock affected chainguard capslock
capslock affected wolfi capslock
certificate-transparency affected wolfi certificate-transparency
certificate-transparency affected chainguard certificate-transparency
cfssl affected wolfi cfssl
cfssl affected chainguard cfssl
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
cloudflared affected wolfi cloudflared
cloudflared affected chainguard cloudflared
cluster-proportional-autoscaler affected wolfi cluster-proportional-autoscaler
cluster-proportional-autoscaler affected chainguard cluster-proportional-autoscaler
cni-plugins affected chainguard cni-plugins
cni-plugins affected wolfi cni-plugins
configmap-reload affected chainguard configmap-reload
configmap-reload affected wolfi configmap-reload
conftest affected chainguard conftest
conftest affected wolfi conftest
cortex affected wolfi cortex
cortex affected chainguard cortex
cosign affected wolfi cosign
cosign affected chainguard cosign
crane affected chainguard crane
crane affected wolfi crane
cri-tools affected wolfi cri-tools
cri-tools affected chainguard cri-tools
croc affected wolfi croc
croc affected chainguard croc
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure affected wolfi crossplane-provider-azure
ctop affected chainguard ctop
ctop affected wolfi ctop
cue affected wolfi cue
cue affected chainguard cue
dask-gateway affected chainguard dask-gateway
dask-gateway affected wolfi dask-gateway
dataplaneapi affected wolfi dataplaneapi
dataplaneapi affected chainguard dataplaneapi
delve affected wolfi delve
delve affected chainguard delve
dex affected chainguard dex
dex affected wolfi dex
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
dive affected chainguard dive
dive affected wolfi dive
docker-credential-acr-env affected wolfi docker-credential-acr-env
docker-credential-acr-env affected chainguard docker-credential-acr-env
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-gcr affected wolfi docker-credential-gcr
docker-credential-gcr affected chainguard docker-credential-gcr
dockerize affected wolfi dockerize
dockerize affected chainguard dockerize
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
envoy-ratelimit affected chainguard envoy-ratelimit
envoy-ratelimit affected wolfi envoy-ratelimit
esbuild affected chainguard esbuild
esbuild affected wolfi esbuild
etcd-3.5 affected chainguard etcd-3.5
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
ferretdb affected wolfi ferretdb
ferretdb affected chainguard ferretdb
flannel affected chainguard flannel
flannel affected wolfi flannel
flannel-cni-plugin affected chainguard flannel-cni-plugin
flannel-cni-plugin affected wolfi flannel-cni-plugin
flux affected wolfi flux
flux affected chainguard flux
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
fq affected wolfi fq
fq affected chainguard fq
frp affected chainguard frp
frp affected wolfi frp
fulcio affected wolfi fulcio
fulcio affected chainguard fulcio
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fzf affected wolfi fzf
fzf affected chainguard fzf
gcsfuse affected wolfi gcsfuse
gcsfuse affected chainguard gcsfuse
git-lfs affected chainguard git-lfs
git-lfs affected wolfi git-lfs
gitness affected wolfi gitness
gitness affected chainguard gitness
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
glab affected wolfi glab
glab affected chainguard glab
go-1.20 affected wolfi go-1.20
go-1.20 affected chainguard go-1.20
go-1.21 affected wolfi go-1.21
go-1.21 affected chainguard go-1.21
go-bindata affected wolfi go-bindata
go-bindata affected chainguard go-bindata
gobuster affected wolfi gobuster
gobuster affected chainguard gobuster
golangci-lint affected wolfi golangci-lint
golangci-lint affected chainguard golangci-lint
go-licenses affected wolfi go-licenses
go-licenses affected chainguard go-licenses
go-md2man affected chainguard go-md2man
go-md2man affected wolfi go-md2man
gops affected wolfi gops
gops affected chainguard gops
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
gosu affected chainguard gosu
gosu affected wolfi gosu
govulncheck affected wolfi govulncheck
govulncheck affected chainguard govulncheck
grpc-health-probe affected chainguard grpc-health-probe
grpc-health-probe affected wolfi grpc-health-probe
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
grype affected wolfi grype
grype affected chainguard grype
guac affected wolfi guac
guac affected chainguard guac
haproxy-ingress affected wolfi haproxy-ingress
haproxy-ingress affected chainguard haproxy-ingress
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected wolfi helm-3
helm-3 affected chainguard helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
hey affected chainguard hey
hey affected wolfi hey
http-echo affected wolfi http-echo
http-echo affected chainguard http-echo
hubble affected wolfi hubble
hubble affected chainguard hubble
hubble-ui affected wolfi hubble-ui
hubble-ui affected chainguard hubble-ui
hugo affected wolfi hugo
hugo affected chainguard hugo
hugo-extended affected wolfi hugo-extended
hugo-extended affected chainguard hugo-extended
influx affected chainguard influx
influx affected wolfi influx
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
k3d affected chainguard k3d
k3d affected wolfi k3d
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k8sgpt-operator affected chainguard k8sgpt-operator
k8sgpt-operator affected wolfi k8sgpt-operator
kaf affected wolfi kaf
kaf affected chainguard kaf
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
kargo affected chainguard kargo
kargo affected wolfi kargo
kind affected wolfi kind
kind affected chainguard kind
kine affected wolfi kine
kine affected chainguard kine
ko affected wolfi ko
ko affected chainguard ko
kor affected wolfi kor
kor affected chainguard kor
kots affected wolfi kots
kots affected chainguard kots
kpt affected wolfi kpt
kpt affected chainguard kpt
kube-bench affected chainguard kube-bench
kube-bench affected wolfi kube-bench
kubebuilder affected wolfi kubebuilder
kubebuilder affected chainguard kubebuilder
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-logging-operator affected chainguard kube-logging-operator
kube-logging-operator affected wolfi kube-logging-operator
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-ingress-defaultbackend affected chainguard kubernetes-ingress-defaultbackend
kubernetes-ingress-defaultbackend affected wolfi kubernetes-ingress-defaultbackend
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
kubewatch affected wolfi kubewatch
kubewatch affected chainguard kubewatch
kustomize affected wolfi kustomize
kustomize affected chainguard kustomize
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
kyverno-policy-reporter-kyverno-plugin affected wolfi kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-kyverno-plugin affected chainguard kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-ui affected wolfi kyverno-policy-reporter-ui
kyverno-policy-reporter-ui affected chainguard kyverno-policy-reporter-ui
litefs affected chainguard litefs
litefs affected wolfi litefs
local-path-provisioner affected wolfi local-path-provisioner
local-path-provisioner affected chainguard local-path-provisioner
mage affected chainguard mage
mage affected wolfi mage
mc affected wolfi mc
mc affected chainguard mc
melange affected wolfi melange
melange affected chainguard melange
memcached-exporter affected chainguard memcached-exporter
memcached-exporter affected wolfi memcached-exporter
metacontroller affected wolfi metacontroller
metacontroller affected chainguard metacontroller
metallb affected wolfi metallb
metallb affected chainguard metallb
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
minify affected chainguard minify
minify affected wolfi minify
minio affected chainguard minio
minio affected wolfi minio
mongo-tools affected chainguard mongo-tools
mongo-tools affected wolfi mongo-tools
nats affected wolfi nats
nats affected chainguard nats
nats-server affected chainguard nats-server
nats-server affected wolfi nats-server
nerdctl affected wolfi nerdctl
nerdctl affected chainguard nerdctl
newrelic-fluent-bit-output affected chainguard newrelic-fluent-bit-output
newrelic-fluent-bit-output affected wolfi newrelic-fluent-bit-output
newrelic-infra-operator affected chainguard newrelic-infra-operator
newrelic-infra-operator affected wolfi newrelic-infra-operator
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-bundle affected wolfi newrelic-infrastructure-bundle
newrelic-infrastructure-bundle affected chainguard newrelic-infrastructure-bundle
newrelic-nri-kube-events affected chainguard newrelic-nri-kube-events
newrelic-nri-kube-events affected wolfi newrelic-nri-kube-events
newrelic-prometheus-configurator affected wolfi newrelic-prometheus-configurator
newrelic-prometheus-configurator affected chainguard newrelic-prometheus-configurator
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nri-apache affected wolfi nri-apache
nri-apache affected chainguard nri-apache
nri-cassandra affected wolfi nri-cassandra
nri-cassandra affected chainguard nri-cassandra
nri-consul affected chainguard nri-consul
nri-consul affected wolfi nri-consul
nri-couchbase affected wolfi nri-couchbase
nri-couchbase affected chainguard nri-couchbase
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-elasticsearch affected chainguard nri-elasticsearch
nri-elasticsearch affected wolfi nri-elasticsearch
nri-f5 affected wolfi nri-f5
nri-f5 affected chainguard nri-f5
nri-haproxy affected wolfi nri-haproxy
nri-haproxy affected chainguard nri-haproxy
nri-jmx affected wolfi nri-jmx
nri-jmx affected chainguard nri-jmx
nri-kafka affected chainguard nri-kafka
nri-kafka affected wolfi nri-kafka
nri-kubernetes affected wolfi nri-kubernetes
nri-kubernetes affected chainguard nri-kubernetes
nri-memcached affected chainguard nri-memcached
nri-memcached affected wolfi nri-memcached
nri-mongodb affected chainguard nri-mongodb
nri-mongodb affected wolfi nri-mongodb
nri-mssql affected chainguard nri-mssql
nri-mssql affected wolfi nri-mssql
nri-mysql affected wolfi nri-mysql
nri-mysql affected chainguard nri-mysql
nri-nagios affected wolfi nri-nagios
nri-nagios affected chainguard nri-nagios
nri-nginx affected chainguard nri-nginx
nri-nginx affected wolfi nri-nginx
nri-postgresql affected wolfi nri-postgresql
nri-postgresql affected chainguard nri-postgresql
nri-prometheus affected wolfi nri-prometheus
nri-prometheus affected chainguard nri-prometheus
nri-rabbitmq affected wolfi nri-rabbitmq
nri-rabbitmq affected chainguard nri-rabbitmq
nri-redis affected chainguard nri-redis
nri-redis affected wolfi nri-redis
nsc affected chainguard nsc
nsc affected wolfi nsc
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
oauth2-proxy affected chainguard oauth2-proxy
oauth2-proxy affected wolfi oauth2-proxy
ollama affected wolfi ollama
ollama affected chainguard ollama
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
oras affected chainguard oras
oras affected wolfi oras
osv-scanner affected chainguard osv-scanner
osv-scanner affected wolfi osv-scanner
paranoia affected chainguard paranoia
paranoia affected wolfi paranoia
petname affected chainguard petname
petname affected wolfi petname
policy-controller affected chainguard policy-controller
policy-controller affected wolfi policy-controller
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-operator affected wolfi prometheus-operator
prometheus-operator affected chainguard prometheus-operator
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-redis-exporter affected chainguard prometheus-redis-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
protoc-gen-go affected wolfi protoc-gen-go
protoc-gen-go affected chainguard protoc-gen-go
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
pulumi affected chainguard pulumi
pulumi affected wolfi pulumi
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-yaml affected chainguard pulumi-language-yaml
pulumi-language-yaml affected wolfi pulumi-language-yaml
q affected chainguard q
q affected wolfi q
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rclone affected chainguard rclone
rclone affected wolfi rclone
regclient affected chainguard regclient
regclient affected wolfi regclient
rekor affected wolfi rekor
rekor affected chainguard rekor
render-template affected chainguard render-template
render-template affected wolfi render-template
restic affected wolfi restic
restic affected chainguard restic
rootlesskit affected wolfi rootlesskit
rootlesskit affected chainguard rootlesskit
rqlite affected wolfi rqlite
rqlite affected chainguard rqlite
runc affected chainguard runc
runc affected wolfi runc
sbomqs affected wolfi sbomqs
sbomqs affected chainguard sbomqs
sbom-scorecard affected chainguard sbom-scorecard
sbom-scorecard affected wolfi sbom-scorecard
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
skopeo affected wolfi skopeo
skopeo affected chainguard skopeo
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager affected wolfi smarter-device-manager
sonobuoy affected chainguard sonobuoy
sonobuoy affected wolfi sonobuoy
sops affected wolfi sops
sops affected chainguard sops
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
spicedb affected wolfi spicedb
spicedb affected chainguard spicedb
spire-server affected wolfi spire-server
spire-server affected chainguard spire-server
src affected wolfi src
src affected chainguard src
src-fingerprint affected wolfi src-fingerprint
src-fingerprint affected chainguard src-fingerprint
stakater-reloader affected wolfi stakater-reloader
stakater-reloader affected chainguard stakater-reloader
stdlib affected Go stdlib
step affected chainguard step
step affected wolfi step
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
supercronic affected chainguard supercronic
supercronic affected wolfi supercronic
syft affected chainguard syft
syft affected wolfi syft
tailscale affected wolfi tailscale
tailscale affected chainguard tailscale
task affected wolfi task
task affected chainguard task
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
temporal affected chainguard temporal
temporal affected wolfi temporal
temporal-fips affected chainguard temporal-fips
temporal-server affected wolfi temporal-server
temporal-server affected chainguard temporal-server
temporal-server-fips affected chainguard temporal-server-fips
temporal-ui-server affected wolfi temporal-ui-server
temporal-ui-server affected chainguard temporal-ui-server
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-provider-aws affected chainguard terraform-provider-aws
terraform-provider-aws affected wolfi terraform-provider-aws
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terragrunt affected wolfi terragrunt
terragrunt affected chainguard terragrunt
tflint affected wolfi tflint
tflint affected chainguard tflint
thanos-operator affected wolfi thanos-operator
thanos-operator affected chainguard thanos-operator
timestamp-authority affected wolfi timestamp-authority
timestamp-authority affected chainguard timestamp-authority
timoni affected wolfi timoni
timoni affected chainguard timoni
tkn affected chainguard tkn
tkn affected wolfi tkn
trillian affected chainguard trillian
trillian affected wolfi trillian
trivy affected chainguard trivy
trivy affected wolfi trivy
trust-manager affected chainguard trust-manager
trust-manager affected wolfi trust-manager
up affected chainguard up
up affected wolfi up
vault-csi-provider affected chainguard vault-csi-provider
vault-k8s affected chainguard vault-k8s
vault-k8s affected wolfi vault-k8s
velero affected wolfi velero
velero affected chainguard velero
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vexctl affected wolfi vexctl
vexctl affected chainguard vexctl
volume-modifier-for-k8s affected chainguard volume-modifier-for-k8s
volume-modifier-for-k8s affected wolfi volume-modifier-for-k8s
vt-cli affected wolfi vt-cli
vt-cli affected chainguard vt-cli
wait-for-port affected chainguard wait-for-port
wait-for-port affected wolfi wait-for-port
wazero affected wolfi wazero
wazero affected chainguard wazero
weaviate affected chainguard weaviate
weaviate affected wolfi weaviate
wire-go affected wolfi wire-go
wire-go affected chainguard wire-go
wireguard-go affected wolfi wireguard-go
wireguard-go affected chainguard wireguard-go
wolfictl affected chainguard wolfictl
wolfictl affected wolfi wolfictl
yq affected wolfi yq
yq affected chainguard yq
ytt affected chainguard ytt
ytt affected wolfi ytt
zarf affected wolfi zarf
zarf affected chainguard zarf
Upstream advisory

CVE-2023-45283

GooglePoC exploit2023-11-07

The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equivalent to a path beginning with \\?\. Paths with a \??\ prefix may be used to access arbitrary locations on the system. For example, the path \??\c:\x is equivalent to the more common path c:\x. Before fix, Clean could convert a rooted path such as \a\..\??\b into the root local device path \??\b. Clean will now convert this to .\??\b. Similarly, Join(\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \??\b. Join will now convert this to \.\??\b. In addition, with fix, IsAbs now correctly reports paths beginning with \??\ as absolute, and VolumeName correctly reports the \??\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \?, resulting in filepath.Clean(\?\c:) returning \?\c: rather than \?\c:\ (among other effects). The previous behavior has been restored.

CVEs:CVE-2023-45283

Upstream advisory

CVE-2023-45283

GooglePoC exploitHIGH2023-11-07

The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equivalent to a path beginning with \\?\. Paths with a \??\ prefix may be used to access arbitrary locations...

CVEs:CVE-2023-45283

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

DEBIAN-CVE-2022-3172

Open SourcePoC exploitHIGH2023-11-03

DEBIAN-CVE-2022-3172

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CLSA-2023-1699468875

Open SourcePoC exploitHIGH2023-11-08

Fix CVE(s): CVE-2022-48560

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.6 affected TuxCare:Ubuntu:18.04 idle-python3.6
libpython3.6 affected TuxCare:Ubuntu:18.04 libpython3.6
libpython3.6-dev affected TuxCare:Ubuntu:18.04 libpython3.6-dev
libpython3.6-minimal affected TuxCare:Ubuntu:18.04 libpython3.6-minimal
libpython3.6-stdlib affected TuxCare:Ubuntu:18.04 libpython3.6-stdlib
libpython3.6-testsuite affected TuxCare:Ubuntu:18.04 libpython3.6-testsuite
python3.6 affected TuxCare:Ubuntu:18.04 python3.6
python3.6-dev affected TuxCare:Ubuntu:18.04 python3.6-dev
python3.6-doc affected TuxCare:Ubuntu:18.04 python3.6-doc
python3.6-examples affected TuxCare:Ubuntu:18.04 python3.6-examples
python3.6-minimal affected TuxCare:Ubuntu:18.04 python3.6-minimal
python3.6-venv affected TuxCare:Ubuntu:18.04 python3.6-venv
Upstream advisory

RHBA-2023:6928

Open SourcePoC exploitHIGH2023-11-14

Red Hat Bug Fix Advisory: go-toolset:rhel8 bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

GHSA-8pgv-569h-w5rw

Open SourcePoC exploitCRITICAL2023-11-12

otelgrpc DoS vulnerability due to unbound cardinality metrics

Affected products

ProductStatusVendorPackageEcosystem
contrib/instrumentation/google.golang.org/grpc/otelgrpc affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc
Upstream advisory

GHSA-8pgv-569h-w5rw

Open SourcePoC exploitCRITICAL2023-11-12

otelgrpc DoS vulnerability due to unbound cardinality metrics

Affected products

ProductStatusVendorPackageEcosystem
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.8 affected wolfi argo-cd-2.8
argo-cd-2.9 affected wolfi argo-cd-2.9
argo-cd-2.9 affected chainguard argo-cd-2.9
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
cert-manager-1.11 affected chainguard cert-manager-1.11
cert-manager-1.11 affected wolfi cert-manager-1.11
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.13 affected wolfi cert-manager-1.13
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
cluster-autoscaler-fips-1.27 affected chainguard cluster-autoscaler-fips-1.27
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
containerd affected chainguard containerd
containerd affected wolfi containerd
contrib/instrumentation/google.golang.org/grpc/otelgrpc affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
docker-compose affected wolfi docker-compose
docker-compose affected chainguard docker-compose
envoy-ratelimit affected wolfi envoy-ratelimit
envoy-ratelimit affected chainguard envoy-ratelimit
k3s affected chainguard k3s
k3s affected wolfi k3s
keda affected chainguard keda
keda affected wolfi keda
keda-2.10 affected chainguard keda-2.10
keda-2.10 affected wolfi keda-2.10
keda-2.11 affected wolfi keda-2.11
keda-2.11 affected chainguard keda-2.11
kine affected chainguard kine
kine affected wolfi kine
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-fips-1.27 affected chainguard kubernetes-fips-1.27
kubernetes-fips-1.28 affected chainguard kubernetes-fips-1.28
kubernetes-fips-1.29 affected chainguard kubernetes-fips-1.29
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kyverno affected wolfi kyverno
kyverno affected chainguard kyverno
metrics-server affected chainguard metrics-server
metrics-server affected wolfi metrics-server
metrics-server-fips affected chainguard metrics-server-fips
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
rancher-agent-2.8 affected chainguard rancher-agent-2.8
rancher-webhook-0.4 affected chainguard rancher-webhook-0.4
rancher-webhook-fips-0.4 affected chainguard rancher-webhook-fips-0.4
tempo-2.3 affected chainguard tempo-2.3
temporal affected wolfi temporal
temporal affected chainguard temporal
temporal-fips affected chainguard temporal-fips
temporal-server affected chainguard temporal-server
temporal-server affected wolfi temporal-server
temporal-server-fips affected chainguard temporal-server-fips
volume-modifier-for-k8s affected chainguard volume-modifier-for-k8s
volume-modifier-for-k8s affected wolfi volume-modifier-for-k8s
Upstream advisory

CVE-2023-47108

Open SourcePoC exploitHIGH2023-11-10

otelgrpc DoS vulnerability due to unbound cardinality metrics

CVEs:CVE-2023-47108

Affected products

ProductStatusVendorPackageEcosystem
contrib/instrumentation/google.golang.org/grpc/otelgrpc affected go.opentelemetry.io go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc
Upstream advisory

CVE-2023-47108

GooglePoC exploitCRITICAL2023-11-10

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` th...

CVEs:CVE-2023-47108

Affected products

ProductStatusVendorPackageEcosystem
opentelemetry affected opentelemetry
Upstream advisory

RHBA-2023:6364

Open SourcePoC exploitHIGH2023-11-07

Red Hat Bug Fix Advisory: golang and delve bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:9::appstream golang
golang-bin affected Red Hat:enterprise_linux:9::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:9::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:9::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:9::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:9::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:9::appstream go-toolset
Upstream advisory

CVE-2023-39326

GooglePoC exploit2023-11-30

A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small.

CVEs:CVE-2023-39326

Upstream advisory

CVE-2023-39326

GooglePoC exploitMEDIUM2023-11-30

A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatica...

CVEs:CVE-2023-39326

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2023-45285

GooglePoC exploitHIGH2023-11-30

Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This onl...

CVEs:CVE-2023-45285

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2023-45285

GooglePoC exploit2023-11-30

Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off).

CVEs:CVE-2023-45285

Upstream advisory

GHSA-rq3x-83w4-p28c

Open SourcePoC exploitMEDIUM2023-11-09

GHSA-rq3x-83w4-p28c

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller affected wolfi actions-runner-controller
amass affected wolfi amass
amass affected chainguard amass
amazon-corretto-crypto-provider affected wolfi amazon-corretto-crypto-provider
amazon-corretto-crypto-provider affected chainguard amazon-corretto-crypto-provider
apko affected wolfi apko
apko affected chainguard apko
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.8 affected wolfi argo-cd-2.8
argo-workflows affected wolfi argo-workflows
argo-workflows affected chainguard argo-workflows
atlantis affected chainguard atlantis
atlantis affected wolfi atlantis
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
bank-vaults affected chainguard bank-vaults
bank-vaults affected wolfi bank-vaults
bom affected wolfi bom
bom affected chainguard bom
boring-registry affected chainguard boring-registry
boring-registry affected wolfi boring-registry
buf affected wolfi buf
buf affected chainguard buf
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
caddy affected wolfi caddy
caddy affected chainguard caddy
calico affected chainguard calico
calico affected wolfi calico
capslock affected chainguard capslock
capslock affected wolfi capslock
certificate-transparency affected wolfi certificate-transparency
certificate-transparency affected chainguard certificate-transparency
cert-manager-1.11 affected chainguard cert-manager-1.11
cert-manager-1.11 affected wolfi cert-manager-1.11
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-1.13 affected wolfi cert-manager-1.13
cfssl affected chainguard cfssl
cfssl affected wolfi cfssl
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
cilium-cli affected wolfi cilium-cli
cilium-cli affected chainguard cilium-cli
cilium-envoy affected chainguard cilium-envoy
cilium-envoy affected wolfi cilium-envoy
cloudflared affected chainguard cloudflared
cloudflared affected wolfi cloudflared
cloud-sql-proxy affected wolfi cloud-sql-proxy
cloud-sql-proxy affected chainguard cloud-sql-proxy
cluster-autoscaler-1.25 affected wolfi cluster-autoscaler-1.25
cluster-autoscaler-1.25 affected chainguard cluster-autoscaler-1.25
cluster-proportional-autoscaler affected chainguard cluster-proportional-autoscaler
cluster-proportional-autoscaler affected wolfi cluster-proportional-autoscaler
cni-plugins affected chainguard cni-plugins
cni-plugins affected wolfi cni-plugins
configmap-reload affected wolfi configmap-reload
configmap-reload affected chainguard configmap-reload
conftest affected wolfi conftest
conftest affected chainguard conftest
consul-1.15 affected chainguard consul-1.15
consul-1.15 affected wolfi consul-1.15
consul-1.16 affected wolfi consul-1.16
consul-1.16 affected chainguard consul-1.16
containerd affected chainguard containerd
containerd affected wolfi containerd
coredns affected wolfi coredns
coredns affected chainguard coredns
cortex affected chainguard cortex
cortex affected wolfi cortex
cosign affected wolfi cosign
cosign affected chainguard cosign
crane affected wolfi crane
crane affected chainguard crane
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
croc affected chainguard croc
croc affected wolfi croc
crossplane affected wolfi crossplane
crossplane affected chainguard crossplane
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-azure affected wolfi crossplane-provider-azure
crossplane-provider-azure affected chainguard crossplane-provider-azure
ctop affected chainguard ctop
ctop affected wolfi ctop
cue affected chainguard cue
cue affected wolfi cue
dask-gateway affected wolfi dask-gateway
dask-gateway affected chainguard dask-gateway
dataplaneapi affected wolfi dataplaneapi
dataplaneapi affected chainguard dataplaneapi
delve affected chainguard delve
delve affected wolfi delve
dex affected wolfi dex
dex affected chainguard dex
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
dive affected wolfi dive
dive affected chainguard dive
docker-credential-acr-env affected chainguard docker-credential-acr-env
docker-credential-acr-env affected wolfi docker-credential-acr-env
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-gcr affected wolfi docker-credential-gcr
docker-credential-gcr affected chainguard docker-credential-gcr
dockerize affected wolfi dockerize
dockerize affected chainguard dockerize
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
envoy-ratelimit affected chainguard envoy-ratelimit
envoy-ratelimit affected wolfi envoy-ratelimit
esbuild affected wolfi esbuild
esbuild affected chainguard esbuild
etcd-3.5 affected chainguard etcd-3.5
etcd-3.5 affected wolfi etcd-3.5
external-dns affected wolfi external-dns
external-dns affected chainguard external-dns
external-secrets-operator affected wolfi external-secrets-operator
external-secrets-operator affected chainguard external-secrets-operator
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
ferretdb affected wolfi ferretdb
ferretdb affected chainguard ferretdb
flannel affected wolfi flannel
flannel affected chainguard flannel
flannel-cni-plugin affected chainguard flannel-cni-plugin
flannel-cni-plugin affected wolfi flannel-cni-plugin
flux affected wolfi flux
flux affected chainguard flux
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
fq affected wolfi fq
fq affected chainguard fq
frp affected wolfi frp
frp affected chainguard frp
fulcio affected chainguard fulcio
fulcio affected wolfi fulcio
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fzf affected chainguard fzf
fzf affected wolfi fzf
gatekeeper-3.12 affected wolfi gatekeeper-3.12
gatekeeper-3.12 affected chainguard gatekeeper-3.12
gatekeeper-3.13 affected wolfi gatekeeper-3.13
gatekeeper-3.13 affected chainguard gatekeeper-3.13
gatekeeper-3.14 affected chainguard gatekeeper-3.14
gatekeeper-3.14 affected wolfi gatekeeper-3.14
gcsfuse affected chainguard gcsfuse
gcsfuse affected wolfi gcsfuse
gitlab-kas affected chainguard gitlab-kas
gitlab-kas affected wolfi gitlab-kas
gitlab-pages affected wolfi gitlab-pages
gitlab-pages affected chainguard gitlab-pages
gitlab-runner affected chainguard gitlab-runner
gitlab-runner affected wolfi gitlab-runner
git-lfs affected wolfi git-lfs
git-lfs affected chainguard git-lfs
gitness affected chainguard gitness
gitness affected wolfi gitness
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
glab affected chainguard glab
glab affected wolfi glab
go-bindata affected wolfi go-bindata
go-bindata affected chainguard go-bindata
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
golangci-lint affected chainguard golangci-lint
golangci-lint affected wolfi golangci-lint
go-licenses affected wolfi go-licenses
go-licenses affected chainguard go-licenses
go-md2man affected chainguard go-md2man
go-md2man affected wolfi go-md2man
gops affected wolfi gops
gops affected chainguard gops
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
goreleaser-1.18 affected chainguard goreleaser-1.18
goreleaser-1.18 affected wolfi goreleaser-1.18
gosu affected wolfi gosu
gosu affected chainguard gosu
govulncheck affected chainguard govulncheck
govulncheck affected wolfi govulncheck
grafana affected wolfi grafana
grafana affected chainguard grafana
grpc-health-probe affected chainguard grpc-health-probe
grpc-health-probe affected wolfi grpc-health-probe
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
grype affected wolfi grype
grype affected chainguard grype
guac affected chainguard guac
guac affected wolfi guac
haproxy-ingress affected chainguard haproxy-ingress
haproxy-ingress affected wolfi haproxy-ingress
helm affected chainguard helm
helm affected wolfi helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
hey affected wolfi hey
hey affected chainguard hey
http-echo affected wolfi http-echo
http-echo affected chainguard http-echo
hubble affected wolfi hubble
hubble affected chainguard hubble
hubble-ui affected wolfi hubble-ui
hubble-ui affected chainguard hubble-ui
hugo affected wolfi hugo
hugo affected chainguard hugo
hugo-extended affected chainguard hugo-extended
hugo-extended affected wolfi hugo-extended
influx affected wolfi influx
influx affected chainguard influx
influxd affected chainguard influxd
influxd affected wolfi influxd
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller affected chainguard ingress-nginx-controller
ipfs affected chainguard ipfs
ipfs affected wolfi ipfs
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
istio-cni-1.19 affected wolfi istio-cni-1.19
istio-cni-1.19 affected chainguard istio-cni-1.19
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-pilot-agent-1.18 affected wolfi istio-pilot-agent-1.18
istio-pilot-agent-1.18 affected chainguard istio-pilot-agent-1.18
istio-pilot-agent-1.19 affected wolfi istio-pilot-agent-1.19
istio-pilot-agent-1.19 affected chainguard istio-pilot-agent-1.19
istio-pilot-discovery-1.18 affected wolfi istio-pilot-discovery-1.18
istio-pilot-discovery-1.18 affected chainguard istio-pilot-discovery-1.18
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
k3d affected wolfi k3d
k3d affected chainguard k3d
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
k8sgpt-operator affected chainguard k8sgpt-operator
k8sgpt-operator affected wolfi k8sgpt-operator
kaf affected wolfi kaf
kaf affected chainguard kaf
kaniko affected wolfi kaniko
kaniko affected chainguard kaniko
kargo affected chainguard kargo
kargo affected wolfi kargo
karpenter affected wolfi karpenter
karpenter affected chainguard karpenter
keda affected chainguard keda
keda affected wolfi keda
keda-2.10 affected wolfi keda-2.10
keda-2.10 affected chainguard keda-2.10
keda-2.11 affected chainguard keda-2.11
keda-2.11 affected wolfi keda-2.11
kind affected chainguard kind
kind affected wolfi kind
kine affected chainguard kine
kine affected wolfi kine
ko affected chainguard ko
ko affected wolfi ko
kor affected wolfi kor
kor affected chainguard kor
kots affected wolfi kots
kots affected chainguard kots
kpt affected chainguard kpt
kpt affected wolfi kpt
kube-bench affected wolfi kube-bench
kube-bench affected chainguard kube-bench
kubebuilder affected chainguard kubebuilder
kubebuilder affected wolfi kubebuilder
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-logging-operator affected chainguard kube-logging-operator
kube-logging-operator affected wolfi kube-logging-operator
kubernetes-1.26 affected chainguard kubernetes-1.26
kubernetes-1.26 affected wolfi kubernetes-1.26
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-csi-external-attacher-4.3 affected wolfi kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.3 affected chainguard kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.4 affected wolfi kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-attacher-4.4 affected chainguard kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-csi-external-snapshotter affected wolfi kubernetes-csi-external-snapshotter
kubernetes-csi-external-snapshotter affected chainguard kubernetes-csi-external-snapshotter
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-node-driver-registrar-2.9 affected wolfi kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-2.9 affected chainguard kubernetes-csi-node-driver-registrar-2.9
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-ingress-defaultbackend affected wolfi kubernetes-ingress-defaultbackend
kubernetes-ingress-defaultbackend affected chainguard kubernetes-ingress-defaultbackend
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kubewatch affected wolfi kubewatch
kubewatch affected chainguard kubewatch
kustomize affected chainguard kustomize
kustomize affected wolfi kustomize
kyverno affected wolfi kyverno
kyverno affected chainguard kyverno
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
kyverno-policy-reporter-kyverno-plugin affected wolfi kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-kyverno-plugin affected chainguard kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-ui affected chainguard kyverno-policy-reporter-ui
kyverno-policy-reporter-ui affected wolfi kyverno-policy-reporter-ui
litefs affected chainguard litefs
litefs affected wolfi litefs
local-path-provisioner affected wolfi local-path-provisioner
local-path-provisioner affected chainguard local-path-provisioner
loki affected wolfi loki
loki affected chainguard loki
mage affected chainguard mage
mage affected wolfi mage
mc affected chainguard mc
mc affected wolfi mc
melange affected chainguard melange
melange affected wolfi melange
memcached-exporter affected chainguard memcached-exporter
memcached-exporter affected wolfi memcached-exporter
metacontroller affected chainguard metacontroller
metacontroller affected wolfi metacontroller
metallb affected chainguard metallb
metallb affected wolfi metallb
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
minify affected wolfi minify
minify affected chainguard minify
minio affected wolfi minio
minio affected chainguard minio
mongo-tools affected chainguard mongo-tools
mongo-tools affected wolfi mongo-tools
nats affected wolfi nats
nats affected chainguard nats
nats-server affected wolfi nats-server
nats-server affected chainguard nats-server
nerdctl affected chainguard nerdctl
nerdctl affected wolfi nerdctl
newrelic-fluent-bit-output affected wolfi newrelic-fluent-bit-output
newrelic-fluent-bit-output affected chainguard newrelic-fluent-bit-output
newrelic-infra-operator affected wolfi newrelic-infra-operator
newrelic-infra-operator affected chainguard newrelic-infra-operator
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-bundle affected wolfi newrelic-infrastructure-bundle
newrelic-infrastructure-bundle affected chainguard newrelic-infrastructure-bundle
newrelic-nri-kube-events affected wolfi newrelic-nri-kube-events
newrelic-nri-kube-events affected chainguard newrelic-nri-kube-events
newrelic-prometheus-configurator affected wolfi newrelic-prometheus-configurator
newrelic-prometheus-configurator affected chainguard newrelic-prometheus-configurator
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
node-problem-detector-0.8 affected wolfi node-problem-detector-0.8
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nri-apache affected chainguard nri-apache
nri-apache affected wolfi nri-apache
nri-cassandra affected chainguard nri-cassandra
nri-cassandra affected wolfi nri-cassandra
nri-consul affected chainguard nri-consul
nri-consul affected wolfi nri-consul
nri-couchbase affected wolfi nri-couchbase
nri-couchbase affected chainguard nri-couchbase
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-elasticsearch affected wolfi nri-elasticsearch
nri-elasticsearch affected chainguard nri-elasticsearch
nri-f5 affected wolfi nri-f5
nri-f5 affected chainguard nri-f5
nri-haproxy affected wolfi nri-haproxy
nri-haproxy affected chainguard nri-haproxy
nri-jmx affected wolfi nri-jmx
nri-jmx affected chainguard nri-jmx
nri-kafka affected chainguard nri-kafka
nri-kafka affected wolfi nri-kafka
nri-kubernetes affected wolfi nri-kubernetes
nri-kubernetes affected chainguard nri-kubernetes
nri-memcached affected chainguard nri-memcached
nri-memcached affected wolfi nri-memcached
nri-mongodb affected chainguard nri-mongodb
nri-mongodb affected wolfi nri-mongodb
nri-mssql affected wolfi nri-mssql
nri-mssql affected chainguard nri-mssql
nri-mysql affected chainguard nri-mysql
nri-mysql affected wolfi nri-mysql
nri-nagios affected chainguard nri-nagios
nri-nagios affected wolfi nri-nagios
nri-nginx affected wolfi nri-nginx
nri-nginx affected chainguard nri-nginx
nri-postgresql affected wolfi nri-postgresql
nri-postgresql affected chainguard nri-postgresql
nri-prometheus affected wolfi nri-prometheus
nri-prometheus affected chainguard nri-prometheus
nri-rabbitmq affected wolfi nri-rabbitmq
nri-rabbitmq affected chainguard nri-rabbitmq
nri-redis affected chainguard nri-redis
nri-redis affected wolfi nri-redis
nsc affected wolfi nsc
nsc affected chainguard nsc
nuclei affected wolfi nuclei
nuclei affected chainguard nuclei
oauth2-proxy affected chainguard oauth2-proxy
oauth2-proxy affected wolfi oauth2-proxy
ollama affected chainguard ollama
ollama affected wolfi ollama
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentofu affected wolfi opentofu
opentofu affected chainguard opentofu
oras affected wolfi oras
oras affected chainguard oras
osv-scanner affected chainguard osv-scanner
osv-scanner affected wolfi osv-scanner
paranoia affected chainguard paranoia
paranoia affected wolfi paranoia
petname affected chainguard petname
petname affected wolfi petname
policy-controller affected chainguard policy-controller
policy-controller affected wolfi policy-controller
prometheus affected wolfi prometheus
prometheus affected chainguard prometheus
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter affected chainguard prometheus-adapter
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-blackbox-exporter affected wolfi prometheus-blackbox-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter affected wolfi prometheus-elasticsearch-exporter
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter affected wolfi prometheus-mongodb-exporter
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-mysqld-exporter affected wolfi prometheus-mysqld-exporter
prometheus-nats-exporter affected wolfi prometheus-nats-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-node-exporter affected wolfi prometheus-node-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-operator affected wolfi prometheus-operator
prometheus-operator affected chainguard prometheus-operator
prometheus-postgres-exporter affected wolfi prometheus-postgres-exporter
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-redis-exporter affected chainguard prometheus-redis-exporter
prometheus-redis-exporter affected wolfi prometheus-redis-exporter
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter affected wolfi prometheus-statsd-exporter
protoc-gen-go affected wolfi protoc-gen-go
protoc-gen-go affected chainguard protoc-gen-go
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-yaml affected chainguard pulumi-language-yaml
pulumi-language-yaml affected wolfi pulumi-language-yaml
q affected chainguard q
q affected wolfi q
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
rclone affected chainguard rclone
rclone affected wolfi rclone
regclient affected wolfi regclient
regclient affected chainguard regclient
rekor affected chainguard rekor
rekor affected wolfi rekor
render-template affected wolfi render-template
render-template affected chainguard render-template
restic affected wolfi restic
restic affected chainguard restic
rootlesskit affected wolfi rootlesskit
rootlesskit affected chainguard rootlesskit
rqlite affected chainguard rqlite
rqlite affected wolfi rqlite
runc affected wolfi runc
runc affected chainguard runc
sbomqs affected wolfi sbomqs
sbomqs affected chainguard sbomqs
sbom-scorecard affected chainguard sbom-scorecard
sbom-scorecard affected wolfi sbom-scorecard
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
sigstore-scaffolding affected wolfi sigstore-scaffolding
sigstore-scaffolding affected chainguard sigstore-scaffolding
skaffold affected wolfi skaffold
skaffold affected chainguard skaffold
skopeo affected chainguard skopeo
skopeo affected wolfi skopeo
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager affected chainguard smarter-device-manager
sonobuoy affected wolfi sonobuoy
sonobuoy affected chainguard sonobuoy
sops affected wolfi sops
sops affected chainguard sops
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
spicedb affected chainguard spicedb
spicedb affected wolfi spicedb
spire-server affected chainguard spire-server
spire-server affected wolfi spire-server
src affected wolfi src
src affected chainguard src
src-fingerprint affected wolfi src-fingerprint
src-fingerprint affected chainguard src-fingerprint
stakater-reloader affected chainguard stakater-reloader
stakater-reloader affected wolfi stakater-reloader
step affected chainguard step
step affected wolfi step
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
supercronic affected chainguard supercronic
supercronic affected wolfi supercronic
syft affected chainguard syft
syft affected wolfi syft
tailscale affected chainguard tailscale
tailscale affected wolfi tailscale
task affected wolfi task
task affected chainguard task
tctl affected chainguard tctl
tctl affected wolfi tctl
tekton-chains affected chainguard tekton-chains
tekton-chains affected wolfi tekton-chains
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.26 affected wolfi telegraf-1.26
telegraf-1.27 affected wolfi telegraf-1.27
telegraf-1.27 affected chainguard telegraf-1.27
temporal affected chainguard temporal
temporal affected wolfi temporal
temporal-fips affected chainguard temporal-fips
temporal-server affected wolfi temporal-server
temporal-server affected chainguard temporal-server
temporal-server-fips affected chainguard temporal-server-fips
temporal-ui-server affected chainguard temporal-ui-server
temporal-ui-server affected wolfi temporal-ui-server
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-provider-aws affected wolfi terraform-provider-aws
terraform-provider-aws affected chainguard terraform-provider-aws
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
tflint affected chainguard tflint
tflint affected wolfi tflint
thanos-0.31 affected wolfi thanos-0.31
thanos-0.31 affected chainguard thanos-0.31
thanos-0.32 affected chainguard thanos-0.32
thanos-0.32 affected wolfi thanos-0.32
thanos-operator affected chainguard thanos-operator
thanos-operator affected wolfi thanos-operator
tigera-operator-1.30 affected chainguard tigera-operator-1.30
tigera-operator-1.30 affected wolfi tigera-operator-1.30
tigera-operator-1.31 affected wolfi tigera-operator-1.31
tigera-operator-1.31 affected chainguard tigera-operator-1.31
timestamp-authority affected chainguard timestamp-authority
timestamp-authority affected wolfi timestamp-authority
timoni affected chainguard timoni
timoni affected wolfi timoni
tkn affected wolfi tkn
tkn affected chainguard tkn
traefik affected chainguard traefik
traefik affected wolfi traefik
trillian affected chainguard trillian
trillian affected wolfi trillian
trivy affected chainguard trivy
trivy affected wolfi trivy
trust-manager affected chainguard trust-manager
trust-manager affected wolfi trust-manager
up affected wolfi up
up affected chainguard up
vault-1.13 affected chainguard vault-1.13
vault-1.13 affected wolfi vault-1.13
vault-csi-provider affected chainguard vault-csi-provider
vault-csi-provider affected wolfi vault-csi-provider
vault-k8s affected chainguard vault-k8s
vault-k8s affected wolfi vault-k8s
velero affected chainguard velero
velero affected wolfi velero
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
volume-modifier-for-k8s affected wolfi volume-modifier-for-k8s
volume-modifier-for-k8s affected chainguard volume-modifier-for-k8s
vt-cli affected chainguard vt-cli
vt-cli affected wolfi vt-cli
wait-for-port affected chainguard wait-for-port
wait-for-port affected wolfi wait-for-port
wazero affected chainguard wazero
wazero affected wolfi wazero
weaviate affected chainguard weaviate
weaviate affected wolfi weaviate
wire-go affected chainguard wire-go
wire-go affected wolfi wire-go
wireguard-go affected wolfi wireguard-go
wireguard-go affected chainguard wireguard-go
wolfictl affected wolfi wolfictl
wolfictl affected chainguard wolfictl
yq affected chainguard yq
yq affected wolfi yq
ytt affected wolfi ytt
ytt affected chainguard ytt
zarf affected chainguard zarf
zarf affected wolfi zarf
Upstream advisory

AZL-37425

Open SourcePoC exploitMEDIUM2023-11-09

CVE-2023-45284 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37513

Open SourcePoC exploitMEDIUM2023-11-09

CVE-2023-45284 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-78944

Open SourcePoC exploitMEDIUM2023-11-09

CVE-2023-45284 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-45284

Open SourcePoC exploitMEDIUM2023-11-09

DEBIAN-CVE-2023-45284

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.15 affected Debian
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GO-2023-2186

Open SourcePoC exploit2023-11-08

Incorrect detection of reserved device names on Windows in path/filepath

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller affected wolfi actions-runner-controller
amass affected chainguard amass
amass affected wolfi amass
apko affected chainguard apko
apko affected wolfi apko
argo-workflows affected wolfi argo-workflows
argo-workflows affected chainguard argo-workflows
atlantis affected wolfi atlantis
atlantis affected chainguard atlantis
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
bom affected chainguard bom
bom affected wolfi bom
boring-registry affected wolfi boring-registry
boring-registry affected chainguard boring-registry
buf affected wolfi buf
buf affected chainguard buf
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
caddy affected wolfi caddy
caddy affected chainguard caddy
capslock affected wolfi capslock
capslock affected chainguard capslock
certificate-transparency affected chainguard certificate-transparency
certificate-transparency affected wolfi certificate-transparency
cfssl affected wolfi cfssl
cfssl affected chainguard cfssl
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
cloudflared affected wolfi cloudflared
cloudflared affected chainguard cloudflared
cluster-proportional-autoscaler affected chainguard cluster-proportional-autoscaler
cluster-proportional-autoscaler affected wolfi cluster-proportional-autoscaler
cni-plugins affected wolfi cni-plugins
cni-plugins affected chainguard cni-plugins
configmap-reload affected wolfi configmap-reload
configmap-reload affected chainguard configmap-reload
conftest affected wolfi conftest
conftest affected chainguard conftest
cortex affected chainguard cortex
cortex affected wolfi cortex
cosign affected chainguard cosign
cosign affected wolfi cosign
crane affected wolfi crane
crane affected chainguard crane
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
croc affected wolfi croc
croc affected chainguard croc
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-azure affected wolfi crossplane-provider-azure
crossplane-provider-azure affected chainguard crossplane-provider-azure
ctop affected chainguard ctop
ctop affected wolfi ctop
cue affected chainguard cue
cue affected wolfi cue
dask-gateway affected wolfi dask-gateway
dask-gateway affected chainguard dask-gateway
dataplaneapi affected wolfi dataplaneapi
dataplaneapi affected chainguard dataplaneapi
delve affected chainguard delve
delve affected wolfi delve
dex affected chainguard dex
dex affected wolfi dex
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
dive affected wolfi dive
dive affected chainguard dive
docker-credential-acr-env affected wolfi docker-credential-acr-env
docker-credential-acr-env affected chainguard docker-credential-acr-env
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-gcr affected chainguard docker-credential-gcr
docker-credential-gcr affected wolfi docker-credential-gcr
dockerize affected wolfi dockerize
dockerize affected chainguard dockerize
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
envoy-ratelimit affected wolfi envoy-ratelimit
envoy-ratelimit affected chainguard envoy-ratelimit
esbuild affected chainguard esbuild
esbuild affected wolfi esbuild
etcd-3.5 affected chainguard etcd-3.5
falcoctl affected wolfi falcoctl
falcoctl affected chainguard falcoctl
ferretdb affected chainguard ferretdb
ferretdb affected wolfi ferretdb
flannel affected wolfi flannel
flannel affected chainguard flannel
flannel-cni-plugin affected wolfi flannel-cni-plugin
flannel-cni-plugin affected chainguard flannel-cni-plugin
flux affected chainguard flux
flux affected wolfi flux
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
fq affected chainguard fq
fq affected wolfi fq
frp affected chainguard frp
frp affected wolfi frp
fulcio affected chainguard fulcio
fulcio affected wolfi fulcio
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
fzf affected chainguard fzf
fzf affected wolfi fzf
gcsfuse affected chainguard gcsfuse
gcsfuse affected wolfi gcsfuse
git-lfs affected wolfi git-lfs
git-lfs affected chainguard git-lfs
gitness affected wolfi gitness
gitness affected chainguard gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
glab affected wolfi glab
glab affected chainguard glab
go-bindata affected wolfi go-bindata
go-bindata affected chainguard go-bindata
gobuster affected wolfi gobuster
gobuster affected chainguard gobuster
golangci-lint affected wolfi golangci-lint
golangci-lint affected chainguard golangci-lint
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
go-md2man affected wolfi go-md2man
go-md2man affected chainguard go-md2man
gops affected chainguard gops
gops affected wolfi gops
goreleaser affected wolfi goreleaser
goreleaser affected chainguard goreleaser
gosu affected chainguard gosu
gosu affected wolfi gosu
govulncheck affected chainguard govulncheck
govulncheck affected wolfi govulncheck
grpc-health-probe affected wolfi grpc-health-probe
grpc-health-probe affected chainguard grpc-health-probe
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
grype affected wolfi grype
grype affected chainguard grype
guac affected wolfi guac
guac affected chainguard guac
haproxy-ingress affected chainguard haproxy-ingress
haproxy-ingress affected wolfi haproxy-ingress
helm affected chainguard helm
helm affected wolfi helm
helm-3 affected wolfi helm-3
helm-3 affected chainguard helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
hey affected wolfi hey
hey affected chainguard hey
http-echo affected chainguard http-echo
http-echo affected wolfi http-echo
hubble affected wolfi hubble
hubble affected chainguard hubble
hubble-ui affected chainguard hubble-ui
hubble-ui affected wolfi hubble-ui
hugo affected wolfi hugo
hugo affected chainguard hugo
hugo-extended affected chainguard hugo-extended
hugo-extended affected wolfi hugo-extended
influx affected wolfi influx
influx affected chainguard influx
ip-masq-agent affected chainguard ip-masq-agent
ip-masq-agent affected wolfi ip-masq-agent
k3d affected chainguard k3d
k3d affected wolfi k3d
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
k8sgpt-operator affected wolfi k8sgpt-operator
k8sgpt-operator affected chainguard k8sgpt-operator
kaf affected chainguard kaf
kaf affected wolfi kaf
kaniko affected wolfi kaniko
kaniko affected chainguard kaniko
kargo affected wolfi kargo
kargo affected chainguard kargo
kind affected wolfi kind
kind affected chainguard kind
kine affected chainguard kine
kine affected wolfi kine
ko affected wolfi ko
ko affected chainguard ko
kor affected chainguard kor
kor affected wolfi kor
kots affected chainguard kots
kots affected wolfi kots
kpt affected chainguard kpt
kpt affected wolfi kpt
kube-bench affected chainguard kube-bench
kube-bench affected wolfi kube-bench
kubebuilder affected wolfi kubebuilder
kubebuilder affected chainguard kubebuilder
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-logging-operator affected wolfi kube-logging-operator
kube-logging-operator affected chainguard kube-logging-operator
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-ingress-defaultbackend affected chainguard kubernetes-ingress-defaultbackend
kubernetes-ingress-defaultbackend affected wolfi kubernetes-ingress-defaultbackend
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kubewatch affected chainguard kubewatch
kubewatch affected wolfi kubewatch
kustomize affected wolfi kustomize
kustomize affected chainguard kustomize
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
kyverno-policy-reporter-kyverno-plugin affected chainguard kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-kyverno-plugin affected wolfi kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-ui affected wolfi kyverno-policy-reporter-ui
kyverno-policy-reporter-ui affected chainguard kyverno-policy-reporter-ui
litefs affected wolfi litefs
litefs affected chainguard litefs
local-path-provisioner affected wolfi local-path-provisioner
local-path-provisioner affected chainguard local-path-provisioner
mage affected wolfi mage
mage affected chainguard mage
mc affected chainguard mc
mc affected wolfi mc
melange affected wolfi melange
melange affected chainguard melange
memcached-exporter affected chainguard memcached-exporter
memcached-exporter affected wolfi memcached-exporter
metacontroller affected wolfi metacontroller
metacontroller affected chainguard metacontroller
metallb affected chainguard metallb
metallb affected wolfi metallb
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
minify affected chainguard minify
minify affected wolfi minify
minio affected wolfi minio
minio affected chainguard minio
mongo-tools affected wolfi mongo-tools
mongo-tools affected chainguard mongo-tools
nats affected chainguard nats
nats affected wolfi nats
nats-server affected wolfi nats-server
nats-server affected chainguard nats-server
nerdctl affected chainguard nerdctl
nerdctl affected wolfi nerdctl
newrelic-fluent-bit-output affected wolfi newrelic-fluent-bit-output
newrelic-fluent-bit-output affected chainguard newrelic-fluent-bit-output
newrelic-infra-operator affected wolfi newrelic-infra-operator
newrelic-infra-operator affected chainguard newrelic-infra-operator
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-bundle affected wolfi newrelic-infrastructure-bundle
newrelic-infrastructure-bundle affected chainguard newrelic-infrastructure-bundle
newrelic-nri-kube-events affected wolfi newrelic-nri-kube-events
newrelic-nri-kube-events affected chainguard newrelic-nri-kube-events
newrelic-prometheus-configurator affected wolfi newrelic-prometheus-configurator
newrelic-prometheus-configurator affected chainguard newrelic-prometheus-configurator
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
nri-apache affected wolfi nri-apache
nri-apache affected chainguard nri-apache
nri-cassandra affected wolfi nri-cassandra
nri-cassandra affected chainguard nri-cassandra
nri-consul affected wolfi nri-consul
nri-consul affected chainguard nri-consul
nri-couchbase affected chainguard nri-couchbase
nri-couchbase affected wolfi nri-couchbase
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nri-elasticsearch affected wolfi nri-elasticsearch
nri-elasticsearch affected chainguard nri-elasticsearch
nri-f5 affected wolfi nri-f5
nri-f5 affected chainguard nri-f5
nri-haproxy affected chainguard nri-haproxy
nri-haproxy affected wolfi nri-haproxy
nri-jmx affected wolfi nri-jmx
nri-jmx affected chainguard nri-jmx
nri-kafka affected chainguard nri-kafka
nri-kafka affected wolfi nri-kafka
nri-kubernetes affected wolfi nri-kubernetes
nri-kubernetes affected chainguard nri-kubernetes
nri-memcached affected wolfi nri-memcached
nri-memcached affected chainguard nri-memcached
nri-mongodb affected chainguard nri-mongodb
nri-mongodb affected wolfi nri-mongodb
nri-mssql affected wolfi nri-mssql
nri-mssql affected chainguard nri-mssql
nri-mysql affected wolfi nri-mysql
nri-mysql affected chainguard nri-mysql
nri-nagios affected chainguard nri-nagios
nri-nagios affected wolfi nri-nagios
nri-nginx affected wolfi nri-nginx
nri-nginx affected chainguard nri-nginx
nri-postgresql affected chainguard nri-postgresql
nri-postgresql affected wolfi nri-postgresql
nri-prometheus affected wolfi nri-prometheus
nri-prometheus affected chainguard nri-prometheus
nri-rabbitmq affected chainguard nri-rabbitmq
nri-rabbitmq affected wolfi nri-rabbitmq
nri-redis affected chainguard nri-redis
nri-redis affected wolfi nri-redis
nsc affected chainguard nsc
nsc affected wolfi nsc
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
oauth2-proxy affected chainguard oauth2-proxy
oauth2-proxy affected wolfi oauth2-proxy
ollama affected chainguard ollama
ollama affected wolfi ollama
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
oras affected wolfi oras
oras affected chainguard oras
osv-scanner affected wolfi osv-scanner
osv-scanner affected chainguard osv-scanner
paranoia affected wolfi paranoia
paranoia affected chainguard paranoia
petname affected wolfi petname
petname affected chainguard petname
policy-controller affected chainguard policy-controller
policy-controller affected wolfi policy-controller
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter affected chainguard prometheus-adapter
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-operator affected chainguard prometheus-operator
prometheus-operator affected wolfi prometheus-operator
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-redis-exporter affected chainguard prometheus-redis-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
protoc-gen-go affected wolfi protoc-gen-go
protoc-gen-go affected chainguard protoc-gen-go
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
pulumi affected chainguard pulumi
pulumi affected wolfi pulumi
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-yaml affected wolfi pulumi-language-yaml
pulumi-language-yaml affected chainguard pulumi-language-yaml
q affected wolfi q
q affected chainguard q
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
rclone affected wolfi rclone
rclone affected chainguard rclone
regclient affected chainguard regclient
regclient affected wolfi regclient
rekor affected wolfi rekor
rekor affected chainguard rekor
render-template affected chainguard render-template
render-template affected wolfi render-template
restic affected chainguard restic
restic affected wolfi restic
rootlesskit affected wolfi rootlesskit
rootlesskit affected chainguard rootlesskit
rqlite affected chainguard rqlite
rqlite affected wolfi rqlite
runc affected wolfi runc
runc affected chainguard runc
sbomqs affected wolfi sbomqs
sbomqs affected chainguard sbomqs
sbom-scorecard affected chainguard sbom-scorecard
sbom-scorecard affected wolfi sbom-scorecard
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
sigstore-scaffolding affected wolfi sigstore-scaffolding
sigstore-scaffolding affected chainguard sigstore-scaffolding
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
skopeo affected wolfi skopeo
skopeo affected chainguard skopeo
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager affected wolfi smarter-device-manager
sonobuoy affected chainguard sonobuoy
sonobuoy affected wolfi sonobuoy
sops affected chainguard sops
sops affected wolfi sops
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
spicedb affected chainguard spicedb
spicedb affected wolfi spicedb
spire-server affected wolfi spire-server
spire-server affected chainguard spire-server
src affected wolfi src
src affected chainguard src
src-fingerprint affected chainguard src-fingerprint
src-fingerprint affected wolfi src-fingerprint
stakater-reloader affected wolfi stakater-reloader
stakater-reloader affected chainguard stakater-reloader
stdlib affected Go stdlib
step affected wolfi step
step affected chainguard step
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
supercronic affected chainguard supercronic
supercronic affected wolfi supercronic
syft affected chainguard syft
syft affected wolfi syft
tailscale affected chainguard tailscale
tailscale affected wolfi tailscale
task affected wolfi task
task affected chainguard task
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
temporal affected wolfi temporal
temporal affected chainguard temporal
temporal-fips affected chainguard temporal-fips
temporal-server affected chainguard temporal-server
temporal-server affected wolfi temporal-server
temporal-server-fips affected chainguard temporal-server-fips
temporal-ui-server affected wolfi temporal-ui-server
temporal-ui-server affected chainguard temporal-ui-server
terraform affected chainguard terraform
terraform affected wolfi terraform
terraform-provider-aws affected chainguard terraform-provider-aws
terraform-provider-aws affected wolfi terraform-provider-aws
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
tflint affected chainguard tflint
tflint affected wolfi tflint
thanos-operator affected chainguard thanos-operator
thanos-operator affected wolfi thanos-operator
timestamp-authority affected wolfi timestamp-authority
timestamp-authority affected chainguard timestamp-authority
timoni affected wolfi timoni
timoni affected chainguard timoni
tkn affected wolfi tkn
tkn affected chainguard tkn
trillian affected wolfi trillian
trillian affected chainguard trillian
trivy affected wolfi trivy
trivy affected chainguard trivy
trust-manager affected wolfi trust-manager
trust-manager affected chainguard trust-manager
up affected wolfi up
up affected chainguard up
vault-csi-provider affected chainguard vault-csi-provider
vault-k8s affected chainguard vault-k8s
vault-k8s affected wolfi vault-k8s
velero affected wolfi velero
velero affected chainguard velero
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
volume-modifier-for-k8s affected chainguard volume-modifier-for-k8s
volume-modifier-for-k8s affected wolfi volume-modifier-for-k8s
vt-cli affected wolfi vt-cli
vt-cli affected chainguard vt-cli
wait-for-port affected chainguard wait-for-port
wait-for-port affected wolfi wait-for-port
wazero affected chainguard wazero
wazero affected wolfi wazero
weaviate affected chainguard weaviate
weaviate affected wolfi weaviate
wire-go affected wolfi wire-go
wire-go affected chainguard wire-go
wireguard-go affected wolfi wireguard-go
wireguard-go affected chainguard wireguard-go
wolfictl affected wolfi wolfictl
wolfictl affected chainguard wolfictl
yq affected chainguard yq
yq affected wolfi yq
ytt affected chainguard ytt
ytt affected wolfi ytt
zarf affected chainguard zarf
zarf affected wolfi zarf
Upstream advisory

CVE-2023-45284

GooglePoC exploit2023-11-07

On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.

CVEs:CVE-2023-45284

Upstream advisory

CVE-2023-45284

GooglePoC exploitMEDIUM2023-11-07

On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local...

CVEs:CVE-2023-45284

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

DEBIAN-CVE-2023-45286

Open SourcePoC exploitMEDIUM2023-11-28

DEBIAN-CVE-2023-45286

Affected products

ProductStatusVendorPackageEcosystem
golang-github-go-resty-resty affected Debian:14 golang-github-go-resty-resty
golang-github-go-resty-resty affected Debian:11 golang-github-go-resty-resty
golang-github-go-resty-resty affected Debian:12 golang-github-go-resty-resty
golang-github-go-resty-resty affected Debian:13 golang-github-go-resty-resty
Upstream advisory

CVE-2023-40109

Open SourcePoC exploitHIGH2023-11-06

In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed ...

CVEs:CVE-2023-40109

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2023:0372-1

Open SourceCoalition ESS < 30%CRITICAL2023-11-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.4 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DEBIAN-CVE-2023-6112

Open SourceCoalition ESS < 30%CRITICAL2023-11-15

DEBIAN-CVE-2023-6112

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-5556-1

Open SourceCoalition ESS < 30%2023-11-15

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2023-6112

GoogleCoalition ESS < 30%2023-11-14

Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6112

Upstream advisory

CVE-2023-6112

GoogleCoalition ESS < 30%CRITICAL2023-11-14

Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6112

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DSA-5551-1

Open SourceCoalition ESS < 30%2023-11-09

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-5996

Open SourceCoalition ESS < 30%CRITICAL2023-11-08

DEBIAN-CVE-2023-5996

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5996

GoogleCoalition ESS < 30%2023-11-07

Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5996

Upstream advisory

CVE-2023-5996

GoogleCoalition ESS < 30%CRITICAL2023-11-07

Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5996

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-5856

Open SourceCoalition ESS < 30%CRITICAL2023-11-01

DEBIAN-CVE-2023-5856

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-36027

Open SourceCoalition ESS < 30%CRITICAL2023-11-09

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2023-36027

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

AZL-31786

Open SourceCoalition ESS < 30%CRITICAL2023-11-02

CVE-2023-5408 affecting package kubernetes for versions less than 1.28.4-5

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:2 kubernetes
Upstream advisory

AZL-34898

Open SourceCoalition ESS < 30%CRITICAL2023-11-02

CVE-2023-5408 affecting package kubernetes for versions less than 1.29.1-2

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:3 kubernetes
Upstream advisory

CVE-2023-36024

Open SourceCoalition ESS < 30%CRITICAL2023-11-09

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2023-36024

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2023-5997

Open SourceCoalition ESS < 30%CRITICAL2023-11-15

DEBIAN-CVE-2023-5997

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5997

GoogleCoalition ESS < 30%CRITICAL2023-11-14

Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5997

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5997

GoogleCoalition ESS < 30%2023-11-14

Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5997

Upstream advisory

DEBIAN-CVE-2023-5851

Open SourceCoalition ESS < 30%MEDIUM2023-11-01

DEBIAN-CVE-2023-5851

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-3f2q-6294-fmq5

Open SourceCoalition ESS < 30%HIGH2023-11-18

Inefficient Regular Expression Complexity in git-urls

Affected products

ProductStatusVendorPackageEcosystem
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.8 affected wolfi argo-cd-2.8
argo-cd-2.9 affected chainguard argo-cd-2.9
argo-cd-2.9 affected wolfi argo-cd-2.9
argo-events affected chainguard argo-events
argo-events affected wolfi argo-events
argo-events-fips affected chainguard argo-events-fips
argo-workflows affected chainguard argo-workflows
argo-workflows affected wolfi argo-workflows
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller-0 affected chainguard flux-notification-controller-0
flux-notification-controller-0.37 affected chainguard flux-notification-controller-0.37
melange affected chainguard melange
melange affected wolfi melange
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
snyk-cli affected chainguard snyk-cli
snyk-cli affected wolfi snyk-cli
task affected chainguard task
task affected wolfi task
whilp/git-urls affected github.com github.com/whilp/git-urls
Upstream advisory

GHSA-3f2q-6294-fmq5

GoogleCoalition ESS < 30%HIGH2023-11-18

Inefficient Regular Expression Complexity in git-urls

Affected products

ProductStatusVendorPackageEcosystem
whilp/git-urls affected github.com github.com/whilp/git-urls
Upstream advisory

CVE-2023-36026

Open SourceCoalition ESS < 30%MEDIUM2023-11-14

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2023-36026

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2023-5853

Open SourceCoalition ESS < 30%MEDIUM2023-11-01

DEBIAN-CVE-2023-5853

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-5858

Open SourceCoalition ESS < 30%MEDIUM2023-11-01

DEBIAN-CVE-2023-5858

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-0436

Open SourceCoalition ESS < 30%HIGH2023-11-07

The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator versions: 1.5...

CVEs:CVE-2023-0436

Affected products

ProductStatusVendorPackageEcosystem
atlas_kubernetes_operator affected mongodb
Upstream advisory

CVE-2023-36008

Open SourceCoalition ESS < 30%CRITICAL2023-11-14

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2023-36008

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-5128

GoogleCoalition ESS < 30%HIGH2023-11-22

The TCD Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'map' shortcode in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib...

CVEs:CVE-2023-5128

Affected products

ProductStatusVendorPackageEcosystem
tcd_google_maps affected tcd-theme
Upstream advisory

GHSA-4233-7q5q-m7p6

GoogleCoalition ESS < 30%CRITICAL2023-11-27

google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
google-translate-api-browser affected npm google-translate-api-browser
Upstream advisory

GHSA-4233-7q5q-m7p6

GoogleCoalition ESS < 30%CRITICAL2023-11-27

google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
google-translate-api-browser affected npm google-translate-api-browser
Upstream advisory

CVE-2023-48711

GoogleCoalition ESS < 30%LOW2023-11-24

google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability

CVEs:CVE-2023-48711

Affected products

ProductStatusVendorPackageEcosystem
google-translate-api-browser affected npm google-translate-api-browser
Upstream advisory

CVE-2023-48711

GoogleCoalition ESS < 30%CRITICAL2023-11-24

google-translate-api-browser is an npm package which interfaces with the google translate web api. A Server-Side Request Forgery (SSRF) Vulnerability is present in applications utilizing the `google-translate-api-browser` package and exposing the `tran...

CVEs:CVE-2023-48711

Affected products

ProductStatusVendorPackageEcosystem
google_translate_api_browser affected cjvnjde
Upstream advisory

CVE-2023-48711

GoogleCoalition ESS < 30%LOW2023-11-24

google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability

CVEs:CVE-2023-48711

Affected products

ProductStatusVendorPackageEcosystem
google-translate-api-browser affected npm google-translate-api-browser
Upstream advisory

CVE-2023-42530

Open SourceCoalition ESS < 30%HIGH2023-11-06

Improper access control vulnerability in SecSettings prior to SMR Nov-2023 Release 1 allows attackers to enable Wi-Fi and Wi-Fi Direct without User Interaction.

CVEs:CVE-2023-42530

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-49673

GoogleCoalition ESS < 30%2023-11-29

A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.

CVEs:CVE-2023-49673

Upstream advisory

CVE-2023-49673

GoogleCoalition ESS < 30%MEDIUM2023-11-29

Jenkins NeuVector Vulnerability Scanner Plugin Cross-Site Request Forgery vulnerability

CVEs:CVE-2023-49673

Affected products

ProductStatusVendorPackageEcosystem
io.jenkins.plugins:neuvector-vulnerability-scanner affected Maven io.jenkins.plugins:neuvector-vulnerability-scanner
Upstream advisory

CVE-2023-49673

GoogleCoalition ESS < 30%HIGH2023-11-29

A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.

CVEs:CVE-2023-49673

Affected products

ProductStatusVendorPackageEcosystem
google_compute_engine affected jenkins
jira affected jenkins
matlab affected jenkins
neuvector_vulnerability_scanner affected jenkins
Upstream advisory

GO-2023-2158

GoogleCoalition ESS < 30%CRITICAL2023-11-02

Google Sheet API key disclosure in github.com/grafana/google-sheets-datasource

Affected products

ProductStatusVendorPackageEcosystem
grafana/google-sheets-datasource affected github.com github.com/grafana/google-sheets-datasource
Upstream advisory

CVE-2023-42532

Open SourceCoalition ESS < 30%CRITICAL2023-11-06

Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.

CVEs:CVE-2023-42532

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42533

Open SourceCoalition ESS < 30%CRITICAL2023-11-06

Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.

CVEs:CVE-2023-42533

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

RHSA-2023:6944

Open SourceCoalition ESS < 30%MEDIUM2023-11-14

Red Hat Security Advisory: protobuf-c security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected Red Hat:enterprise_linux:8::appstream protobuf-c
protobuf-c-compiler affected Red Hat:enterprise_linux:8::appstream protobuf-c-compiler
protobuf-c-compiler-debuginfo affected Red Hat:enterprise_linux:8::appstream protobuf-c-compiler-debuginfo
protobuf-c-debuginfo affected Red Hat:enterprise_linux:8::appstream protobuf-c-debuginfo
protobuf-c-debugsource affected Red Hat:enterprise_linux:8::appstream protobuf-c-debugsource
protobuf-c-devel affected Red Hat:enterprise_linux:8::appstream protobuf-c-devel
Upstream advisory

ALSA-2023:6944

Open SourceCoalition ESS < 30%CRITICAL2023-11-14

Moderate: protobuf-c security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected AlmaLinux:8 protobuf-c
protobuf-c-compiler affected AlmaLinux:8 protobuf-c-compiler
protobuf-c-devel affected AlmaLinux:8 protobuf-c-devel
Upstream advisory

RHSA-2023:6621

Open SourceCoalition ESS < 30%MEDIUM2023-11-07

Red Hat Security Advisory: protobuf-c security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected Red Hat:enterprise_linux:9::crb protobuf-c
protobuf-c affected Red Hat:enterprise_linux:9::baseos protobuf-c
protobuf-c-compiler affected Red Hat:enterprise_linux:9::crb protobuf-c-compiler
protobuf-c-compiler affected Red Hat:enterprise_linux:9::baseos protobuf-c-compiler
protobuf-c-compiler-debuginfo affected Red Hat:enterprise_linux:9::baseos protobuf-c-compiler-debuginfo
protobuf-c-compiler-debuginfo affected Red Hat:enterprise_linux:9::crb protobuf-c-compiler-debuginfo
protobuf-c-debuginfo affected Red Hat:enterprise_linux:9::baseos protobuf-c-debuginfo
protobuf-c-debuginfo affected Red Hat:enterprise_linux:9::crb protobuf-c-debuginfo
protobuf-c-debugsource affected Red Hat:enterprise_linux:9::baseos protobuf-c-debugsource
protobuf-c-debugsource affected Red Hat:enterprise_linux:9::crb protobuf-c-debugsource
protobuf-c-devel affected Red Hat:enterprise_linux:9::baseos protobuf-c-devel
protobuf-c-devel affected Red Hat:enterprise_linux:9::crb protobuf-c-devel
Upstream advisory

ALSA-2023:6621

Open SourceCoalition ESS < 30%CRITICAL2023-11-07

Moderate: protobuf-c security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected AlmaLinux:9 protobuf-c
protobuf-c-compiler affected AlmaLinux:9 protobuf-c-compiler
protobuf-c-devel affected AlmaLinux:9 protobuf-c-devel
Upstream advisory

CVE-2023-40104

Open SourceCoalition ESS < 30%HIGH2023-11-06

In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2023-40104

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32514

GoogleCoalition ESS < 30%HIGH2023-11-18

Cross-Site Request Forgery (CSRF) vulnerability in Himanshu Parashar Google Site Verification plugin using Meta Tag.This issue affects Google Site Verification plugin using Meta Tag: from n/a through 1.2.

CVEs:CVE-2023-32514

Affected products

ProductStatusVendorPackageEcosystem
google_site_verification_plugin_using_meta_tag affected himanshuparashar
Upstream advisory

CVE-2023-47237

GoogleCoalition ESS < 30%HIGH2023-11-09

Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson Auto Publish for Google My Business plugin <= 3.7 versions.

CVEs:CVE-2023-47237

Affected products

ProductStatusVendorPackageEcosystem
auto_publish_for_google_my_business affected auto_publish_for_google_my_business_project
Upstream advisory

CVE-2023-42535

Open SourceCoalition ESS < 30%HIGH2023-11-06

Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-42535

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42528

Open SourceCoalition ESS < 30%HIGH2023-11-06

Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-42528

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42529

Open SourceCoalition ESS < 30%HIGH2023-11-06

Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.

CVEs:CVE-2023-42529

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42536

Open SourceCoalition ESS < 30%HIGH2023-11-06

An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

CVEs:CVE-2023-42536

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42537

Open SourceCoalition ESS < 30%HIGH2023-11-06

An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

CVEs:CVE-2023-42537

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-40115

Open SourceCoalition ESS < 30%CRITICAL2023-11-06

In readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40115

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42538

Open SourceCoalition ESS < 30%HIGH2023-11-06

An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

CVEs:CVE-2023-42538

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42534

Open SourceCoalition ESS < 30%MEDIUM2023-11-06

Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.

CVEs:CVE-2023-42534

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42527

Open SourceCoalition ESS < 30%MEDIUM2023-11-06

Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.

CVEs:CVE-2023-42527

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-295039120

GoogleCoalition ESS < 30%2023-11-01

ASB-A-295039120

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-290061915

GoogleCoalition ESS < 30%2023-11-01

ASB-A-290061915

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-295019252

GoogleCoalition ESS < 30%2023-11-01

ASB-A-295019252

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2023-40110

Open SourceCoalition ESS < 30%HIGH2023-11-06

In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2023-40110

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40114

Open SourceCoalition ESS < 30%HIGH2023-11-06

In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2023-40114

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40111

Open SourceCoalition ESS < 30%HIGH2023-11-06

In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed....

CVEs:CVE-2023-40111

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40100

Open SourceCoalition ESS < 30%HIGH2023-11-06

In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40100

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40124

Open SourceCoalition ESS < 30%MEDIUM2023-11-06

In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40124

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32818

Open SourceCoalition ESS < 30%HIGH2023-11-06

In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896 & ALPS08013430; Is...

CVEs:CVE-2023-32818

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42750

Open SourceCoalition ESS < 30%CRITICAL2023-11-01

In gnss service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42750

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40106

Open SourceCoalition ESS < 30%HIGH2023-11-06

In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...

CVEs:CVE-2023-40106

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40107

Open SourceCoalition ESS < 30%HIGH2023-11-06

In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40107

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40112

Open SourceCoalition ESS < 30%MEDIUM2023-11-06

In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of past print jobs or other print-related information, with no additional execution privileges needed. Use...

CVEs:CVE-2023-40112

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42645

Open SourceCoalition ESS < 30%HIGH2023-11-01

In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42645

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42647

Open SourceCoalition ESS < 30%HIGH2023-11-01

In Ifaa service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42647

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42649

Open SourceCoalition ESS < 30%HIGH2023-11-01

In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42649

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42653

Open SourceCoalition ESS < 30%CRITICAL2023-11-01

In faceid service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges

CVEs:CVE-2023-42653

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48456

Open SourceCoalition ESS < 30%CRITICAL2023-11-01

In camera driver, there is a possible out of bounds write due to a incorrect bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2022-48456

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48461

Open SourceCoalition ESS < 30%CRITICAL2023-11-01

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2022-48461

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40105

Open SourceCoalition ESS < 30%MEDIUM2023-11-06

In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2023-40105

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40113

Open SourceCoalition ESS < 30%MEDIUM2023-11-06

In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2023-40113

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42655

Open SourceCoalition ESS < 30%MEDIUM2023-11-01

In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed

CVEs:CVE-2023-42655

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48454

Open SourceCoalition ESS < 30%CRITICAL2023-11-01

In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2022-48454

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48455

Open SourceCoalition ESS < 30%CRITICAL2023-11-01

In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2022-48455

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48457

Open SourceCoalition ESS < 30%HIGH2023-11-01

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2022-48457

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48458

Open SourceCoalition ESS < 30%HIGH2023-11-01

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2022-48458

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48459

Open SourceCoalition ESS < 30%HIGH2023-11-01

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2022-48459

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48460

Open SourceCoalition ESS < 30%HIGH2023-11-01

In setting service, there is a possible undefined behavior due to incorrect error handling. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2022-48460

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42641

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42641

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42642

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42642

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42643

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42643

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42644

Open SourceCoalition ESS < 30%HIGH2023-11-01

In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42644

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42646

Open SourceCoalition ESS < 30%HIGH2023-11-01

In Ifaa service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42646

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42648

Open SourceCoalition ESS < 30%HIGH2023-11-01

In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42648

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42650

Open SourceCoalition ESS < 30%HIGH2023-11-01

In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42650

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42651

Open SourceCoalition ESS < 30%HIGH2023-11-01

In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42651

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42652

Open SourceCoalition ESS < 30%HIGH2023-11-01

In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42652

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42632

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42632

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42633

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42633

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42634

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42634

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42635

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42635

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42636

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42636

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42637

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42637

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42638

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42638

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42639

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42639

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42640

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42640

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42654

Open SourceCoalition ESS < 30%HIGH2023-11-01

In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42654

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42631

Open SourceCoalition ESS < 30%HIGH2023-11-01

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42631

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-280447210

GoogleEPSS <= 49%2023-11-01

PUB-A-280447210

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-28173

GoogleEPSS <= 49%HIGH2023-11-12

Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Images plugin <= 2.1.3 versions.

CVEs:CVE-2023-28173

Affected products

ProductStatusVendorPackageEcosystem
google_xml_sitemap_for_images affected digitalinspiration
Upstream advisory

CVE-2023-26514

GoogleEPSS <= 49%HIGH2023-11-12

Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Dynamic XML Sitemaps Generator for Google plugin <= 1.3.3 versions.

CVEs:CVE-2023-26514

Affected products

ProductStatusVendorPackageEcosystem
dynamic_xml_sitemaps_generator_for_google affected wpgrim
Upstream advisory

CVE-2023-30739

Open SourceEPSS <= 49%HIGH2023-11-06

Arbitrary File Descriptor Write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-30739

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-274006187

GoogleEPSS <= 49%2023-11-01

ASB-A-274006187

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-280446988

GoogleEPSS <= 49%2023-11-01

PUB-A-280446988

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-280447263

GoogleEPSS <= 49%2023-11-01

PUB-A-280447263

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-2c7c-3mj9-8fqh

Open SourceAll remainingCRITICAL2023-11-21

Decryption of malicious PBES2 JWE objects can consume unbounded system resources

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
argo-cd-2.8 affected wolfi argo-cd-2.8
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.9 affected wolfi argo-cd-2.9
argo-cd-2.9 affected chainguard argo-cd-2.9
argo-workflows affected wolfi argo-workflows
argo-workflows affected chainguard argo-workflows
bank-vaults-fips affected chainguard bank-vaults-fips
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-1.13 affected wolfi cert-manager-1.13
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
cilium-envoy affected wolfi cilium-envoy
cilium-envoy affected chainguard cilium-envoy
cloudflared affected chainguard cloudflared
cloudflared affected wolfi cloudflared
consul-1.17 affected chainguard consul-1.17
consul-1.17-fips affected chainguard consul-1.17-fips
cosign affected chainguard cosign
cosign affected wolfi cosign
cosign-fips affected wolfi cosign-fips
cosign-fips affected chainguard cosign-fips
dex affected wolfi dex
dex affected chainguard dex
external-secrets-operator affected wolfi external-secrets-operator
external-secrets-operator affected chainguard external-secrets-operator
falco affected chainguard falco
falco affected wolfi falco
falcoctl-fips affected chainguard falcoctl-fips
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller-0 affected chainguard flux-source-controller-0
fulcio affected chainguard fulcio
fulcio affected wolfi fulcio
fulcio-fips affected chainguard fulcio-fips
github.com/go-jose/go-jose/v3 affected go
github.com/go-jose/go-jose/v3 affected Go github.com/go-jose/go-jose/v3
github.com/square/go-jose affected Go github.com/square/go-jose
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
go-jose/go-jose/v3 affected github.com github.com/go-jose/go-jose/v3
go-jose/go-jose/v3 affected github.com
go-jose/go-jose/v3 affected github.com github.com/go-jose/go-jose/v3
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
istio-pilot-discovery-1.20 affected chainguard istio-pilot-discovery-1.20
istio-pilot-discovery-1.20 affected wolfi istio-pilot-discovery-1.20
istio-pilot-discovery-fips-1.19 affected chainguard istio-pilot-discovery-fips-1.19
keda affected wolfi keda
keda affected chainguard keda
keda-2.11 affected wolfi keda-2.11
keda-2.11 affected chainguard keda-2.11
kots affected chainguard kots
kots affected wolfi kots
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kyverno affected chainguard kyverno
kyverno affected wolfi kyverno
oauth2-proxy affected chainguard oauth2-proxy
oauth2-proxy affected wolfi oauth2-proxy
rekor affected wolfi rekor
rekor affected chainguard rekor
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
sops affected chainguard sops
sops affected wolfi sops
spire-server affected wolfi spire-server
spire-server affected chainguard spire-server
spire-server-fips affected chainguard spire-server-fips
square/go-jose affected github.com
square/go-jose affected github.com github.com/square/go-jose
square/go-jose affected github.com github.com/square/go-jose
tekton-chains affected chainguard tekton-chains
tekton-chains affected wolfi tekton-chains
tekton-pipelines affected chainguard tekton-pipelines
tekton-pipelines affected wolfi tekton-pipelines
terragrunt affected wolfi terragrunt
terragrunt affected chainguard terragrunt
timestamp-authority-fips affected chainguard timestamp-authority-fips
tkn affected chainguard tkn
tkn affected wolfi tkn
traefik affected wolfi traefik
traefik affected chainguard traefik
vault-1.13 affected chainguard vault-1.13
vault-1.13 affected wolfi vault-1.13
vault-fips-1.14 affected chainguard vault-fips-1.14
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
Upstream advisory

GHSA-2c7c-3mj9-8fqh

GoogleAll remainingCRITICAL2023-11-21

Decryption of malicious PBES2 JWE objects can consume unbounded system resources

Affected products

ProductStatusVendorPackageEcosystem
go-jose/go-jose/v3 affected github.com github.com/go-jose/go-jose/v3
square/go-jose affected github.com github.com/square/go-jose
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.