Google Security Advisories · April 2024 — Google Security Advisories
398 advisories 234 CVEs 11 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2024-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 11 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2024-29748

Project ZeroExploitedCISA KEV listed2024-04-02

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2024-29748

Upstream advisory

CVE-2024-29748

Open SourceExploitedCISA KEV listedHIGH2024-04-02

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2024-29748

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-318507188

GoogleExploitedCISA KEV listedNONE2024-04-01

PUB-A-318507188

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-29745

Open SourceExploitedCISA KEV listedMEDIUM2024-04-02

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29745

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29745

Project ZeroExploitedCISA KEV listed2024-04-02

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29745

Upstream advisory

PUB-A-318507136

GoogleExploitedCISA KEV listedMEDIUM2024-04-01

PUB-A-318507136

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

RHSA-2024:1674

Open SourceExploitedVulnCheck KEV listedHIGH2024-04-04

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.16 Security update

Affected products

ProductStatusVendorPackageEcosystem
eap7-activemq-artemis affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis
eap7-activemq-artemis-cli affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-cli
eap7-activemq-artemis-commons affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-commons
eap7-activemq-artemis-core-client affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-core-client
eap7-activemq-artemis-dto affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-dto
eap7-activemq-artemis-hornetq-protocol affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-hornetq-protocol
eap7-activemq-artemis-hqclient-protocol affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-hqclient-protocol
eap7-activemq-artemis-jdbc-store affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-jdbc-store
eap7-activemq-artemis-jms-client affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-jms-client
eap7-activemq-artemis-jms-server affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-jms-server
eap7-activemq-artemis-journal affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-journal
eap7-activemq-artemis-ra affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-ra
eap7-activemq-artemis-selector affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-selector
eap7-activemq-artemis-server affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-server
eap7-activemq-artemis-service-extensions affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-service-extensions
eap7-activemq-artemis-tools affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-activemq-artemis-tools
eap7-apache-cxf affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-apache-cxf
eap7-apache-cxf-rt affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-apache-cxf-rt
eap7-apache-cxf-services affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-apache-cxf-services
eap7-apache-cxf-tools affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-apache-cxf-tools
eap7-eclipse-jgit affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-eclipse-jgit
eap7-elytron-web affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-elytron-web
eap7-hal-console affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-hal-console
eap7-hibernate affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-hibernate
eap7-hibernate-core affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-hibernate-core
eap7-hibernate-entitymanager affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-hibernate-entitymanager
eap7-hibernate-envers affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-hibernate-envers
eap7-hibernate-java8 affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-hibernate-java8
eap7-infinispan affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-infinispan
eap7-infinispan-cachestore-jdbc affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-infinispan-cachestore-jdbc
eap7-infinispan-cachestore-remote affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-infinispan-cachestore-remote
eap7-infinispan-client-hotrod affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-infinispan-client-hotrod
eap7-infinispan-commons affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-infinispan-commons
eap7-infinispan-component-annotations affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-infinispan-component-annotations
eap7-infinispan-core affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-infinispan-core
eap7-infinispan-hibernate-cache-commons affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-infinispan-hibernate-cache-commons
eap7-infinispan-hibernate-cache-spi affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-infinispan-hibernate-cache-spi
eap7-infinispan-hibernate-cache-v53 affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-infinispan-hibernate-cache-v53
eap7-insights-java-client affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-insights-java-client
eap7-jberet affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jberet
eap7-jberet-core affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jberet-core
eap7-jboss-annotations-api_1.3_spec affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jboss-annotations-api_1.3_spec
eap7-jboss-cert-helper affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jboss-cert-helper
eap7-jboss-cert-helper-debuginfo affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jboss-cert-helper-debuginfo
eap7-jboss-remoting affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jboss-remoting
eap7-jboss-server-migration affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jboss-server-migration
eap7-jboss-server-migration-cli affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jboss-server-migration-cli
eap7-jboss-server-migration-core affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jboss-server-migration-core
eap7-jboss-xnio-base affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jboss-xnio-base
eap7-jgroups-kubernetes affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-jgroups-kubernetes
eap7-lucene-analyzers-common affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-lucene-analyzers-common
eap7-lucene-backward-codecs affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-lucene-backward-codecs
eap7-lucene-core affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-lucene-core
eap7-lucene-facet affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-lucene-facet
eap7-lucene-misc affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-lucene-misc
eap7-lucene-queries affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-lucene-queries
eap7-lucene-queryparser affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-lucene-queryparser
eap7-lucene-solr affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-lucene-solr
eap7-undertow affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-undertow
eap7-undertow-server affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-undertow-server
eap7-wildfly affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-wildfly
eap7-wildfly-elytron affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-wildfly-elytron
eap7-wildfly-elytron-tool affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-wildfly-elytron-tool
eap7-wildfly-javadocs affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-wildfly-javadocs
eap7-wildfly-java-jdk11 affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-wildfly-java-jdk11
eap7-wildfly-java-jdk8 affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-wildfly-java-jdk8
eap7-wildfly-modules affected Red Hat:jboss_enterprise_application_platform:7.4::el7 eap7-wildfly-modules
Upstream advisory

RHSA-2024:1675

Open SourceExploitedVulnCheck KEV listedHIGH2024-04-04

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.16 Security update

Affected products

ProductStatusVendorPackageEcosystem
eap7-activemq-artemis affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis
eap7-activemq-artemis-cli affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-cli
eap7-activemq-artemis-commons affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-commons
eap7-activemq-artemis-core-client affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-core-client
eap7-activemq-artemis-dto affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-dto
eap7-activemq-artemis-hornetq-protocol affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-hornetq-protocol
eap7-activemq-artemis-hqclient-protocol affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-hqclient-protocol
eap7-activemq-artemis-jdbc-store affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-jdbc-store
eap7-activemq-artemis-jms-client affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-jms-client
eap7-activemq-artemis-jms-server affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-jms-server
eap7-activemq-artemis-journal affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-journal
eap7-activemq-artemis-ra affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-ra
eap7-activemq-artemis-selector affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-selector
eap7-activemq-artemis-server affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-server
eap7-activemq-artemis-service-extensions affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-service-extensions
eap7-activemq-artemis-tools affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-activemq-artemis-tools
eap7-apache-cxf affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-apache-cxf
eap7-apache-cxf-rt affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-apache-cxf-rt
eap7-apache-cxf-services affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-apache-cxf-services
eap7-apache-cxf-tools affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-apache-cxf-tools
eap7-eclipse-jgit affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-eclipse-jgit
eap7-elytron-web affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-elytron-web
eap7-hal-console affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-hal-console
eap7-hibernate affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-hibernate
eap7-hibernate-core affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-hibernate-core
eap7-hibernate-entitymanager affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-hibernate-entitymanager
eap7-hibernate-envers affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-hibernate-envers
eap7-hibernate-java8 affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-hibernate-java8
eap7-infinispan affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-infinispan
eap7-infinispan-cachestore-jdbc affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-infinispan-cachestore-jdbc
eap7-infinispan-cachestore-remote affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-infinispan-cachestore-remote
eap7-infinispan-client-hotrod affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-infinispan-client-hotrod
eap7-infinispan-commons affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-infinispan-commons
eap7-infinispan-component-annotations affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-infinispan-component-annotations
eap7-infinispan-core affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-infinispan-core
eap7-infinispan-hibernate-cache-commons affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-infinispan-hibernate-cache-commons
eap7-infinispan-hibernate-cache-spi affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-infinispan-hibernate-cache-spi
eap7-infinispan-hibernate-cache-v53 affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-infinispan-hibernate-cache-v53
eap7-insights-java-client affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-insights-java-client
eap7-jberet affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-jberet
eap7-jberet-core affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-jberet-core
eap7-jboss-annotations-api_1.3_spec affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-jboss-annotations-api_1.3_spec
eap7-jboss-cert-helper affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-jboss-cert-helper
eap7-jboss-remoting affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-jboss-remoting
eap7-jboss-server-migration affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-jboss-server-migration
eap7-jboss-server-migration-cli affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-jboss-server-migration-cli
eap7-jboss-server-migration-core affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-jboss-server-migration-core
eap7-jboss-xnio-base affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-jboss-xnio-base
eap7-jgroups-kubernetes affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-jgroups-kubernetes
eap7-lucene-analyzers-common affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-lucene-analyzers-common
eap7-lucene-backward-codecs affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-lucene-backward-codecs
eap7-lucene-core affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-lucene-core
eap7-lucene-facet affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-lucene-facet
eap7-lucene-grouping affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-lucene-grouping
eap7-lucene-misc affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-lucene-misc
eap7-lucene-queries affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-lucene-queries
eap7-lucene-queryparser affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-lucene-queryparser
eap7-lucene-solr affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-lucene-solr
eap7-undertow affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-undertow
eap7-undertow-server affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-undertow-server
eap7-wildfly affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-wildfly
eap7-wildfly-elytron affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-wildfly-elytron
eap7-wildfly-elytron-tool affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-wildfly-elytron-tool
eap7-wildfly-javadocs affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-wildfly-javadocs
eap7-wildfly-java-jdk11 affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-wildfly-java-jdk11
eap7-wildfly-java-jdk17 affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-wildfly-java-jdk17
eap7-wildfly-java-jdk8 affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-wildfly-java-jdk8
eap7-wildfly-modules affected Red Hat:jboss_enterprise_application_platform:7.4::el8 eap7-wildfly-modules
Upstream advisory

RHSA-2024:1676

Open SourceExploitedVulnCheck KEV listedHIGH2024-04-04

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.16 Security update

Affected products

ProductStatusVendorPackageEcosystem
eap7-activemq-artemis affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis
eap7-activemq-artemis-cli affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-cli
eap7-activemq-artemis-commons affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-commons
eap7-activemq-artemis-core-client affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-core-client
eap7-activemq-artemis-dto affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-dto
eap7-activemq-artemis-hornetq-protocol affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-hornetq-protocol
eap7-activemq-artemis-hqclient-protocol affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-hqclient-protocol
eap7-activemq-artemis-jdbc-store affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-jdbc-store
eap7-activemq-artemis-jms-client affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-jms-client
eap7-activemq-artemis-jms-server affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-jms-server
eap7-activemq-artemis-journal affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-journal
eap7-activemq-artemis-ra affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-ra
eap7-activemq-artemis-selector affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-selector
eap7-activemq-artemis-server affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-server
eap7-activemq-artemis-service-extensions affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-service-extensions
eap7-activemq-artemis-tools affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-activemq-artemis-tools
eap7-apache-cxf affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-apache-cxf
eap7-apache-cxf-rt affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-apache-cxf-rt
eap7-apache-cxf-services affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-apache-cxf-services
eap7-apache-cxf-tools affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-apache-cxf-tools
eap7-eclipse-jgit affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-eclipse-jgit
eap7-elytron-web affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-elytron-web
eap7-hal-console affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-hal-console
eap7-hibernate affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-hibernate
eap7-hibernate-core affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-hibernate-core
eap7-hibernate-envers affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-hibernate-envers
eap7-infinispan affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-infinispan
eap7-infinispan-cachestore-jdbc affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-infinispan-cachestore-jdbc
eap7-infinispan-cachestore-remote affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-infinispan-cachestore-remote
eap7-infinispan-client-hotrod affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-infinispan-client-hotrod
eap7-infinispan-commons affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-infinispan-commons
eap7-infinispan-component-annotations affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-infinispan-component-annotations
eap7-infinispan-core affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-infinispan-core
eap7-infinispan-hibernate-cache-commons affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-infinispan-hibernate-cache-commons
eap7-infinispan-hibernate-cache-spi affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-infinispan-hibernate-cache-spi
eap7-infinispan-hibernate-cache-v53 affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-infinispan-hibernate-cache-v53
eap7-insights-java-client affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-insights-java-client
eap7-jberet affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-jberet
eap7-jberet-core affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-jberet-core
eap7-jboss-annotations-api_1.3_spec affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-jboss-annotations-api_1.3_spec
eap7-jboss-cert-helper affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-jboss-cert-helper
eap7-jboss-remoting affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-jboss-remoting
eap7-jboss-server-migration affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-jboss-server-migration
eap7-jboss-server-migration-cli affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-jboss-server-migration-cli
eap7-jboss-server-migration-core affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-jboss-server-migration-core
eap7-jboss-xnio-base affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-jboss-xnio-base
eap7-jgroups-kubernetes affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-jgroups-kubernetes
eap7-lucene-analyzers-common affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-lucene-analyzers-common
eap7-lucene-backward-codecs affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-lucene-backward-codecs
eap7-lucene-core affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-lucene-core
eap7-lucene-facet affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-lucene-facet
eap7-lucene-misc affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-lucene-misc
eap7-lucene-queries affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-lucene-queries
eap7-lucene-queryparser affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-lucene-queryparser
eap7-lucene-solr affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-lucene-solr
eap7-undertow affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-undertow
eap7-undertow-server affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-undertow-server
eap7-wildfly affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-wildfly
eap7-wildfly-elytron affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-wildfly-elytron
eap7-wildfly-elytron-tool affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-wildfly-elytron-tool
eap7-wildfly-javadocs affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-wildfly-javadocs
eap7-wildfly-java-jdk11 affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-wildfly-java-jdk11
eap7-wildfly-java-jdk17 affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-wildfly-java-jdk17
eap7-wildfly-java-jdk8 affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-wildfly-java-jdk8
eap7-wildfly-modules affected Red Hat:jboss_enterprise_application_platform:7.4::el9 eap7-wildfly-modules
Upstream advisory

SUSE-SU-2024:1427-1

Open SourceWeaponized exploitHIGH2024-04-24

Security Beta update for SUSE Manager Client Tools and Salt

Affected products

ProductStatusVendorPackageEcosystem
ansible affected SUSE:Manager Client Tools 15-BETA ansible
dracut-saltboot affected SUSE:Manager Client Tools 15-BETA dracut-saltboot
golang-github-prometheus-node_exporter affected SUSE:Manager Client Tools Beta for SLE Micro 5 golang-github-prometheus-node_exporter
grafana affected SUSE:Manager Client Tools 15-BETA grafana
POS_Image-Graphical7 affected SUSE:Manager Client Tools 15-BETA POS_Image-Graphical7
POS_Image-JeOS7 affected SUSE:Manager Client Tools 15-BETA POS_Image-JeOS7
spacecmd affected SUSE:Manager Client Tools 15-BETA spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 15-BETA spacewalk-client-tools
supportutils-plugin-susemanager-client affected SUSE:Manager Client Tools 15-BETA supportutils-plugin-susemanager-client
uyuni-tools affected SUSE:Manager Client Tools 15-BETA uyuni-tools
uyuni-tools affected SUSE:Manager Client Tools Beta for SLE Micro 5 uyuni-tools
Upstream advisory

MGASA-2024-0150

Open SourceActive exploitation (sightings)CRITICAL2024-04-27

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

DSA-5668-1

Open SourceActive exploitation (sightings)2024-04-20

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

GHSA-jfh3-f27x-p9gp

Open SourceActive exploitation (sightings)HIGH2024-04-17

GHSA-jfh3-f27x-p9gp

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-3833

Open SourceActive exploitation (sightings)HIGH2024-04-17

DEBIAN-CVE-2024-3833

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3833

GoogleActive exploitation (sightings)HIGH2024-04-16

Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3833

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-g47c-q844-rxj3

Open SourceActive exploitation (sightings)HIGH2024-04-06

GHSA-g47c-q844-rxj3

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3156

Open SourceActive exploitation (sightings)HIGH2024-04-06

DEBIAN-CVE-2024-3156

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

MGASA-2024-0109

Open SourceActive exploitation (sightings)CRITICAL2024-04-05

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

DSA-5654-1

Open SourceActive exploitation (sightings)2024-04-03

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

CVE-2024-3156

GoogleActive exploitation (sightings)HIGH2024-04-02

Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3156

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-3156

GoogleActive exploitation (sightings)2024-04-02

Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3156

Upstream advisory

DSA-5675-1

Open SourceActive exploitation (sightings)2024-04-26

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

CVE-2024-4058

GoogleActive exploitation (sightings)2024-04-24

Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2024-4058

Upstream advisory

CVE-2024-4058

GoogleActive exploitation (sightings)CRITICAL2024-04-24

Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2024-4058

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-3566

GoogleActive exploitation (sightings)CRITICAL2024-04-10

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

CVEs:CVE-2024-3566

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
go affected golang
node.js affected nodejs
php affected php
process affected haskell
process_library affected haskell
rust affected rust-lang
yt-dlp affected yt-dlp_project
Upstream advisory

CVE-2024-3566

GoogleActive exploitation (sightings)2024-04-10

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

CVEs:CVE-2024-3566

Upstream advisory

GHSA-qqpr-fvmc-87j3

Open SourceActive exploitation (sightings)HIGH2024-04-17

GHSA-qqpr-fvmc-87j3

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-3832

Open SourceActive exploitation (sightings)HIGH2024-04-17

DEBIAN-CVE-2024-3832

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3832

GoogleActive exploitation (sightings)HIGH2024-04-16

Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3832

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-3832

GoogleActive exploitation (sightings)2024-04-16

Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3832

Upstream advisory

SUSE-SU-2024:1419-1

Open SourceActive exploitation (sightings)HIGH2024-04-24

Security Beta update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-alertmanager affected SUSE:Manager Client Tools 12-BETA golang-github-prometheus-alertmanager
golang-github-prometheus-node_exporter affected SUSE:Manager Client Tools 12-BETA golang-github-prometheus-node_exporter
golang-github-prometheus-promu affected SUSE:Manager Client Tools 12-BETA golang-github-prometheus-promu
grafana affected SUSE:Manager Client Tools 12-BETA grafana
spacecmd affected SUSE:Manager Client Tools 12-BETA spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 12-BETA spacewalk-client-tools
supportutils-plugin-susemanager-client affected SUSE:Manager Client Tools 12-BETA supportutils-plugin-susemanager-client
uyuni-tools affected SUSE:Manager Client Tools 12-BETA uyuni-tools
Upstream advisory

DSA-5656-1

Open SourceActive exploitation (sightings)2024-04-11

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

GHSA-jf9g-42gm-v87w

Open SourceActive exploitation (sightings)CRITICAL2024-04-10

GHSA-jf9g-42gm-v87w

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-3516

Open SourceActive exploitation (sightings)CRITICAL2024-04-10

DEBIAN-CVE-2024-3516

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3516

GoogleActive exploitation (sightings)2024-04-10

Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3516

Upstream advisory

CVE-2024-3516

GoogleActive exploitation (sightings)CRITICAL2024-04-10

Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3516

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-jv87-hfr8-8j2r

Open SourceActive exploitation (sightings)CRITICAL2024-04-17

GHSA-jv87-hfr8-8j2r

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3914

Open SourceActive exploitation (sightings)CRITICAL2024-04-17

DEBIAN-CVE-2024-3914

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3914

GoogleActive exploitation (sightings)CRITICAL2024-04-16

Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3914

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-3914

GoogleActive exploitation (sightings)2024-04-16

Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3914

Upstream advisory

GHSA-4m4g-p795-cmq7

Open SourceActive exploitation (sightings)HIGH2024-04-10

GHSA-4m4g-p795-cmq7

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3157

Open SourceActive exploitation (sightings)CRITICAL2024-04-10

DEBIAN-CVE-2024-3157

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3157

GoogleActive exploitation (sightings)2024-04-10

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)

CVEs:CVE-2024-3157

Upstream advisory

CVE-2024-3157

GoogleActive exploitation (sightings)CRITICAL2024-04-10

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)

CVEs:CVE-2024-3157

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-x6cj-gx36-vcxv

Open SourceActive exploitation (sightings)CRITICAL2024-04-10

GHSA-x6cj-gx36-vcxv

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3515

Open SourceActive exploitation (sightings)CRITICAL2024-04-10

DEBIAN-CVE-2024-3515

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3515

GoogleActive exploitation (sightings)2024-04-10

Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3515

Upstream advisory

CVE-2024-3515

GoogleActive exploitation (sightings)CRITICAL2024-04-10

Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3515

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-r9g8-4h9q-3jfp

Open SourceActive exploitation (sightings)CRITICAL2024-04-06

GHSA-r9g8-4h9q-3jfp

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3158

Open SourceActive exploitation (sightings)CRITICAL2024-04-06

DEBIAN-CVE-2024-3158

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3158

GoogleActive exploitation (sightings)CRITICAL2024-04-02

Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3158

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-3158

GoogleActive exploitation (sightings)2024-04-02

Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3158

Upstream advisory

GHSA-m9w6-wp3h-vq8g

GoogleActive exploitation (sightings)MEDIUM2024-04-25

CoreDNS may return invalid cache entries

Affected products

ProductStatusVendorPackageEcosystem
coredns/coredns affected github.com github.com/coredns/coredns
Upstream advisory

GHSA-m9w6-wp3h-vq8g

Open SourceActive exploitation (sightings)MEDIUM2024-04-25

CoreDNS may return invalid cache entries

Affected products

ProductStatusVendorPackageEcosystem
cloudflared affected chainguard cloudflared
cloudflared affected wolfi cloudflared
consul-1.15 affected chainguard consul-1.15
consul-1.15 affected wolfi consul-1.15
consul-1.16 affected chainguard consul-1.16
consul-1.16 affected wolfi consul-1.16
consul-1.17 affected chainguard consul-1.17
consul-1.17-fips affected chainguard consul-1.17-fips
coredns affected chainguard coredns
coredns affected wolfi coredns
coredns/coredns affected github.com github.com/coredns/coredns
coredns-fips affected chainguard coredns-fips
juicefs-1.2 affected chainguard juicefs-1.2
juicefs-1.3 affected chainguard juicefs-1.3
juicefs-1.3 affected wolfi juicefs-1.3
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
Upstream advisory

SUSE-SU-2024:1166-1

Open SourceActive exploitation (sightings)HIGH2024-04-08

Security update for kubernetes1.23

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.26 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.26
kubernetes1.26 affected openSUSE:Leap 15.5 kubernetes1.26
Upstream advisory

SUSE-SU-2024:1165-1

Open SourceActive exploitation (sightings)HIGH2024-04-08

Security update for kubernetes1.23

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.25 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.25
kubernetes1.25 affected openSUSE:Leap 15.5 kubernetes1.25
Upstream advisory

SUSE-SU-2024:1164-1

Open SourceActive exploitation (sightings)HIGH2024-04-08

Security update for kubernetes1.23

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.24 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.24
kubernetes1.24 affected openSUSE:Leap 15.5 kubernetes1.24
Upstream advisory

SUSE-SU-2024:1163-1

Open SourceActive exploitation (sightings)HIGH2024-04-08

Security update for kubernetes1.23

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.23 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.23
kubernetes1.23 affected openSUSE:Leap 15.5 kubernetes1.23
Upstream advisory

GHSA-fff2-pwcg-x73m

Open SourceActive exploitation (sightings)MEDIUM2024-04-17

GHSA-fff2-pwcg-x73m

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3838

Open SourceActive exploitation (sightings)MEDIUM2024-04-17

DEBIAN-CVE-2024-3838

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3838

GoogleActive exploitation (sightings)2024-04-16

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium)

CVEs:CVE-2024-3838

Upstream advisory

CVE-2024-3838

GoogleActive exploitation (sightings)MEDIUM2024-04-16

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium)

CVEs:CVE-2024-3838

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-hw42-3568-wj87

GoogleActive exploitation (sightings)HIGH2024-04-09

google-oauth-java-client improperly verifies cryptographic signature

Affected products

ProductStatusVendorPackageEcosystem
com.google.oauth-client:google-oauth-client affected Maven com.google.oauth-client:google-oauth-client
Upstream advisory

GHSA-hw42-3568-wj87

GoogleActive exploitation (sightings)HIGH2024-04-09

google-oauth-java-client improperly verifies cryptographic signature

Affected products

ProductStatusVendorPackageEcosystem
com.google.oauth-client:google-oauth-client affected Maven com.google.oauth-client:google-oauth-client
Upstream advisory

GHSA-xh97-72ww-2w58

GoogleActive exploitation (sightings)HIGH2024-04-09

Duplicate Advisory: Improper Verification of Cryptographic Signature in google-oauth-java-client

Affected products

ProductStatusVendorPackageEcosystem
com.google.oauth-client:google-oauth-client affected Maven com.google.oauth-client:google-oauth-client
Upstream advisory

GHSA-xh97-72ww-2w58

GoogleActive exploitation (sightings)HIGH2024-04-09

Duplicate Advisory: Improper Verification of Cryptographic Signature in google-oauth-java-client

Affected products

ProductStatusVendorPackageEcosystem
com.google.oauth-client:google-oauth-client affected Maven com.google.oauth-client:google-oauth-client
Upstream advisory

CVE-2024-20844

Open SourceActive exploitation (sightings)HIGH2024-04-01

Out-of-bounds write vulnerability while parsing remaining codewords in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2024-20844

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20842

Open SourceActive exploitation (sightings)MEDIUM2024-04-01

Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVEs:CVE-2024-20842

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20048

Open SourceActive exploitation (sightings)MEDIUM2024-04-01

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541769; Issue ...

CVEs:CVE-2024-20048

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29743

Open SourceActive exploitation (sightings)HIGH2024-04-02

In tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29743

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-315322962

GoogleActive exploitation (sightings)HIGH2024-04-01

PUB-A-315322962

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20045

Open SourceActive exploitation (sightings)MEDIUM2024-04-01

In audio, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS080...

CVEs:CVE-2024-20045

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-52349

Open SourceActive exploitation (sightings)CRITICAL2024-04-08

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-52349

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-52352

Open SourceActive exploitation (sightings)HIGH2024-04-08

In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-52352

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

RHSA-2024:2562

Open SourcePoC exploitHIGH2024-04-30

Red Hat Security Advisory: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:9::appstream golang
golang-bin affected Red Hat:enterprise_linux:9::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:9::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:9::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:9::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:9::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:9::appstream go-toolset
Upstream advisory

ALSA-2024:2562

Open SourcePoC exploitHIGH2024-04-30

Important: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected AlmaLinux:9 golang
golang-bin affected AlmaLinux:9 golang-bin
golang-docs affected AlmaLinux:9 golang-docs
golang-misc affected AlmaLinux:9 golang-misc
golang-src affected AlmaLinux:9 golang-src
golang-tests affected AlmaLinux:9 golang-tests
go-toolset affected AlmaLinux:9 go-toolset
Upstream advisory

ALSA-2024:1962

Open SourcePoC exploitHIGH2024-04-23

Important: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected AlmaLinux:8 delve
golang affected AlmaLinux:8 golang
golang-bin affected AlmaLinux:8 golang-bin
golang-docs affected AlmaLinux:8 golang-docs
golang-misc affected AlmaLinux:8 golang-misc
golang-src affected AlmaLinux:8 golang-src
golang-tests affected AlmaLinux:8 golang-tests
go-toolset affected AlmaLinux:8 go-toolset
Upstream advisory

ALSA-2024:1963

Open SourcePoC exploitHIGH2024-04-23

Important: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected AlmaLinux:9 golang
golang-bin affected AlmaLinux:9 golang-bin
golang-docs affected AlmaLinux:9 golang-docs
golang-misc affected AlmaLinux:9 golang-misc
golang-src affected AlmaLinux:9 golang-src
golang-tests affected AlmaLinux:9 golang-tests
go-toolset affected AlmaLinux:9 go-toolset
Upstream advisory

OESA-2024-1488

Open SourcePoC exploitHIGH2024-04-19

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP4 golang
golang affected openEuler:22.03-LTS golang
golang affected openEuler:22.03-LTS-SP1 golang
golang affected openEuler:22.03-LTS-SP2 golang
golang affected openEuler:22.03-LTS-SP3 golang
Upstream advisory

MGASA-2024-0128

Open SourcePoC exploitHIGH2024-04-13

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:9 golang
Upstream advisory

BIT-golang-2023-45288

Open SourcePoC exploitHIGH2024-04-06

HTTP/2 CONTINUATION flood in net/http

Affected products

ProductStatusVendorPackageEcosystem
golang affected Bitnami golang
Upstream advisory

GHSA-4v7x-pqxf-cx7m

Open SourcePoC exploitHIGH2024-04-04

net/http, x/net/http2: close connections when receiving too many headers

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
actions-runner-controller affected wolfi actions-runner-controller
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller-fips affected chainguard actions-runner-controller-fips
addon-resizer affected chainguard addon-resizer
addon-resizer affected wolfi addon-resizer
addon-resizer-fips affected chainguard addon-resizer-fips
amass affected wolfi amass
amass affected chainguard amass
apko affected wolfi apko
apko affected chainguard apko
argo-cd-2.10 affected wolfi argo-cd-2.10
argo-cd-2.10 affected chainguard argo-cd-2.10
argo-cd-2.8 affected wolfi argo-cd-2.8
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.9 affected wolfi argo-cd-2.9
argo-cd-2.9 affected chainguard argo-cd-2.9
argo-cd-fips-2.10 affected chainguard argo-cd-fips-2.10
argo-cd-fips-2.8 affected chainguard argo-cd-fips-2.8
argo-cd-fips-2.9 affected chainguard argo-cd-fips-2.9
argo-workflows affected wolfi argo-workflows
argo-workflows affected chainguard argo-workflows
argo-workflows-fips affected chainguard argo-workflows-fips
atlantis affected wolfi atlantis
atlantis affected chainguard atlantis
atlantis-fips affected chainguard atlantis-fips
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
aws-ebs-csi-driver-fips affected chainguard aws-ebs-csi-driver-fips
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-efs-csi-driver-fips-1.6 affected chainguard aws-efs-csi-driver-fips-1.6
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller-2.4.5 affected chainguard aws-load-balancer-controller-2.4.5
aws-load-balancer-controller-2.5 affected chainguard aws-load-balancer-controller-2.5
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
aws-network-policy-agent affected wolfi aws-network-policy-agent
aws-network-policy-agent affected chainguard aws-network-policy-agent
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bazelisk affected chainguard bazelisk
bazelisk affected wolfi bazelisk
bincapz affected chainguard bincapz
bincapz affected wolfi bincapz
bom affected wolfi bom
bom affected chainguard bom
boring-registry affected chainguard boring-registry
boring-registry affected wolfi boring-registry
boring-registry-fips affected chainguard boring-registry-fips
buf affected wolfi buf
buf affected chainguard buf
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
caddy affected wolfi caddy
caddy affected chainguard caddy
caddy-fips affected chainguard caddy-fips
cadvisor affected wolfi cadvisor
cadvisor affected chainguard cadvisor
cadvisor-fips affected chainguard cadvisor-fips
calico affected chainguard calico
calico affected wolfi calico
calico-fips affected chainguard calico-fips
calico-fips-3.25 affected chainguard calico-fips-3.25
capslock affected chainguard capslock
capslock affected wolfi capslock
cass-operator affected wolfi cass-operator
cass-operator affected chainguard cass-operator
cass-operator-fips affected chainguard cass-operator-fips
cass-operator-fips-no-pvc-delete affected chainguard cass-operator-fips-no-pvc-delete
cert-exporter affected chainguard cert-exporter
cert-exporter affected wolfi cert-exporter
cert-exporter-fips affected chainguard cert-exporter-fips
certificate-transparency affected wolfi certificate-transparency
certificate-transparency affected chainguard certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.13 affected wolfi cert-manager-1.13
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-1.14 affected wolfi cert-manager-1.14
cert-manager-1.14 affected chainguard cert-manager-1.14
cert-manager-fips-1.12 affected chainguard cert-manager-fips-1.12
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
cert-manager-fips-1.14 affected chainguard cert-manager-fips-1.14
cert-manager-webhook-pdns affected wolfi cert-manager-webhook-pdns
cert-manager-webhook-pdns affected chainguard cert-manager-webhook-pdns
cert-manager-webhook-pdns-fips affected chainguard cert-manager-webhook-pdns-fips
cfssl affected chainguard cfssl
cfssl affected wolfi cfssl
chainctl affected chainguard chainctl
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
chezmoi affected wolfi chezmoi
chezmoi affected chainguard chezmoi
cilium-1.14 affected chainguard cilium-1.14
cilium-1.14 affected wolfi cilium-1.14
cilium-1.15 affected chainguard cilium-1.15
cilium-1.15 affected wolfi cilium-1.15
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
cilium-fips-1.14 affected chainguard cilium-fips-1.14
cilium-fips-1.15 affected chainguard cilium-fips-1.15
cloudflared affected wolfi cloudflared
cloudflared affected chainguard cloudflared
cloud-provider-gcp-cloud-controller-manager affected wolfi cloud-provider-gcp-cloud-controller-manager
cloud-provider-gcp-cloud-controller-manager affected chainguard cloud-provider-gcp-cloud-controller-manager
cloud-provider-gcp-cloud-controller-manager-fips affected chainguard cloud-provider-gcp-cloud-controller-manager-fips
cloud-sql-proxy affected wolfi cloud-sql-proxy
cloud-sql-proxy affected chainguard cloud-sql-proxy
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
cluster-api-controller affected chainguard cluster-api-controller
cluster-api-controller affected wolfi cluster-api-controller
cluster-autoscaler-1.25 affected wolfi cluster-autoscaler-1.25
cluster-autoscaler-1.25 affected chainguard cluster-autoscaler-1.25
cluster-autoscaler-1.26 affected wolfi cluster-autoscaler-1.26
cluster-autoscaler-1.26 affected chainguard cluster-autoscaler-1.26
cluster-autoscaler-1.27 affected chainguard cluster-autoscaler-1.27
cluster-autoscaler-1.27 affected wolfi cluster-autoscaler-1.27
cluster-autoscaler-1.28 affected wolfi cluster-autoscaler-1.28
cluster-autoscaler-1.28 affected chainguard cluster-autoscaler-1.28
cluster-autoscaler-1.29 affected wolfi cluster-autoscaler-1.29
cluster-autoscaler-1.29 affected chainguard cluster-autoscaler-1.29
cluster-autoscaler-fips-1.26 affected chainguard cluster-autoscaler-fips-1.26
cluster-autoscaler-fips-1.27 affected chainguard cluster-autoscaler-fips-1.27
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
cluster-autoscaler-fips-1.29 affected chainguard cluster-autoscaler-fips-1.29
clusterctl affected wolfi clusterctl
clusterctl affected chainguard clusterctl
cluster-proportional-autoscaler affected wolfi cluster-proportional-autoscaler
cluster-proportional-autoscaler affected chainguard cluster-proportional-autoscaler
cni-plugins affected chainguard cni-plugins
cni-plugins affected wolfi cni-plugins
configmap-reload affected chainguard configmap-reload
configmap-reload affected wolfi configmap-reload
confluent-common-docker affected chainguard confluent-common-docker
confluent-common-docker affected wolfi confluent-common-docker
conftest affected chainguard conftest
conftest affected wolfi conftest
conftest-fips affected chainguard conftest-fips
consul-1.15 affected chainguard consul-1.15
consul-1.15 affected wolfi consul-1.15
consul-1.16 affected wolfi consul-1.16
consul-1.16 affected chainguard consul-1.16
consul-1.17 affected chainguard consul-1.17
consul-1.17-fips affected chainguard consul-1.17-fips
containerd affected chainguard containerd
containerd affected wolfi containerd
contour-1.28 affected chainguard contour-1.28
contour-1.28 affected wolfi contour-1.28
controller-gen affected chainguard controller-gen
controller-gen affected wolfi controller-gen
coredns affected wolfi coredns
coredns affected chainguard coredns
coredns-fips affected chainguard coredns-fips
cortex affected wolfi cortex
cortex affected chainguard cortex
cortex-fips affected chainguard cortex-fips
cosign affected wolfi cosign
cosign affected chainguard cosign
cosign-fips affected chainguard cosign-fips
cosign-fips affected wolfi cosign-fips
crane affected wolfi crane
crane affected chainguard crane
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
croc affected wolfi croc
croc affected chainguard croc
crossplane affected wolfi crossplane
crossplane affected chainguard crossplane
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-aws-cloudformation affected wolfi crossplane-provider-aws-cloudformation
crossplane-provider-aws-cloudformation affected chainguard crossplane-provider-aws-cloudformation
crossplane-provider-aws-cloudfront affected wolfi crossplane-provider-aws-cloudfront
crossplane-provider-aws-cloudfront affected chainguard crossplane-provider-aws-cloudfront
crossplane-provider-aws-cloudwatchlogs affected wolfi crossplane-provider-aws-cloudwatchlogs
crossplane-provider-aws-cloudwatchlogs affected chainguard crossplane-provider-aws-cloudwatchlogs
crossplane-provider-aws-dynamodb affected wolfi crossplane-provider-aws-dynamodb
crossplane-provider-aws-dynamodb affected chainguard crossplane-provider-aws-dynamodb
crossplane-provider-aws-ec2 affected chainguard crossplane-provider-aws-ec2
crossplane-provider-aws-ec2 affected wolfi crossplane-provider-aws-ec2
crossplane-provider-aws-eks affected wolfi crossplane-provider-aws-eks
crossplane-provider-aws-eks affected chainguard crossplane-provider-aws-eks
crossplane-provider-aws-elasticache affected wolfi crossplane-provider-aws-elasticache
crossplane-provider-aws-elasticache affected chainguard crossplane-provider-aws-elasticache
crossplane-provider-aws-firehose affected chainguard crossplane-provider-aws-firehose
crossplane-provider-aws-firehose affected wolfi crossplane-provider-aws-firehose
crossplane-provider-aws-iam affected chainguard crossplane-provider-aws-iam
crossplane-provider-aws-iam affected wolfi crossplane-provider-aws-iam
crossplane-provider-aws-kinesis affected wolfi crossplane-provider-aws-kinesis
crossplane-provider-aws-kinesis affected chainguard crossplane-provider-aws-kinesis
crossplane-provider-aws-kms affected chainguard crossplane-provider-aws-kms
crossplane-provider-aws-kms affected wolfi crossplane-provider-aws-kms
crossplane-provider-aws-lambda affected wolfi crossplane-provider-aws-lambda
crossplane-provider-aws-lambda affected chainguard crossplane-provider-aws-lambda
crossplane-provider-aws-memorydb affected chainguard crossplane-provider-aws-memorydb
crossplane-provider-aws-memorydb affected wolfi crossplane-provider-aws-memorydb
crossplane-provider-aws-rds affected chainguard crossplane-provider-aws-rds
crossplane-provider-aws-rds affected wolfi crossplane-provider-aws-rds
crossplane-provider-aws-route53 affected chainguard crossplane-provider-aws-route53
crossplane-provider-aws-route53 affected wolfi crossplane-provider-aws-route53
crossplane-provider-aws-s3 affected wolfi crossplane-provider-aws-s3
crossplane-provider-aws-s3 affected chainguard crossplane-provider-aws-s3
crossplane-provider-aws-sns affected wolfi crossplane-provider-aws-sns
crossplane-provider-aws-sns affected chainguard crossplane-provider-aws-sns
crossplane-provider-aws-sqs affected chainguard crossplane-provider-aws-sqs
crossplane-provider-aws-sqs affected wolfi crossplane-provider-aws-sqs
crossplane-provider-azure affected wolfi crossplane-provider-azure
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure-authorization affected wolfi crossplane-provider-azure-authorization
crossplane-provider-azure-authorization affected chainguard crossplane-provider-azure-authorization
crossplane-provider-azure-managedidentity affected wolfi crossplane-provider-azure-managedidentity
crossplane-provider-azure-managedidentity affected chainguard crossplane-provider-azure-managedidentity
crossplane-provider-azure-sql affected chainguard crossplane-provider-azure-sql
crossplane-provider-azure-sql affected wolfi crossplane-provider-azure-sql
crossplane-provider-azure-storage affected chainguard crossplane-provider-azure-storage
crossplane-provider-azure-storage affected wolfi crossplane-provider-azure-storage
crossplane-provider-family-aws affected wolfi crossplane-provider-family-aws
crossplane-provider-family-aws affected chainguard crossplane-provider-family-aws
crossplane-provider-family-azure affected chainguard crossplane-provider-family-azure
crossplane-provider-family-azure affected wolfi crossplane-provider-family-azure
crossplane-provider-gcp affected wolfi crossplane-provider-gcp
crossplane-provider-gcp affected chainguard crossplane-provider-gcp
cue affected chainguard cue
cue affected wolfi cue
cue-fips affected chainguard cue-fips
dagdotdev affected wolfi dagdotdev
dagdotdev affected chainguard dagdotdev
dask-gateway affected chainguard dask-gateway
dask-gateway affected wolfi dask-gateway
datadog-agent affected wolfi datadog-agent
datadog-agent affected chainguard datadog-agent
datadog-agent-fips affected chainguard datadog-agent-fips
dataplaneapi affected wolfi dataplaneapi
dataplaneapi affected chainguard dataplaneapi
delve affected wolfi delve
delve affected chainguard delve
dex affected wolfi dex
dex affected chainguard dex
dex-fips affected chainguard dex-fips
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
direnv affected chainguard direnv
direnv affected wolfi direnv
dive affected wolfi dive
dive affected chainguard dive
docker-cli affected wolfi docker-cli
docker-cli affected chainguard docker-cli
docker-compose affected chainguard docker-compose
docker-compose affected wolfi docker-compose
docker-credential-acr-env affected chainguard docker-credential-acr-env
docker-credential-acr-env affected wolfi docker-credential-acr-env
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-gcr affected chainguard docker-credential-gcr
docker-credential-gcr affected wolfi docker-credential-gcr
dockerize affected wolfi dockerize
dockerize affected chainguard dockerize
dockerize-fips affected chainguard dockerize-fips
doppler-kubernetes-operator affected chainguard doppler-kubernetes-operator
doppler-kubernetes-operator affected wolfi doppler-kubernetes-operator
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
envoy-ratelimit affected wolfi envoy-ratelimit
envoy-ratelimit affected chainguard envoy-ratelimit
envoy-ratelimit-fips affected chainguard envoy-ratelimit-fips
esbuild affected wolfi esbuild
esbuild affected chainguard esbuild
etcd-3.4 affected chainguard etcd-3.4
etcd-3.5 affected chainguard etcd-3.5
etcd-3.5 affected wolfi etcd-3.5
etcd-fips-3.4 affected chainguard etcd-fips-3.4
etcd-fips-3.5 affected chainguard etcd-fips-3.5
external-dns affected chainguard external-dns
external-dns affected wolfi external-dns
external-dns-fips affected chainguard external-dns-fips
external-secrets-0.7 affected chainguard external-secrets-0.7
external-secrets-fips affected chainguard external-secrets-fips
external-secrets-operator affected chainguard external-secrets-operator
external-secrets-operator affected wolfi external-secrets-operator
falco affected wolfi falco
falco affected chainguard falco
falcoctl affected wolfi falcoctl
falcoctl affected chainguard falcoctl
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
falcosidekick affected wolfi falcosidekick
falcosidekick affected chainguard falcosidekick
falcosidekick-fips affected chainguard falcosidekick-fips
ferretdb affected wolfi ferretdb
ferretdb affected chainguard ferretdb
filebeat affected wolfi filebeat
filebeat affected chainguard filebeat
filebeat-fips affected chainguard filebeat-fips
flannel affected wolfi flannel
flannel affected chainguard flannel
flannel-cni-plugin affected wolfi flannel-cni-plugin
flannel-cni-plugin affected chainguard flannel-cni-plugin
flux affected wolfi flux
flux affected chainguard flux
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
flyte affected wolfi flyte
flyte affected chainguard flyte
fq affected chainguard fq
fq affected wolfi fq
frp affected chainguard frp
frp affected wolfi frp
fulcio affected wolfi fulcio
fulcio affected chainguard fulcio
fulcio-fips affected chainguard fulcio-fips
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
gatekeeper-3.13 affected chainguard gatekeeper-3.13
gatekeeper-3.13 affected wolfi gatekeeper-3.13
gatekeeper-3.14 affected wolfi gatekeeper-3.14
gatekeeper-3.14 affected chainguard gatekeeper-3.14
gatekeeper-fips-3.13 affected chainguard gatekeeper-fips-3.13
gatekeeper-fips-3.14 affected chainguard gatekeeper-fips-3.14
gatekeeper-fips-3.15 affected chainguard gatekeeper-fips-3.15
gcsfuse affected chainguard gcsfuse
gcsfuse affected wolfi gcsfuse
gh affected chainguard gh
gh affected wolfi gh
ghaudit affected chainguard ghaudit
ghaudit affected wolfi ghaudit
gitlab-kas affected wolfi gitlab-kas
gitlab-kas affected chainguard gitlab-kas
gitlab-pages affected chainguard gitlab-pages
gitlab-pages affected wolfi gitlab-pages
gitlab-rails-ee-17.3 affected chainguard gitlab-rails-ee-17.3
gitlab-rails-ee-fips-17.2 affected chainguard gitlab-rails-ee-fips-17.2
gitlab-runner affected chainguard gitlab-runner
gitlab-runner affected wolfi gitlab-runner
gitleaks affected wolfi gitleaks
gitleaks affected chainguard gitleaks
git-lfs affected chainguard git-lfs
git-lfs affected wolfi git-lfs
gitness affected wolfi gitness
gitness affected chainguard gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
glab affected chainguard glab
glab affected wolfi glab
go-1.20 affected wolfi go-1.20
go-1.20 affected chainguard go-1.20
go-1.21 affected wolfi go-1.21
go-1.21 affected chainguard go-1.21
go-1.22 affected chainguard go-1.22
go-1.22 affected wolfi go-1.22
go-bindata affected chainguard go-bindata
go-bindata affected wolfi go-bindata
gobump affected wolfi gobump
gobump affected chainguard gobump
gobuster affected wolfi gobuster
gobuster affected chainguard gobuster
go-fips-1.21 affected chainguard go-fips-1.21
go-fips-1.21 affected wolfi go-fips-1.21
go-ipfs-fips affected chainguard go-ipfs-fips
golangci-lint affected wolfi golangci-lint
golangci-lint affected chainguard golangci-lint
go-licenses affected wolfi go-licenses
go-licenses affected chainguard go-licenses
go-md2man affected chainguard go-md2man
go-md2man affected wolfi go-md2man
gomplate affected wolfi gomplate
gomplate affected chainguard gomplate
goreleaser affected wolfi goreleaser
goreleaser affected chainguard goreleaser
goreleaser-1.18 affected chainguard goreleaser-1.18
goreleaser-1.18 affected wolfi goreleaser-1.18
gostatsd affected wolfi gostatsd
gostatsd affected chainguard gostatsd
gosu affected chainguard gosu
gosu affected wolfi gosu
gotenberg affected chainguard gotenberg
govulncheck affected wolfi govulncheck
govulncheck affected chainguard govulncheck
gptscript affected wolfi gptscript
gptscript affected chainguard gptscript
gpu-operator affected chainguard gpu-operator
grafana-10.3 affected chainguard grafana-10.3
grafana-10.4 affected chainguard grafana-10.4
grafana-10.4 affected wolfi grafana-10.4
grafana-8 affected chainguard grafana-8
grafana-9 affected chainguard grafana-9
grafana-9-fips affected chainguard grafana-9-fips
grafana-agent-operator affected chainguard grafana-agent-operator
grafana-agent-operator affected wolfi grafana-agent-operator
grafana-fips-10.3 affected chainguard grafana-fips-10.3
grafana-fips-10.4 affected chainguard grafana-fips-10.4
grafana-operator affected chainguard grafana-operator
grafana-operator affected wolfi grafana-operator
grafana-operator-fips affected chainguard grafana-operator-fips
grpc-health-probe affected wolfi grpc-health-probe
grpc-health-probe affected chainguard grpc-health-probe
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
guac affected chainguard guac
guac affected wolfi guac
haproxy-ingress affected wolfi haproxy-ingress
haproxy-ingress affected chainguard haproxy-ingress
harbor-2.10 affected wolfi harbor-2.10
harbor-2.10 affected chainguard harbor-2.10
harbor-2.8 affected chainguard harbor-2.8
harbor-2.9 affected chainguard harbor-2.9
harbor-cli affected chainguard harbor-cli
harbor-cli affected wolfi harbor-cli
harbor-fips-2.10 affected chainguard harbor-fips-2.10
harbor-fips-2.8 affected chainguard harbor-fips-2.8
harbor-fips-2.9 affected chainguard harbor-fips-2.9
harbor-registry affected chainguard harbor-registry
harbor-registry affected wolfi harbor-registry
harbor-registry-fips affected chainguard harbor-registry-fips
harbor-scanner-trivy affected chainguard harbor-scanner-trivy
harbor-scanner-trivy affected wolfi harbor-scanner-trivy
harbor-scanner-trivy-fips affected chainguard harbor-scanner-trivy-fips
hcloud affected wolfi hcloud
hcloud affected chainguard hcloud
hello-world-golang affected chainguard hello-world-golang
hello-world-golang affected wolfi hello-world-golang
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected chainguard helm-operator
helm-operator affected wolfi helm-operator
helm-operator-fips affected chainguard helm-operator-fips
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
hey affected wolfi hey
hey affected chainguard hey
http affected net net/http
http-echo affected chainguard http-echo
http-echo affected wolfi http-echo
hubble affected chainguard hubble
hubble affected wolfi hubble
hubble-fips affected chainguard hubble-fips
hubble-ui affected chainguard hubble-ui
hubble-ui affected wolfi hubble-ui
hubble-ui-backend affected chainguard hubble-ui-backend
hubble-ui-backend-fips affected chainguard hubble-ui-backend-fips
hugo affected chainguard hugo
hugo affected wolfi hugo
hugo-extended affected wolfi hugo-extended
hugo-extended affected chainguard hugo-extended
influx affected wolfi influx
influx affected chainguard influx
influxd affected chainguard influxd
influxd affected wolfi influxd
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller-fips affected chainguard ingress-nginx-controller-fips
ipfs affected chainguard ipfs
ipfs affected wolfi ipfs
ip-masq-agent affected chainguard ip-masq-agent
ip-masq-agent affected wolfi ip-masq-agent
istio-cni-1.19 affected wolfi istio-cni-1.19
istio-cni-1.19 affected chainguard istio-cni-1.19
istio-cni-1.20 affected wolfi istio-cni-1.20
istio-cni-1.20 affected chainguard istio-cni-1.20
istio-cni-1.21 affected wolfi istio-cni-1.21
istio-cni-1.21 affected chainguard istio-cni-1.21
istio-cni-fips-1.19 affected chainguard istio-cni-fips-1.19
istio-fips-1.20 affected chainguard istio-fips-1.20
istio-fips-1.21 affected chainguard istio-fips-1.21
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-1.21 affected chainguard istio-operator-1.21
istio-operator-1.21 affected wolfi istio-operator-1.21
istio-operator-fips-1.19 affected chainguard istio-operator-fips-1.19
istio-pilot-agent-1.19 affected wolfi istio-pilot-agent-1.19
istio-pilot-agent-1.19 affected chainguard istio-pilot-agent-1.19
istio-pilot-agent-1.21 affected wolfi istio-pilot-agent-1.21
istio-pilot-agent-1.21 affected chainguard istio-pilot-agent-1.21
istio-pilot-agent-fips-1.19 affected chainguard istio-pilot-agent-fips-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.20 affected wolfi istio-pilot-discovery-1.20
istio-pilot-discovery-1.20 affected chainguard istio-pilot-discovery-1.20
istio-pilot-discovery-1.21 affected wolfi istio-pilot-discovery-1.21
istio-pilot-discovery-1.21 affected chainguard istio-pilot-discovery-1.21
istio-pilot-discovery-fips-1.19 affected chainguard istio-pilot-discovery-fips-1.19
jsonnet-bundler affected chainguard jsonnet-bundler
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected wolfi k3s
k3s affected chainguard k3s
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
k8sgpt-operator affected chainguard k8sgpt-operator
k8sgpt-operator affected wolfi k8sgpt-operator
k8ssandra-operator affected wolfi k8ssandra-operator
k8ssandra-operator affected chainguard k8ssandra-operator
k8ssandra-operator-fips affected chainguard k8ssandra-operator-fips
k9s affected chainguard k9s
k9s affected wolfi k9s
kaf affected chainguard kaf
kaf affected wolfi kaf
kafka_exporter affected chainguard kafka_exporter
kafka_exporter affected wolfi kafka_exporter
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
kargo affected wolfi kargo
kargo affected chainguard kargo
karpenter affected wolfi karpenter
karpenter affected chainguard karpenter
karpenter-0.23 affected chainguard karpenter-0.23
karpenter-0.35 affected chainguard karpenter-0.35
karpenter-fips-0.35 affected chainguard karpenter-fips-0.35
keda-2.13 affected chainguard keda-2.13
keda-2.13 affected wolfi keda-2.13
keda-fips affected chainguard keda-fips
kiam affected chainguard kiam
kind affected chainguard kind
kind affected wolfi kind
kine affected chainguard kine
kine affected wolfi kine
ko affected wolfi ko
ko affected chainguard ko
ko-fips affected wolfi ko-fips
ko-fips affected chainguard ko-fips
kor affected wolfi kor
kor affected chainguard kor
kpt affected wolfi kpt
kpt affected chainguard kpt
kubeadm-bootstrap-controller affected chainguard kubeadm-bootstrap-controller
kubeadm-bootstrap-controller affected wolfi kubeadm-bootstrap-controller
kubeadm-controlplane-controller affected wolfi kubeadm-controlplane-controller
kubeadm-controlplane-controller affected chainguard kubeadm-controlplane-controller
kube-bench affected chainguard kube-bench
kube-bench affected wolfi kube-bench
kube-bench-fips affected chainguard kube-bench-fips
kubebuilder affected wolfi kubebuilder
kubebuilder affected chainguard kubebuilder
kubecolor affected wolfi kubecolor
kubecolor affected chainguard kubecolor
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kube-logging-operator affected wolfi kube-logging-operator
kube-logging-operator affected chainguard kube-logging-operator
kube-oidc-proxy affected chainguard kube-oidc-proxy
kuberay-operator affected chainguard kuberay-operator
kuberay-operator affected wolfi kuberay-operator
kube-rbac-proxy affected chainguard kube-rbac-proxy
kube-rbac-proxy affected wolfi kube-rbac-proxy
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-csi-external-attacher-4.3 affected wolfi kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.3 affected chainguard kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.4 affected wolfi kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-attacher-4.4 affected chainguard kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-attacher-fips-4.3 affected chainguard kubernetes-csi-external-attacher-fips-4.3
kubernetes-csi-external-attacher-fips-4.4 affected chainguard kubernetes-csi-external-attacher-fips-4.4
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-external-resizer-1.10 affected wolfi kubernetes-csi-external-resizer-1.10
kubernetes-csi-external-resizer-1.10 affected chainguard kubernetes-csi-external-resizer-1.10
kubernetes-csi-external-resizer-1.8 affected chainguard kubernetes-csi-external-resizer-1.8
kubernetes-csi-external-resizer-1.9 affected chainguard kubernetes-csi-external-resizer-1.9
kubernetes-csi-external-resizer-fips-1.10 affected chainguard kubernetes-csi-external-resizer-fips-1.10
kubernetes-csi-external-resizer-fips-1.8 affected chainguard kubernetes-csi-external-resizer-fips-1.8
kubernetes-csi-external-resizer-fips-1.9 affected chainguard kubernetes-csi-external-resizer-fips-1.9
kubernetes-csi-external-snapshotter affected chainguard kubernetes-csi-external-snapshotter
kubernetes-csi-external-snapshotter affected wolfi kubernetes-csi-external-snapshotter
kubernetes-csi-external-snapshotter-6.0 affected chainguard kubernetes-csi-external-snapshotter-6.0
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-csi-node-driver-registrar-2.10 affected wolfi kubernetes-csi-node-driver-registrar-2.10
kubernetes-csi-node-driver-registrar-2.10 affected chainguard kubernetes-csi-node-driver-registrar-2.10
kubernetes-csi-node-driver-registrar-2.6 affected chainguard kubernetes-csi-node-driver-registrar-2.6
kubernetes-csi-node-driver-registrar-2.7 affected chainguard kubernetes-csi-node-driver-registrar-2.7
kubernetes-csi-node-driver-registrar-2.8 affected chainguard kubernetes-csi-node-driver-registrar-2.8
kubernetes-csi-node-driver-registrar-2.9 affected wolfi kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-2.9 affected chainguard kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-fips-2.10 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.10
kubernetes-csi-node-driver-registrar-fips-2.6 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.6
kubernetes-csi-node-driver-registrar-fips-2.7 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.7
kubernetes-csi-node-driver-registrar-fips-2.8 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.8
kubernetes-csi-node-driver-registrar-fips-2.9 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.9
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard-fips affected chainguard kubernetes-dashboard-fips
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper-fips affected chainguard kubernetes-dashboard-metrics-scraper-fips
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
kubernetes-event-exporter affected wolfi kubernetes-event-exporter
kubernetes-event-exporter affected chainguard kubernetes-event-exporter
kubernetes-fips-1.27 affected chainguard kubernetes-fips-1.27
kubernetes-fips-1.28 affected chainguard kubernetes-fips-1.28
kubernetes-fips-1.29 affected chainguard kubernetes-fips-1.29
kubernetes-ingress-defaultbackend affected wolfi kubernetes-ingress-defaultbackend
kubernetes-ingress-defaultbackend affected chainguard kubernetes-ingress-defaultbackend
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kube-state-metrics affected wolfi kube-state-metrics
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics-2.2.0 affected chainguard kube-state-metrics-2.2.0
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
kubewatch affected chainguard kubewatch
kubewatch affected wolfi kubewatch
kustomize affected wolfi kustomize
kustomize affected chainguard kustomize
kwok affected chainguard kwok
kwok affected wolfi kwok
kyverno affected chainguard kyverno
kyverno affected wolfi kyverno
kyverno-fips affected chainguard kyverno-fips
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
kyverno-policy-reporter-2.11 affected chainguard kyverno-policy-reporter-2.11
kyverno-policy-reporter-kyverno-plugin affected wolfi kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-kyverno-plugin affected chainguard kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-kyverno-plugin-1.5 affected chainguard kyverno-policy-reporter-kyverno-plugin-1.5
kyverno-policy-reporter-ui affected wolfi kyverno-policy-reporter-ui
kyverno-policy-reporter-ui affected chainguard kyverno-policy-reporter-ui
kyverno-policy-reporter-ui-1.7 affected chainguard kyverno-policy-reporter-ui-1.7
lazygit affected wolfi lazygit
lazygit affected chainguard lazygit
litefs affected wolfi litefs
litefs affected chainguard litefs
litestream affected chainguard litestream
litestream affected wolfi litestream
local-path-provisioner affected chainguard local-path-provisioner
local-path-provisioner affected wolfi local-path-provisioner
localstack affected chainguard localstack
logstash-exporter affected chainguard logstash-exporter
logstash-exporter affected wolfi logstash-exporter
logstash-jre-bcfips affected chainguard logstash-jre-bcfips
loki affected wolfi loki
loki affected chainguard loki
mage affected wolfi mage
mage affected chainguard mage
mc affected chainguard mc
mc affected wolfi mc
mc-fips affected chainguard mc-fips
melange affected wolfi melange
melange affected chainguard melange
memcached-exporter affected chainguard memcached-exporter
memcached-exporter affected wolfi memcached-exporter
metacontroller affected chainguard metacontroller
metacontroller affected wolfi metacontroller
metallb affected wolfi metallb
metallb affected chainguard metallb
metallb-fips affected chainguard metallb-fips
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
minify affected chainguard minify
minify affected wolfi minify
minio affected chainguard minio
minio affected wolfi minio
minio-fips affected chainguard minio-fips
mkcert affected wolfi mkcert
mkcert affected chainguard mkcert
mods affected wolfi mods
mods affected chainguard mods
mongo-tools affected chainguard mongo-tools
mongo-tools affected wolfi mongo-tools
multus-cni affected chainguard multus-cni
multus-cni affected wolfi multus-cni
multus-cni-fips affected chainguard multus-cni-fips
nats affected chainguard nats
nats affected wolfi nats
nats-server affected wolfi nats-server
nats-server affected chainguard nats-server
nerdctl affected chainguard nerdctl
nerdctl affected wolfi nerdctl
net/http2 affected golang
neuvector-scanner affected chainguard neuvector-scanner
neuvector-scanner affected wolfi neuvector-scanner
neuvector-sigstore-interface affected chainguard neuvector-sigstore-interface
neuvector-sigstore-interface affected wolfi neuvector-sigstore-interface
newrelic-fluent-bit-output affected chainguard newrelic-fluent-bit-output
newrelic-fluent-bit-output affected wolfi newrelic-fluent-bit-output
newrelic-infra-operator affected wolfi newrelic-infra-operator
newrelic-infra-operator affected chainguard newrelic-infra-operator
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent-1.43 affected chainguard newrelic-infrastructure-agent-1.43
newrelic-nri-kube-events affected chainguard newrelic-nri-kube-events
newrelic-nri-kube-events affected wolfi newrelic-nri-kube-events
newrelic-nri-kube-events-1.9 affected chainguard newrelic-nri-kube-events-1.9
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
newrelic-prometheus-configurator affected chainguard newrelic-prometheus-configurator
newrelic-prometheus-configurator affected wolfi newrelic-prometheus-configurator
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
node-feature-discovery-0.14 affected chainguard node-feature-discovery-0.14
node-feature-discovery-0.15 affected chainguard node-feature-discovery-0.15
node-feature-discovery-0.15 affected wolfi node-feature-discovery-0.15
node-problem-detector-0.8 affected wolfi node-problem-detector-0.8
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
nri-apache affected chainguard nri-apache
nri-apache affected wolfi nri-apache
nri-cassandra affected wolfi nri-cassandra
nri-cassandra affected chainguard nri-cassandra
nri-consul affected wolfi nri-consul
nri-consul affected chainguard nri-consul
nri-couchbase affected chainguard nri-couchbase
nri-couchbase affected wolfi nri-couchbase
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nri-elasticsearch affected chainguard nri-elasticsearch
nri-elasticsearch affected wolfi nri-elasticsearch
nri-f5 affected chainguard nri-f5
nri-f5 affected wolfi nri-f5
nri-haproxy affected wolfi nri-haproxy
nri-haproxy affected chainguard nri-haproxy
nri-jmx affected chainguard nri-jmx
nri-jmx affected wolfi nri-jmx
nri-kafka affected wolfi nri-kafka
nri-kafka affected chainguard nri-kafka
nri-kubernetes affected wolfi nri-kubernetes
nri-kubernetes affected chainguard nri-kubernetes
nri-kubernetes-2.13 affected chainguard nri-kubernetes-2.13
nri-memcached affected chainguard nri-memcached
nri-memcached affected wolfi nri-memcached
nri-mongodb affected wolfi nri-mongodb
nri-mongodb affected chainguard nri-mongodb
nri-mssql affected chainguard nri-mssql
nri-mssql affected wolfi nri-mssql
nri-mysql affected chainguard nri-mysql
nri-mysql affected wolfi nri-mysql
nri-nagios affected chainguard nri-nagios
nri-nagios affected wolfi nri-nagios
nri-nginx affected chainguard nri-nginx
nri-nginx affected wolfi nri-nginx
nri-postgresql affected chainguard nri-postgresql
nri-postgresql affected wolfi nri-postgresql
nri-prometheus affected wolfi nri-prometheus
nri-prometheus affected chainguard nri-prometheus
nri-rabbitmq affected wolfi nri-rabbitmq
nri-rabbitmq affected chainguard nri-rabbitmq
nri-redis affected chainguard nri-redis
nri-redis affected wolfi nri-redis
nsc affected chainguard nsc
nsc affected wolfi nsc
nuclei affected wolfi nuclei
nuclei affected chainguard nuclei
oauth2-proxy affected wolfi oauth2-proxy
oauth2-proxy affected chainguard oauth2-proxy
ollama affected wolfi ollama
ollama affected chainguard ollama
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
opentofu affected chainguard opentofu
opentofu affected wolfi opentofu
opentofu-1.6 affected chainguard opentofu-1.6
oras affected wolfi oras
oras affected chainguard oras
osv-scanner affected chainguard osv-scanner
osv-scanner affected wolfi osv-scanner
paranoia affected chainguard paranoia
paranoia affected wolfi paranoia
petname affected chainguard petname
petname affected wolfi petname
php-fpm_exporter affected wolfi php-fpm_exporter
php-fpm_exporter affected chainguard php-fpm_exporter
policy-controller affected wolfi policy-controller
policy-controller affected chainguard policy-controller
pombump affected wolfi pombump
pombump affected chainguard pombump
postgres-operator affected wolfi postgres-operator
postgres-operator affected chainguard postgres-operator
postgres-operator-fips affected chainguard postgres-operator-fips
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-2.51 affected wolfi prometheus-2.51
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-alertmanager-fips affected chainguard prometheus-alertmanager-fips
prometheus-beat-exporter affected wolfi prometheus-beat-exporter
prometheus-beat-exporter affected chainguard prometheus-beat-exporter
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-blackbox-exporter affected wolfi prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter affected wolfi prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter-fips affected chainguard prometheus-elasticsearch-exporter-fips
prometheus-fips affected chainguard prometheus-fips
prometheus-fips-2.45 affected chainguard prometheus-fips-2.45
prometheus-mongodb-exporter affected wolfi prometheus-mongodb-exporter
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter-0.37 affected chainguard prometheus-mongodb-exporter-0.37
prometheus-mongodb-exporter-fips affected chainguard prometheus-mongodb-exporter-fips
prometheus-mongodb-exporter-fips-0.37 affected chainguard prometheus-mongodb-exporter-fips-0.37
prometheus-mysqld-exporter affected wolfi prometheus-mysqld-exporter
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-nats-exporter affected wolfi prometheus-nats-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter affected wolfi prometheus-node-exporter
prometheus-node-exporter-1.4 affected chainguard prometheus-node-exporter-1.4
prometheus-node-exporter-1.5 affected chainguard prometheus-node-exporter-1.5
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-operator affected chainguard prometheus-operator
prometheus-operator affected wolfi prometheus-operator
prometheus-operator-fips affected chainguard prometheus-operator-fips
prometheus-postgres-exporter affected wolfi prometheus-postgres-exporter
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-postgres-exporter-0.13 affected chainguard prometheus-postgres-exporter-0.13
prometheus-postgres-exporter-fips affected chainguard prometheus-postgres-exporter-fips
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway-1.4 affected chainguard prometheus-pushgateway-1.4
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
prometheus-pushgateway-fips-1.4 affected chainguard prometheus-pushgateway-fips-1.4
prometheus-redis-exporter affected wolfi prometheus-redis-exporter
prometheus-redis-exporter affected chainguard prometheus-redis-exporter
prometheus-redis-exporter-fips-1.44 affected chainguard prometheus-redis-exporter-fips-1.44
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected wolfi prometheus-statsd-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter-0.22 affected chainguard prometheus-statsd-exporter-0.22
prometheus-statsd-exporter-fips affected chainguard prometheus-statsd-exporter-fips
protoc-gen-go affected chainguard protoc-gen-go
protoc-gen-go affected wolfi protoc-gen-go
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
pulumi affected chainguard pulumi
pulumi affected wolfi pulumi
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
q affected wolfi q
q affected chainguard q
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rclone affected chainguard rclone
rclone affected wolfi rclone
regclient affected chainguard regclient
regclient affected wolfi regclient
rekor affected chainguard rekor
rekor affected wolfi rekor
rekor-fips affected chainguard rekor-fips
render-template affected wolfi render-template
render-template affected chainguard render-template
request-1279 affected chainguard request-1279
request-1279-1-12 affected chainguard request-1279-1-12
restic affected chainguard restic
restic affected wolfi restic
restic-fips affected chainguard restic-fips
rootlesskit affected chainguard rootlesskit
rootlesskit affected wolfi rootlesskit
rqlite affected chainguard rqlite
rqlite affected wolfi rqlite
runc affected chainguard runc
runc affected wolfi runc
s5cmd affected chainguard s5cmd
s5cmd affected wolfi s5cmd
sbomqs affected chainguard sbomqs
sbomqs affected wolfi sbomqs
sbom-scorecard affected chainguard sbom-scorecard
sbom-scorecard affected wolfi sbom-scorecard
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
shfmt affected chainguard shfmt
shfmt affected wolfi shfmt
sigstore-scaffolding affected wolfi sigstore-scaffolding
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding-fips affected chainguard sigstore-scaffolding-fips
skaffold affected wolfi skaffold
skaffold affected chainguard skaffold
skopeo affected wolfi skopeo
skopeo affected chainguard skopeo
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
sonobuoy affected wolfi sonobuoy
sonobuoy affected chainguard sonobuoy
sops affected wolfi sops
sops affected chainguard sops
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
speedtest-go affected wolfi speedtest-go
speedtest-go affected chainguard speedtest-go
spegel affected chainguard spegel
spegel affected wolfi spegel
spicedb affected wolfi spicedb
spicedb affected chainguard spicedb
spire-server affected chainguard spire-server
spire-server affected wolfi spire-server
spqr affected wolfi spqr
spqr affected chainguard spqr
src affected chainguard src
src affected wolfi src
src-fingerprint affected chainguard src-fingerprint
src-fingerprint affected wolfi src-fingerprint
stakater-reloader affected chainguard stakater-reloader
stakater-reloader affected wolfi stakater-reloader
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
step affected wolfi step
step affected chainguard step
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
step-ca-fips affected chainguard step-ca-fips
step-fips affected chainguard step-fips
step-issuer affected wolfi step-issuer
step-issuer affected chainguard step-issuer
step-issuer-fips affected chainguard step-issuer-fips
stern affected wolfi stern
stern affected chainguard stern
supercronic affected chainguard supercronic
supercronic affected wolfi supercronic
swagger affected wolfi swagger
swagger affected chainguard swagger
tailscale affected chainguard tailscale
tailscale affected wolfi tailscale
task affected chainguard task
task affected wolfi task
tctl affected wolfi tctl
tctl affected chainguard tctl
tctl-fips affected chainguard tctl-fips
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
tekton-pipelines-fips affected chainguard tekton-pipelines-fips
telegraf-1.29 affected wolfi telegraf-1.29
telegraf-1.29 affected chainguard telegraf-1.29
telegraf-1.30 affected chainguard telegraf-1.30
telegraf-1.30 affected wolfi telegraf-1.30
tempo affected wolfi tempo
tempo affected chainguard tempo
temporal affected wolfi temporal
temporal affected chainguard temporal
temporal-fips affected chainguard temporal-fips
temporal-server affected chainguard temporal-server
temporal-server affected wolfi temporal-server
temporal-server-fips affected chainguard temporal-server-fips
temporal-ui-server affected wolfi temporal-ui-server
temporal-ui-server affected chainguard temporal-ui-server
temporal-ui-server-fips affected chainguard temporal-ui-server-fips
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-docs affected wolfi terraform-docs
terraform-docs affected chainguard terraform-docs
terraform-fips-1.5 affected chainguard terraform-fips-1.5
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terraform-provider-google affected wolfi terraform-provider-google
terraform-provider-google affected chainguard terraform-provider-google
terraform-provider-pagerduty affected wolfi terraform-provider-pagerduty
terraform-provider-pagerduty affected chainguard terraform-provider-pagerduty
terraform-provider-pagerduty-fips affected chainguard terraform-provider-pagerduty-fips
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
terragrunt affected wolfi terragrunt
terragrunt affected chainguard terragrunt
tflint affected chainguard tflint
tflint affected wolfi tflint
tfsec affected wolfi tfsec
tfsec affected chainguard tfsec
thanos affected chainguard thanos
thanos affected wolfi thanos
thanos-fips affected chainguard thanos-fips
thanos-operator affected wolfi thanos-operator
thanos-operator affected chainguard thanos-operator
thanos-operator-fips affected chainguard thanos-operator-fips
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
tigera-operator-1.30 affected chainguard tigera-operator-1.30
tigera-operator-1.30 affected wolfi tigera-operator-1.30
tigera-operator-1.31 affected wolfi tigera-operator-1.31
tigera-operator-1.31 affected chainguard tigera-operator-1.31
tigera-operator-1.32 affected wolfi tigera-operator-1.32
tigera-operator-1.32 affected chainguard tigera-operator-1.32
tigera-operator-1.33 affected chainguard tigera-operator-1.33
tigera-operator-1.33 affected wolfi tigera-operator-1.33
tigera-operator-fips affected chainguard tigera-operator-fips
tigera-operator-fips-1.29 affected chainguard tigera-operator-fips-1.29
tigera-operator-fips-1.32 affected chainguard tigera-operator-fips-1.32
timestamp-authority affected wolfi timestamp-authority
timestamp-authority affected chainguard timestamp-authority
timestamp-authority-fips affected chainguard timestamp-authority-fips
timoni affected wolfi timoni
timoni affected chainguard timoni
tkn affected chainguard tkn
tkn affected wolfi tkn
tkn-fips affected chainguard tkn-fips
trillian affected wolfi trillian
trillian affected chainguard trillian
trillian-fips affected chainguard trillian-fips
trivy affected chainguard trivy
trivy affected wolfi trivy
trust-manager affected wolfi trust-manager
trust-manager affected chainguard trust-manager
trust-manager-fips affected chainguard trust-manager-fips
up affected chainguard up
up affected wolfi up
vault-csi-provider affected chainguard vault-csi-provider
vault-csi-provider affected wolfi vault-csi-provider
vault-k8s affected wolfi vault-k8s
vault-k8s affected chainguard vault-k8s
vault-k8s-fips affected chainguard vault-k8s-fips
velero affected chainguard velero
velero affected wolfi velero
velero-fips affected chainguard velero-fips
velero-plugin-for-aws affected chainguard velero-plugin-for-aws
velero-plugin-for-aws affected wolfi velero-plugin-for-aws
velero-plugin-for-aws-fips affected chainguard velero-plugin-for-aws-fips
velero-plugin-for-csi affected chainguard velero-plugin-for-csi
velero-plugin-for-csi affected wolfi velero-plugin-for-csi
velero-plugin-for-csi-fips affected chainguard velero-plugin-for-csi-fips
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vertical-pod-autoscaler-fips affected chainguard vertical-pod-autoscaler-fips
vexctl affected wolfi vexctl
vexctl affected chainguard vexctl
volume-modifier-for-k8s affected wolfi volume-modifier-for-k8s
volume-modifier-for-k8s affected chainguard volume-modifier-for-k8s
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
vt-cli affected chainguard vt-cli
vt-cli affected wolfi vt-cli
wait-for-port affected wolfi wait-for-port
wait-for-port affected chainguard wait-for-port
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
wazero affected wolfi wazero
wazero affected chainguard wazero
wire-go affected chainguard wire-go
wire-go affected wolfi wire-go
wireguard-go affected wolfi wireguard-go
wireguard-go affected chainguard wireguard-go
xcaddy affected chainguard xcaddy
xcaddy affected wolfi xcaddy
x/net affected golang.org golang.org/x/net
x/net/http2 affected golang.org golang.org/x/net/http2
yam affected chainguard yam
yam affected wolfi yam
yq affected wolfi yq
yq affected chainguard yq
ytt affected wolfi ytt
ytt affected chainguard ytt
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

GHSA-4v7x-pqxf-cx7m

Open SourcePoC exploitHIGH2024-04-04

net/http, x/net/http2: close connections when receiving too many headers

Affected products

ProductStatusVendorPackageEcosystem
http affected net net/http
x/net affected golang.org golang.org/x/net
x/net/http2 affected golang.org golang.org/x/net/http2
Upstream advisory

AZL-38158

Open SourcePoC exploitHIGH2024-04-04

CVE-2023-45288 affecting package application-gateway-kubernetes-ingress for versions less than 1.7.7-1

Affected products

ProductStatusVendorPackageEcosystem
application-gateway-kubernetes-ingress affected Azure Linux:3 application-gateway-kubernetes-ingress
Upstream advisory

AZL-38173

Open SourcePoC exploitHIGH2024-04-04

CVE-2023-45288 affecting package kubernetes for versions less than 1.30.1-1

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:3 kubernetes
Upstream advisory

AZL-39235

Open SourcePoC exploitHIGH2024-04-04

CVE-2023-45288 affecting package kubernetes for versions less than 1.28.4-7

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:2 kubernetes
Upstream advisory

DEBIAN-CVE-2023-45288

Open SourcePoC exploitHIGH2024-04-04

DEBIAN-CVE-2023-45288

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
golang-golang-x-net affected Debian:11 golang-golang-x-net
golang-golang-x-net affected Debian:12 golang-golang-x-net
golang-golang-x-net affected Debian:13 golang-golang-x-net
golang-golang-x-net affected Debian:14 golang-golang-x-net
Upstream advisory

CVE-2023-45288

Open SourcePoC exploitMEDIUM2024-04-03

net/http, x/net/http2: close connections when receiving too many headers

CVEs:CVE-2023-45288

Affected products

ProductStatusVendorPackageEcosystem
http affected net net/http
x/net affected golang.org golang.org/x/net
x/net/http2 affected golang.org golang.org/x/net/http2
Upstream advisory

GO-2024-2687

Open SourcePoC exploitHIGH2024-04-03

HTTP/2 CONTINUATION flood in net/http

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
actions-runner-controller affected wolfi actions-runner-controller
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller-fips affected chainguard actions-runner-controller-fips
addon-resizer affected chainguard addon-resizer
addon-resizer affected wolfi addon-resizer
addon-resizer-fips affected chainguard addon-resizer-fips
amass affected wolfi amass
amass affected chainguard amass
apko affected chainguard apko
apko affected wolfi apko
argo-workflows affected chainguard argo-workflows
argo-workflows affected wolfi argo-workflows
argo-workflows-fips affected chainguard argo-workflows-fips
atlantis affected chainguard atlantis
atlantis affected wolfi atlantis
atlantis-fips affected chainguard atlantis-fips
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
aws-network-policy-agent affected wolfi aws-network-policy-agent
aws-network-policy-agent affected chainguard aws-network-policy-agent
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bazelisk affected wolfi bazelisk
bazelisk affected chainguard bazelisk
bom affected chainguard bom
bom affected wolfi bom
boring-registry affected wolfi boring-registry
boring-registry affected chainguard boring-registry
boring-registry-fips affected chainguard boring-registry-fips
buf affected wolfi buf
buf affected chainguard buf
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
caddy affected wolfi caddy
caddy affected chainguard caddy
caddy-fips affected chainguard caddy-fips
cadvisor affected chainguard cadvisor
cadvisor affected wolfi cadvisor
cadvisor-fips affected chainguard cadvisor-fips
capslock affected chainguard capslock
capslock affected wolfi capslock
cass-operator affected chainguard cass-operator
cass-operator affected wolfi cass-operator
cass-operator-fips affected chainguard cass-operator-fips
cass-operator-fips-no-pvc-delete affected chainguard cass-operator-fips-no-pvc-delete
cert-exporter affected chainguard cert-exporter
cert-exporter affected wolfi cert-exporter
cert-exporter-fips affected chainguard cert-exporter-fips
certificate-transparency affected wolfi certificate-transparency
certificate-transparency affected chainguard certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cert-manager-webhook-pdns affected chainguard cert-manager-webhook-pdns
cert-manager-webhook-pdns affected wolfi cert-manager-webhook-pdns
cert-manager-webhook-pdns-fips affected chainguard cert-manager-webhook-pdns-fips
cfssl affected wolfi cfssl
cfssl affected chainguard cfssl
chainctl affected chainguard chainctl
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
chezmoi affected wolfi chezmoi
chezmoi affected chainguard chezmoi
cilium-1.15 affected chainguard cilium-1.15
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
cilium-fips-1.15 affected chainguard cilium-fips-1.15
cloudflared affected chainguard cloudflared
cloudflared affected wolfi cloudflared
cloud-provider-gcp-cloud-controller-manager affected chainguard cloud-provider-gcp-cloud-controller-manager
cloud-provider-gcp-cloud-controller-manager affected wolfi cloud-provider-gcp-cloud-controller-manager
cloud-provider-gcp-cloud-controller-manager-fips affected chainguard cloud-provider-gcp-cloud-controller-manager-fips
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
cluster-proportional-autoscaler affected wolfi cluster-proportional-autoscaler
cluster-proportional-autoscaler affected chainguard cluster-proportional-autoscaler
cni-plugins affected wolfi cni-plugins
cni-plugins affected chainguard cni-plugins
configmap-reload affected chainguard configmap-reload
configmap-reload affected wolfi configmap-reload
confluent-common-docker affected chainguard confluent-common-docker
confluent-common-docker affected wolfi confluent-common-docker
conftest affected wolfi conftest
conftest affected chainguard conftest
conftest-fips affected chainguard conftest-fips
controller-gen affected wolfi controller-gen
controller-gen affected chainguard controller-gen
cortex affected wolfi cortex
cortex affected chainguard cortex
cortex-fips affected chainguard cortex-fips
cosign affected wolfi cosign
cosign affected chainguard cosign
cosign-fips affected chainguard cosign-fips
crane affected wolfi crane
crane affected chainguard crane
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
croc affected chainguard croc
croc affected wolfi croc
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-aws-cloudformation affected wolfi crossplane-provider-aws-cloudformation
crossplane-provider-aws-cloudformation affected chainguard crossplane-provider-aws-cloudformation
crossplane-provider-aws-cloudfront affected wolfi crossplane-provider-aws-cloudfront
crossplane-provider-aws-cloudfront affected chainguard crossplane-provider-aws-cloudfront
crossplane-provider-aws-cloudwatchlogs affected chainguard crossplane-provider-aws-cloudwatchlogs
crossplane-provider-aws-cloudwatchlogs affected wolfi crossplane-provider-aws-cloudwatchlogs
crossplane-provider-aws-dynamodb affected wolfi crossplane-provider-aws-dynamodb
crossplane-provider-aws-dynamodb affected chainguard crossplane-provider-aws-dynamodb
crossplane-provider-aws-ec2 affected wolfi crossplane-provider-aws-ec2
crossplane-provider-aws-ec2 affected chainguard crossplane-provider-aws-ec2
crossplane-provider-aws-eks affected wolfi crossplane-provider-aws-eks
crossplane-provider-aws-eks affected chainguard crossplane-provider-aws-eks
crossplane-provider-aws-elasticache affected chainguard crossplane-provider-aws-elasticache
crossplane-provider-aws-elasticache affected wolfi crossplane-provider-aws-elasticache
crossplane-provider-aws-firehose affected chainguard crossplane-provider-aws-firehose
crossplane-provider-aws-firehose affected wolfi crossplane-provider-aws-firehose
crossplane-provider-aws-iam affected wolfi crossplane-provider-aws-iam
crossplane-provider-aws-iam affected chainguard crossplane-provider-aws-iam
crossplane-provider-aws-kinesis affected chainguard crossplane-provider-aws-kinesis
crossplane-provider-aws-kinesis affected wolfi crossplane-provider-aws-kinesis
crossplane-provider-aws-kms affected wolfi crossplane-provider-aws-kms
crossplane-provider-aws-kms affected chainguard crossplane-provider-aws-kms
crossplane-provider-aws-lambda affected chainguard crossplane-provider-aws-lambda
crossplane-provider-aws-lambda affected wolfi crossplane-provider-aws-lambda
crossplane-provider-aws-memorydb affected chainguard crossplane-provider-aws-memorydb
crossplane-provider-aws-memorydb affected wolfi crossplane-provider-aws-memorydb
crossplane-provider-aws-rds affected chainguard crossplane-provider-aws-rds
crossplane-provider-aws-rds affected wolfi crossplane-provider-aws-rds
crossplane-provider-aws-route53 affected chainguard crossplane-provider-aws-route53
crossplane-provider-aws-route53 affected wolfi crossplane-provider-aws-route53
crossplane-provider-aws-s3 affected wolfi crossplane-provider-aws-s3
crossplane-provider-aws-s3 affected chainguard crossplane-provider-aws-s3
crossplane-provider-aws-sns affected wolfi crossplane-provider-aws-sns
crossplane-provider-aws-sns affected chainguard crossplane-provider-aws-sns
crossplane-provider-aws-sqs affected wolfi crossplane-provider-aws-sqs
crossplane-provider-aws-sqs affected chainguard crossplane-provider-aws-sqs
crossplane-provider-azure affected wolfi crossplane-provider-azure
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure-authorization affected wolfi crossplane-provider-azure-authorization
crossplane-provider-azure-authorization affected chainguard crossplane-provider-azure-authorization
crossplane-provider-azure-managedidentity affected wolfi crossplane-provider-azure-managedidentity
crossplane-provider-azure-managedidentity affected chainguard crossplane-provider-azure-managedidentity
crossplane-provider-azure-sql affected wolfi crossplane-provider-azure-sql
crossplane-provider-azure-sql affected chainguard crossplane-provider-azure-sql
crossplane-provider-azure-storage affected wolfi crossplane-provider-azure-storage
crossplane-provider-azure-storage affected chainguard crossplane-provider-azure-storage
crossplane-provider-family-aws affected wolfi crossplane-provider-family-aws
crossplane-provider-family-aws affected chainguard crossplane-provider-family-aws
crossplane-provider-family-azure affected chainguard crossplane-provider-family-azure
crossplane-provider-family-azure affected wolfi crossplane-provider-family-azure
crossplane-provider-gcp affected chainguard crossplane-provider-gcp
cue affected wolfi cue
cue affected chainguard cue
cue-fips affected chainguard cue-fips
dagdotdev affected wolfi dagdotdev
dagdotdev affected chainguard dagdotdev
dask-gateway affected wolfi dask-gateway
dask-gateway affected chainguard dask-gateway
dataplaneapi affected chainguard dataplaneapi
dataplaneapi affected wolfi dataplaneapi
delve affected wolfi delve
delve affected chainguard delve
dex affected chainguard dex
dex affected wolfi dex
dex-fips affected chainguard dex-fips
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
direnv affected chainguard direnv
direnv affected wolfi direnv
dive affected wolfi dive
dive affected chainguard dive
docker-cli affected wolfi docker-cli
docker-cli affected chainguard docker-cli
docker-compose affected chainguard docker-compose
docker-compose affected wolfi docker-compose
docker-credential-acr-env affected chainguard docker-credential-acr-env
docker-credential-acr-env affected wolfi docker-credential-acr-env
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-gcr affected wolfi docker-credential-gcr
docker-credential-gcr affected chainguard docker-credential-gcr
dockerize affected wolfi dockerize
dockerize affected chainguard dockerize
dockerize-fips affected chainguard dockerize-fips
doppler-kubernetes-operator affected chainguard doppler-kubernetes-operator
doppler-kubernetes-operator affected wolfi doppler-kubernetes-operator
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
envoy-ratelimit affected chainguard envoy-ratelimit
envoy-ratelimit affected wolfi envoy-ratelimit
envoy-ratelimit-fips affected chainguard envoy-ratelimit-fips
esbuild affected wolfi esbuild
esbuild affected chainguard esbuild
etcd-3.4 affected chainguard etcd-3.4
etcd-3.5 affected chainguard etcd-3.5
etcd-fips-3.4 affected chainguard etcd-fips-3.4
etcd-fips-3.5 affected chainguard etcd-fips-3.5
external-secrets-fips affected chainguard external-secrets-fips
falcoctl affected wolfi falcoctl
falcoctl affected chainguard falcoctl
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
falcosidekick affected wolfi falcosidekick
falcosidekick affected chainguard falcosidekick
falcosidekick-fips affected chainguard falcosidekick-fips
ferretdb affected wolfi ferretdb
ferretdb affected chainguard ferretdb
flannel affected chainguard flannel
flannel affected wolfi flannel
flannel-cni-plugin affected wolfi flannel-cni-plugin
flannel-cni-plugin affected chainguard flannel-cni-plugin
flux affected chainguard flux
flux affected wolfi flux
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
flyte affected chainguard flyte
flyte affected wolfi flyte
fq affected chainguard fq
fq affected wolfi fq
frp affected chainguard frp
frp affected wolfi frp
fulcio affected wolfi fulcio
fulcio affected chainguard fulcio
fulcio-fips affected chainguard fulcio-fips
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
gcsfuse affected wolfi gcsfuse
gcsfuse affected chainguard gcsfuse
gh affected wolfi gh
gh affected chainguard gh
ghaudit affected chainguard ghaudit
ghaudit affected wolfi ghaudit
gitleaks affected chainguard gitleaks
gitleaks affected wolfi gitleaks
git-lfs affected wolfi git-lfs
git-lfs affected chainguard git-lfs
gitness affected chainguard gitness
gitness affected wolfi gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
glab affected wolfi glab
glab affected chainguard glab
go-1.20 affected chainguard go-1.20
go-1.20 affected wolfi go-1.20
go-1.21 affected wolfi go-1.21
go-1.21 affected chainguard go-1.21
go-1.22 affected chainguard go-1.22
go-1.22 affected wolfi go-1.22
go-bindata affected chainguard go-bindata
go-bindata affected wolfi go-bindata
gobump affected chainguard gobump
gobump affected wolfi gobump
gobuster affected wolfi gobuster
gobuster affected chainguard gobuster
golangci-lint affected chainguard golangci-lint
golangci-lint affected wolfi golangci-lint
go-licenses affected wolfi go-licenses
go-licenses affected chainguard go-licenses
go-md2man affected chainguard go-md2man
go-md2man affected wolfi go-md2man
gomplate affected chainguard gomplate
gomplate affected wolfi gomplate
goreleaser affected wolfi goreleaser
goreleaser affected chainguard goreleaser
gostatsd affected wolfi gostatsd
gostatsd affected chainguard gostatsd
gosu affected chainguard gosu
gosu affected wolfi gosu
gotenberg affected chainguard gotenberg
govulncheck affected wolfi govulncheck
govulncheck affected chainguard govulncheck
gptscript affected wolfi gptscript
gptscript affected chainguard gptscript
grafana-agent-operator affected wolfi grafana-agent-operator
grafana-agent-operator affected chainguard grafana-agent-operator
grafana-operator affected chainguard grafana-operator
grafana-operator affected wolfi grafana-operator
grafana-operator-fips affected chainguard grafana-operator-fips
grpc-health-probe affected chainguard grpc-health-probe
grpc-health-probe affected wolfi grpc-health-probe
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
guac affected wolfi guac
guac affected chainguard guac
haproxy-ingress affected chainguard haproxy-ingress
haproxy-ingress affected wolfi haproxy-ingress
harbor-cli affected wolfi harbor-cli
harbor-cli affected chainguard harbor-cli
harbor-registry affected chainguard harbor-registry
harbor-registry affected wolfi harbor-registry
harbor-registry-fips affected chainguard harbor-registry-fips
harbor-scanner-trivy affected wolfi harbor-scanner-trivy
harbor-scanner-trivy affected chainguard harbor-scanner-trivy
harbor-scanner-trivy-fips affected chainguard harbor-scanner-trivy-fips
hcloud affected chainguard hcloud
hcloud affected wolfi hcloud
hello-world-golang affected chainguard hello-world-golang
hello-world-golang affected wolfi hello-world-golang
helm affected chainguard helm
helm affected wolfi helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected wolfi helm-operator
helm-operator affected chainguard helm-operator
helm-operator-fips affected chainguard helm-operator-fips
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
hey affected wolfi hey
hey affected chainguard hey
http-echo affected chainguard http-echo
http-echo affected wolfi http-echo
hubble affected chainguard hubble
hubble affected wolfi hubble
hubble-fips affected chainguard hubble-fips
hubble-ui affected chainguard hubble-ui
hubble-ui affected wolfi hubble-ui
hubble-ui-backend-fips affected chainguard hubble-ui-backend-fips
hugo affected wolfi hugo
hugo affected chainguard hugo
hugo-extended affected chainguard hugo-extended
hugo-extended affected wolfi hugo-extended
influx affected wolfi influx
influx affected chainguard influx
ip-masq-agent affected chainguard ip-masq-agent
ip-masq-agent affected wolfi ip-masq-agent
jsonnet-bundler affected chainguard jsonnet-bundler
k3d affected wolfi k3d
k3d affected chainguard k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k8sgpt-operator affected wolfi k8sgpt-operator
k8sgpt-operator affected chainguard k8sgpt-operator
k8ssandra-operator affected wolfi k8ssandra-operator
k8ssandra-operator affected chainguard k8ssandra-operator
k8ssandra-operator-fips affected chainguard k8ssandra-operator-fips
k9s affected wolfi k9s
k9s affected chainguard k9s
kaf affected wolfi kaf
kaf affected chainguard kaf
kafka_exporter affected chainguard kafka_exporter
kafka_exporter affected wolfi kafka_exporter
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
kargo affected wolfi kargo
kargo affected chainguard kargo
karpenter-0.35 affected chainguard karpenter-0.35
karpenter-fips-0.35 affected chainguard karpenter-fips-0.35
kiam affected chainguard kiam
kind affected wolfi kind
kind affected chainguard kind
kine affected wolfi kine
kine affected chainguard kine
ko affected chainguard ko
ko affected wolfi ko
ko-fips affected chainguard ko-fips
kor affected wolfi kor
kor affected chainguard kor
kpt affected wolfi kpt
kpt affected chainguard kpt
kube-bench affected wolfi kube-bench
kube-bench affected chainguard kube-bench
kube-bench-fips affected chainguard kube-bench-fips
kubebuilder affected chainguard kubebuilder
kubebuilder affected wolfi kubebuilder
kubecolor affected wolfi kubecolor
kubecolor affected chainguard kubecolor
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kube-logging-operator affected wolfi kube-logging-operator
kube-logging-operator affected chainguard kube-logging-operator
kube-oidc-proxy affected chainguard kube-oidc-proxy
kuberay-operator affected chainguard kuberay-operator
kuberay-operator affected wolfi kuberay-operator
kube-rbac-proxy affected wolfi kube-rbac-proxy
kube-rbac-proxy affected chainguard kube-rbac-proxy
kubernetes-1.24 affected wolfi kubernetes-1.24
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard-fips affected chainguard kubernetes-dashboard-fips
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper-fips affected chainguard kubernetes-dashboard-metrics-scraper-fips
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-event-exporter affected wolfi kubernetes-event-exporter
kubernetes-event-exporter affected chainguard kubernetes-event-exporter
kubernetes-ingress-defaultbackend affected chainguard kubernetes-ingress-defaultbackend
kubernetes-ingress-defaultbackend affected wolfi kubernetes-ingress-defaultbackend
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
kubewatch affected chainguard kubewatch
kubewatch affected wolfi kubewatch
kustomize affected chainguard kustomize
kustomize affected wolfi kustomize
kwok affected wolfi kwok
kwok affected chainguard kwok
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
kyverno-policy-reporter-kyverno-plugin affected chainguard kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-kyverno-plugin affected wolfi kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-ui affected wolfi kyverno-policy-reporter-ui
kyverno-policy-reporter-ui affected chainguard kyverno-policy-reporter-ui
lazygit affected chainguard lazygit
lazygit affected wolfi lazygit
litefs affected chainguard litefs
litefs affected wolfi litefs
litestream affected chainguard litestream
litestream affected wolfi litestream
local-path-provisioner affected chainguard local-path-provisioner
local-path-provisioner affected wolfi local-path-provisioner
localstack affected chainguard localstack
logstash-exporter affected wolfi logstash-exporter
logstash-exporter affected chainguard logstash-exporter
mage affected chainguard mage
mage affected wolfi mage
mc affected wolfi mc
mc affected chainguard mc
mc-fips affected chainguard mc-fips
melange affected chainguard melange
melange affected wolfi melange
memcached-exporter affected wolfi memcached-exporter
memcached-exporter affected chainguard memcached-exporter
metacontroller affected wolfi metacontroller
metacontroller affected chainguard metacontroller
metallb affected chainguard metallb
metallb affected wolfi metallb
metallb-fips affected chainguard metallb-fips
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
minify affected wolfi minify
minify affected chainguard minify
minio affected chainguard minio
minio affected wolfi minio
minio-fips affected chainguard minio-fips
mkcert affected wolfi mkcert
mkcert affected chainguard mkcert
mods affected chainguard mods
mods affected wolfi mods
mongo-tools affected chainguard mongo-tools
mongo-tools affected wolfi mongo-tools
multus-cni affected chainguard multus-cni
multus-cni affected wolfi multus-cni
multus-cni-fips affected chainguard multus-cni-fips
nats affected wolfi nats
nats affected chainguard nats
nats-server affected wolfi nats-server
nats-server affected chainguard nats-server
nerdctl affected chainguard nerdctl
nerdctl affected wolfi nerdctl
neuvector-scanner affected wolfi neuvector-scanner
neuvector-scanner affected chainguard neuvector-scanner
neuvector-sigstore-interface affected wolfi neuvector-sigstore-interface
neuvector-sigstore-interface affected chainguard neuvector-sigstore-interface
newrelic-fluent-bit-output affected chainguard newrelic-fluent-bit-output
newrelic-fluent-bit-output affected wolfi newrelic-fluent-bit-output
newrelic-infra-operator affected chainguard newrelic-infra-operator
newrelic-infra-operator affected wolfi newrelic-infra-operator
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-nri-kube-events affected chainguard newrelic-nri-kube-events
newrelic-nri-kube-events affected wolfi newrelic-nri-kube-events
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
newrelic-prometheus-configurator affected wolfi newrelic-prometheus-configurator
newrelic-prometheus-configurator affected chainguard newrelic-prometheus-configurator
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nri-apache affected wolfi nri-apache
nri-apache affected chainguard nri-apache
nri-cassandra affected chainguard nri-cassandra
nri-cassandra affected wolfi nri-cassandra
nri-consul affected wolfi nri-consul
nri-consul affected chainguard nri-consul
nri-couchbase affected chainguard nri-couchbase
nri-couchbase affected wolfi nri-couchbase
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-elasticsearch affected wolfi nri-elasticsearch
nri-elasticsearch affected chainguard nri-elasticsearch
nri-f5 affected chainguard nri-f5
nri-f5 affected wolfi nri-f5
nri-haproxy affected wolfi nri-haproxy
nri-haproxy affected chainguard nri-haproxy
nri-jmx affected chainguard nri-jmx
nri-jmx affected wolfi nri-jmx
nri-kafka affected wolfi nri-kafka
nri-kafka affected chainguard nri-kafka
nri-kubernetes affected chainguard nri-kubernetes
nri-kubernetes affected wolfi nri-kubernetes
nri-memcached affected wolfi nri-memcached
nri-memcached affected chainguard nri-memcached
nri-mongodb affected wolfi nri-mongodb
nri-mongodb affected chainguard nri-mongodb
nri-mssql affected wolfi nri-mssql
nri-mssql affected chainguard nri-mssql
nri-mysql affected wolfi nri-mysql
nri-mysql affected chainguard nri-mysql
nri-nagios affected wolfi nri-nagios
nri-nagios affected chainguard nri-nagios
nri-nginx affected wolfi nri-nginx
nri-nginx affected chainguard nri-nginx
nri-postgresql affected wolfi nri-postgresql
nri-postgresql affected chainguard nri-postgresql
nri-prometheus affected chainguard nri-prometheus
nri-prometheus affected wolfi nri-prometheus
nri-rabbitmq affected chainguard nri-rabbitmq
nri-rabbitmq affected wolfi nri-rabbitmq
nri-redis affected wolfi nri-redis
nri-redis affected chainguard nri-redis
nsc affected wolfi nsc
nsc affected chainguard nsc
nuclei affected wolfi nuclei
nuclei affected chainguard nuclei
oauth2-proxy affected wolfi oauth2-proxy
oauth2-proxy affected chainguard oauth2-proxy
ollama affected wolfi ollama
ollama affected chainguard ollama
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
oras affected chainguard oras
oras affected wolfi oras
osv-scanner affected wolfi osv-scanner
osv-scanner affected chainguard osv-scanner
paranoia affected chainguard paranoia
paranoia affected wolfi paranoia
petname affected chainguard petname
petname affected wolfi petname
php-fpm_exporter affected chainguard php-fpm_exporter
php-fpm_exporter affected wolfi php-fpm_exporter
policy-controller affected wolfi policy-controller
policy-controller affected chainguard policy-controller
pombump affected wolfi pombump
pombump affected chainguard pombump
postgres-operator affected chainguard postgres-operator
postgres-operator affected wolfi postgres-operator
postgres-operator-fips affected chainguard postgres-operator-fips
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-alertmanager-fips affected chainguard prometheus-alertmanager-fips
prometheus-beat-exporter affected chainguard prometheus-beat-exporter
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter-fips affected chainguard prometheus-elasticsearch-exporter-fips
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter-0.37 affected chainguard prometheus-mongodb-exporter-0.37
prometheus-mongodb-exporter-fips affected chainguard prometheus-mongodb-exporter-fips
prometheus-mongodb-exporter-fips-0.37 affected chainguard prometheus-mongodb-exporter-fips-0.37
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter-1.4 affected chainguard prometheus-node-exporter-1.4
prometheus-node-exporter-1.5 affected chainguard prometheus-node-exporter-1.5
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-operator affected wolfi prometheus-operator
prometheus-operator affected chainguard prometheus-operator
prometheus-operator-fips affected chainguard prometheus-operator-fips
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-postgres-exporter-fips affected chainguard prometheus-postgres-exporter-fips
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway-1.4 affected chainguard prometheus-pushgateway-1.4
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
prometheus-pushgateway-fips-1.4 affected chainguard prometheus-pushgateway-fips-1.4
prometheus-redis-exporter affected chainguard prometheus-redis-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter-fips affected chainguard prometheus-statsd-exporter-fips
protoc-gen-go affected wolfi protoc-gen-go
protoc-gen-go affected chainguard protoc-gen-go
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
q affected chainguard q
q affected wolfi q
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rclone affected chainguard rclone
rclone affected wolfi rclone
regclient affected chainguard regclient
regclient affected wolfi regclient
rekor affected chainguard rekor
rekor affected wolfi rekor
rekor-fips affected chainguard rekor-fips
render-template affected wolfi render-template
render-template affected chainguard render-template
request-1279 affected chainguard request-1279
restic affected wolfi restic
restic affected chainguard restic
restic-fips affected chainguard restic-fips
rootlesskit affected wolfi rootlesskit
rootlesskit affected chainguard rootlesskit
rqlite affected wolfi rqlite
rqlite affected chainguard rqlite
runc affected chainguard runc
runc affected wolfi runc
s5cmd affected chainguard s5cmd
s5cmd affected wolfi s5cmd
sbomqs affected chainguard sbomqs
sbomqs affected wolfi sbomqs
sbom-scorecard affected chainguard sbom-scorecard
sbom-scorecard affected wolfi sbom-scorecard
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
shfmt affected chainguard shfmt
shfmt affected wolfi shfmt
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
sigstore-scaffolding-fips affected chainguard sigstore-scaffolding-fips
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
skopeo affected wolfi skopeo
skopeo affected chainguard skopeo
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
sonobuoy affected chainguard sonobuoy
sonobuoy affected wolfi sonobuoy
sops affected chainguard sops
sops affected wolfi sops
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
speedtest-go affected wolfi speedtest-go
speedtest-go affected chainguard speedtest-go
spegel affected chainguard spegel
spegel affected wolfi spegel
spicedb affected wolfi spicedb
spicedb affected chainguard spicedb
spire-server affected chainguard spire-server
spire-server affected wolfi spire-server
spqr affected wolfi spqr
spqr affected chainguard spqr
src affected chainguard src
src affected wolfi src
src-fingerprint affected wolfi src-fingerprint
src-fingerprint affected chainguard src-fingerprint
stakater-reloader affected chainguard stakater-reloader
stakater-reloader affected wolfi stakater-reloader
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
stdlib affected Go stdlib
step affected wolfi step
step affected chainguard step
step-ca affected chainguard step-ca
step-ca affected wolfi step-ca
step-ca-fips affected chainguard step-ca-fips
step-fips affected chainguard step-fips
step-issuer affected wolfi step-issuer
step-issuer affected chainguard step-issuer
step-issuer-fips affected chainguard step-issuer-fips
stern affected wolfi stern
stern affected chainguard stern
supercronic affected chainguard supercronic
supercronic affected wolfi supercronic
swagger affected wolfi swagger
swagger affected chainguard swagger
tailscale affected wolfi tailscale
tailscale affected chainguard tailscale
task affected chainguard task
task affected wolfi task
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
tempo affected chainguard tempo
tempo affected wolfi tempo
temporal affected chainguard temporal
temporal affected wolfi temporal
temporal-fips affected chainguard temporal-fips
temporal-server affected wolfi temporal-server
temporal-server affected chainguard temporal-server
temporal-server-fips affected chainguard temporal-server-fips
temporal-ui-server affected chainguard temporal-ui-server
temporal-ui-server affected wolfi temporal-ui-server
temporal-ui-server-fips affected chainguard temporal-ui-server-fips
terraform affected chainguard terraform
terraform affected wolfi terraform
terraform-docs affected chainguard terraform-docs
terraform-docs affected wolfi terraform-docs
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terraform-provider-google affected wolfi terraform-provider-google
terraform-provider-google affected chainguard terraform-provider-google
terraform-provider-pagerduty affected chainguard terraform-provider-pagerduty
terraform-provider-pagerduty affected wolfi terraform-provider-pagerduty
terraform-provider-pagerduty-fips affected chainguard terraform-provider-pagerduty-fips
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
tflint affected chainguard tflint
tflint affected wolfi tflint
tfsec affected chainguard tfsec
tfsec affected wolfi tfsec
thanos affected wolfi thanos
thanos affected chainguard thanos
thanos-fips affected chainguard thanos-fips
thanos-operator affected chainguard thanos-operator
thanos-operator affected wolfi thanos-operator
thanos-operator-fips affected chainguard thanos-operator-fips
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
tigera-operator-fips-1.29 affected chainguard tigera-operator-fips-1.29
timestamp-authority affected chainguard timestamp-authority
timestamp-authority affected wolfi timestamp-authority
timestamp-authority-fips affected chainguard timestamp-authority-fips
timoni affected wolfi timoni
timoni affected chainguard timoni
tkn affected wolfi tkn
tkn affected chainguard tkn
tkn-fips affected chainguard tkn-fips
trillian affected wolfi trillian
trillian affected chainguard trillian
trillian-fips affected chainguard trillian-fips
trivy affected wolfi trivy
trivy affected chainguard trivy
trust-manager affected wolfi trust-manager
trust-manager affected chainguard trust-manager
trust-manager-fips affected chainguard trust-manager-fips
up affected wolfi up
up affected chainguard up
vault-csi-provider affected chainguard vault-csi-provider
vault-k8s affected wolfi vault-k8s
vault-k8s affected chainguard vault-k8s
vault-k8s-fips affected chainguard vault-k8s-fips
velero affected wolfi velero
velero affected chainguard velero
velero-fips affected chainguard velero-fips
velero-plugin-for-aws affected chainguard velero-plugin-for-aws
velero-plugin-for-aws affected wolfi velero-plugin-for-aws
velero-plugin-for-aws-fips affected chainguard velero-plugin-for-aws-fips
velero-plugin-for-csi affected chainguard velero-plugin-for-csi
velero-plugin-for-csi affected wolfi velero-plugin-for-csi
velero-plugin-for-csi-fips affected chainguard velero-plugin-for-csi-fips
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler-fips affected chainguard vertical-pod-autoscaler-fips
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
volume-modifier-for-k8s affected chainguard volume-modifier-for-k8s
volume-modifier-for-k8s affected wolfi volume-modifier-for-k8s
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
vt-cli affected chainguard vt-cli
vt-cli affected wolfi vt-cli
wait-for-port affected wolfi wait-for-port
wait-for-port affected chainguard wait-for-port
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
wazero affected wolfi wazero
wazero affected chainguard wazero
wire-go affected wolfi wire-go
wire-go affected chainguard wire-go
wireguard-go affected chainguard wireguard-go
wireguard-go affected wolfi wireguard-go
xcaddy affected chainguard xcaddy
xcaddy affected wolfi xcaddy
x/net affected golang.org golang.org/x/net
yam affected wolfi yam
yam affected chainguard yam
yq affected chainguard yq
yq affected wolfi yq
ytt affected wolfi ytt
ytt affected chainguard ytt
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

CVE-2023-45288

GooglePoC exploitHIGH2024-03-06

An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a...

CVEs:CVE-2023-45288

Upstream advisory

CVE-2023-45288

Open SourcePoC exploitMEDIUM2024-03-06

net/http, x/net/http2: close connections when receiving too many headers

CVEs:CVE-2023-45288

Affected products

ProductStatusVendorPackageEcosystem
http affected net net/http
x/net affected golang.org golang.org/x/net
x/net/http2 affected golang.org golang.org/x/net/http2
Upstream advisory

GHSA-33c5-9fx5-fvjm

Open SourcePoC exploitCRITICAL2024-04-24

Privilege Escalation in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
apimachinery affected k8s.io k8s.io/apimachinery
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-33c5-9fx5-fvjm

Open SourcePoC exploitCRITICAL2024-04-24

Privilege Escalation in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
actions-runner-controller-fips affected chainguard actions-runner-controller-fips
addon-resizer-fips affected chainguard addon-resizer-fips
apimachinery affected k8s.io k8s.io/apimachinery
argo-workflows-fips affected chainguard argo-workflows-fips
aws-ebs-csi-driver-fips affected chainguard aws-ebs-csi-driver-fips
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults-fips affected chainguard bank-vaults-fips
cass-operator-fips affected chainguard cass-operator-fips
cass-operator-fips-no-pvc-delete affected chainguard cass-operator-fips-no-pvc-delete
cert-exporter affected chainguard cert-exporter
cert-exporter affected wolfi cert-exporter
cert-exporter-fips affected chainguard cert-exporter-fips
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-fips-1.12 affected chainguard cert-manager-fips-1.12
cert-manager-webhook-pdns-fips affected chainguard cert-manager-webhook-pdns-fips
cilium-1.14 affected wolfi cilium-1.14
cilium-1.14 affected chainguard cilium-1.14
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
cilium-fips-1.14 affected chainguard cilium-fips-1.14
cluster-autoscaler-1.28 affected chainguard cluster-autoscaler-1.28
cluster-autoscaler-1.28 affected wolfi cluster-autoscaler-1.28
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
cluster-autoscaler-fips-1.29 affected chainguard cluster-autoscaler-fips-1.29
consul-1.17 affected chainguard consul-1.17
coredns-fips affected chainguard coredns-fips
cosign-fips affected wolfi cosign-fips
cosign-fips affected chainguard cosign-fips
datadog-agent affected chainguard datadog-agent
datadog-agent affected wolfi datadog-agent
datadog-agent-fips affected chainguard datadog-agent-fips
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
external-dns-fips affected chainguard external-dns-fips
external-secrets-fips affected chainguard external-secrets-fips
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
falcosidekick-fips affected chainguard falcosidekick-fips
fulcio-fips affected chainguard fulcio-fips
ghaudit affected chainguard ghaudit
ghaudit affected wolfi ghaudit
glab affected chainguard glab
glab affected wolfi glab
gpu-operator affected chainguard gpu-operator
grafana-fips-10.4 affected chainguard grafana-fips-10.4
grafana-operator-fips affected chainguard grafana-operator-fips
harbor-2.9 affected chainguard harbor-2.9
harbor-fips-2.10 affected chainguard harbor-fips-2.10
harbor-fips-2.9 affected chainguard harbor-fips-2.9
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected wolfi helm-operator
helm-operator affected chainguard helm-operator
helm-operator-fips affected chainguard helm-operator-fips
hubble affected wolfi hubble
hubble affected chainguard hubble
hubble-fips affected chainguard hubble-fips
hubble-ui-backend-fips affected chainguard hubble-ui-backend-fips
istio-fips-1.21 affected chainguard istio-fips-1.21
k8ssandra-operator-fips affected chainguard k8ssandra-operator-fips
karpenter-0.23 affected chainguard karpenter-0.23
karpenter-0.35 affected chainguard karpenter-0.35
karpenter-fips-0.35 affected chainguard karpenter-fips-0.35
karpenter-fips-0.36 affected chainguard karpenter-fips-0.36
keda-fips affected chainguard keda-fips
kiam affected chainguard kiam
kine affected chainguard kine
kine affected wolfi kine
ko-fips affected wolfi ko-fips
ko-fips affected chainguard ko-fips
kots affected wolfi kots
kots affected chainguard kots
kots-compat affected chainguard kots-compat
kubeadm-bootstrap-controller affected chainguard kubeadm-bootstrap-controller
kubeadm-bootstrap-controller affected wolfi kubeadm-bootstrap-controller
kube-bench-fips affected chainguard kube-bench-fips
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kube-oidc-proxy affected chainguard kube-oidc-proxy
kube-rbac-proxy-fips affected chainguard kube-rbac-proxy-fips
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-csi-node-driver-registrar-2.6 affected chainguard kubernetes-csi-node-driver-registrar-2.6
kubernetes-csi-node-driver-registrar-2.7 affected chainguard kubernetes-csi-node-driver-registrar-2.7
kubernetes-csi-node-driver-registrar-2.8 affected chainguard kubernetes-csi-node-driver-registrar-2.8
kubernetes-csi-node-driver-registrar-2.9 affected chainguard kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-2.9 affected wolfi kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-fips-2.10 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.10
kubernetes-csi-node-driver-registrar-fips-2.6 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.6
kubernetes-csi-node-driver-registrar-fips-2.7 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.7
kubernetes-csi-node-driver-registrar-fips-2.8 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.8
kubernetes-csi-node-driver-registrar-fips-2.9 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.9
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard-fips affected chainguard kubernetes-dashboard-fips
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper-fips affected chainguard kubernetes-dashboard-metrics-scraper-fips
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-secret-generator affected chainguard kubernetes-secret-generator
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kubewatch affected wolfi kubewatch
kubewatch affected chainguard kubewatch
kwok affected wolfi kwok
kwok affected chainguard kwok
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
local-path-provisioner affected wolfi local-path-provisioner
local-path-provisioner affected chainguard local-path-provisioner
local-static-provisioner affected chainguard local-static-provisioner
local-static-provisioner affected wolfi local-static-provisioner
melange affected wolfi melange
melange affected chainguard melange
metallb-fips affected chainguard metallb-fips
metrics-server-fips affected chainguard metrics-server-fips
multus-cni-fips affected chainguard multus-cni-fips
newrelic-infra-operator affected wolfi newrelic-infra-operator
newrelic-infra-operator affected chainguard newrelic-infra-operator
newrelic-nri-kube-events affected chainguard newrelic-nri-kube-events
newrelic-nri-kube-events affected wolfi newrelic-nri-kube-events
newrelic-nri-kube-events-1.9 affected chainguard newrelic-nri-kube-events-1.9
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-kubernetes affected wolfi nri-kubernetes
nri-kubernetes affected chainguard nri-kubernetes
nri-kubernetes-2.13 affected chainguard nri-kubernetes-2.13
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
policy-controller-fips affected chainguard policy-controller-fips
postgres-operator affected wolfi postgres-operator
postgres-operator affected chainguard postgres-operator
postgres-operator-fips affected chainguard postgres-operator-fips
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-operator-fips affected chainguard prometheus-operator-fips
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
request-1279 affected chainguard request-1279
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
sigstore-scaffolding-fips affected chainguard sigstore-scaffolding-fips
skaffold affected wolfi skaffold
skaffold affected chainguard skaffold
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
sonobuoy affected wolfi sonobuoy
sonobuoy affected chainguard sonobuoy
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
spire-server affected wolfi spire-server
spire-server affected chainguard spire-server
spire-server-fips affected chainguard spire-server-fips
src affected wolfi src
src affected chainguard src
stakater-reloader affected wolfi stakater-reloader
stakater-reloader affected chainguard stakater-reloader
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
step-issuer affected wolfi step-issuer
step-issuer affected chainguard step-issuer
step-issuer-fips affected chainguard step-issuer-fips
stern affected chainguard stern
stern affected wolfi stern
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
tekton-pipelines-fips affected chainguard tekton-pipelines-fips
terraform affected chainguard terraform
terraform affected wolfi terraform
terraform-1.8 affected chainguard terraform-1.8
thanos-fips affected chainguard thanos-fips
thanos-operator affected wolfi thanos-operator
thanos-operator affected chainguard thanos-operator
thanos-operator-fips affected chainguard thanos-operator-fips
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
tigera-operator-1.30 affected chainguard tigera-operator-1.30
tigera-operator-1.30 affected wolfi tigera-operator-1.30
tigera-operator-1.31 affected wolfi tigera-operator-1.31
tigera-operator-1.31 affected chainguard tigera-operator-1.31
tigera-operator-1.32 affected chainguard tigera-operator-1.32
tigera-operator-1.32 affected wolfi tigera-operator-1.32
tigera-operator-fips-1.29 affected chainguard tigera-operator-fips-1.29
tkn affected chainguard tkn
tkn affected wolfi tkn
tkn-fips affected chainguard tkn-fips
trust-manager affected wolfi trust-manager
trust-manager affected chainguard trust-manager
trust-manager-fips affected chainguard trust-manager-fips
vault-csi-provider affected chainguard vault-csi-provider
vault-k8s affected wolfi vault-k8s
vault-k8s affected chainguard vault-k8s
vault-k8s-fips affected chainguard vault-k8s-fips
velero-fips affected chainguard velero-fips
velero-plugin-for-aws-fips affected chainguard velero-plugin-for-aws-fips
velero-plugin-for-csi affected wolfi velero-plugin-for-csi
velero-plugin-for-csi affected chainguard velero-plugin-for-csi
velero-plugin-for-csi-fips affected chainguard velero-plugin-for-csi-fips
vertical-pod-autoscaler-fips affected chainguard vertical-pod-autoscaler-fips
volume-modifier-for-k8s affected wolfi volume-modifier-for-k8s
volume-modifier-for-k8s affected chainguard volume-modifier-for-k8s
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
zarf affected wolfi zarf
zarf affected chainguard zarf
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

SUSE-SU-2024:1404-1

Open SourcePoC exploit2024-04-23

Security update for kubernetes1.23

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.23 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.23
kubernetes1.23 affected openSUSE:Leap 15.5 kubernetes1.23
Upstream advisory

SUSE-SU-2024:1403-1

Open SourcePoC exploit2024-04-23

Security update for kubernetes1.24

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.24 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.24
kubernetes1.24 affected openSUSE:Leap 15.5 kubernetes1.24
Upstream advisory

GHSA-pxhw-596r-rwq5

Open SourcePoC exploitCRITICAL2024-04-23

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-pxhw-596r-rwq5

Open SourcePoC exploitCRITICAL2024-04-23

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

Affected products

ProductStatusVendorPackageEcosystem
argocd-image-updater affected chainguard argocd-image-updater
argocd-image-updater affected wolfi argocd-image-updater
argocd-image-updater-fips affected chainguard argocd-image-updater-fips
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
aws-ebs-csi-driver-fips affected chainguard aws-ebs-csi-driver-fips
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-efs-csi-driver-fips-1.6 affected chainguard aws-efs-csi-driver-fips-1.6
calico affected wolfi calico
calico affected chainguard calico
calico-fips affected chainguard calico-fips
cluster-autoscaler-1.25 affected chainguard cluster-autoscaler-1.25
cluster-autoscaler-1.25 affected wolfi cluster-autoscaler-1.25
cluster-autoscaler-1.26 affected wolfi cluster-autoscaler-1.26
cluster-autoscaler-1.26 affected chainguard cluster-autoscaler-1.26
cluster-autoscaler-1.27 affected chainguard cluster-autoscaler-1.27
cluster-autoscaler-1.27 affected wolfi cluster-autoscaler-1.27
cluster-autoscaler-1.28 affected wolfi cluster-autoscaler-1.28
cluster-autoscaler-1.28 affected chainguard cluster-autoscaler-1.28
cluster-autoscaler-1.29 affected wolfi cluster-autoscaler-1.29
cluster-autoscaler-1.29 affected chainguard cluster-autoscaler-1.29
cluster-autoscaler-fips-1.26 affected chainguard cluster-autoscaler-fips-1.26
cluster-autoscaler-fips-1.27 affected chainguard cluster-autoscaler-fips-1.27
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
cluster-autoscaler-fips-1.29 affected chainguard cluster-autoscaler-fips-1.29
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-fips-1.27 affected chainguard kubernetes-fips-1.27
kubernetes-fips-1.28 affected chainguard kubernetes-fips-1.28
kubernetes-fips-1.29 affected chainguard kubernetes-fips-1.29
local-static-provisioner affected wolfi local-static-provisioner
local-static-provisioner affected chainguard local-static-provisioner
node-feature-discovery-0.14 affected chainguard node-feature-discovery-0.14
node-feature-discovery-0.15 affected chainguard node-feature-discovery-0.15
node-feature-discovery-0.15 affected wolfi node-feature-discovery-0.15
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
rancher-webhook-0.4 affected chainguard rancher-webhook-0.4
rancher-webhook-fips-0.4 affected chainguard rancher-webhook-fips-0.4
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
Upstream advisory

AZL-40016

Open SourcePoC exploitCRITICAL2024-04-22

CVE-2024-3177 affecting package kubernetes for versions less than 1.30.1-1

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:3 kubernetes
Upstream advisory

AZL-40051

Open SourcePoC exploitCRITICAL2024-04-22

CVE-2024-3177 affecting package kubernetes 1.28.4-25

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:2 kubernetes
Upstream advisory

DEBIAN-CVE-2024-3177

Open SourcePoC exploitCRITICAL2024-04-22

DEBIAN-CVE-2024-3177

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2024-3177

GooglePoC exploitCRITICAL2024-04-16

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with th...

CVEs:CVE-2024-3177

Upstream advisory

CVE-2024-3177

GooglePoC exploit2024-04-16

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVEs:CVE-2024-3177

Upstream advisory

CVE-2024-3177

Open SourcePoC exploitLOW2024-04-16

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

CVEs:CVE-2024-3177

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-mh2p-2x66-3hr4

Open SourcePoC exploitHIGH2024-04-06

GHSA-mh2p-2x66-3hr4

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3159

Open SourcePoC exploitHIGH2024-04-06

DEBIAN-CVE-2024-3159

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3159

GooglePoC exploitHIGH2024-04-02

Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3159

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-3159

GooglePoC exploit2024-04-02

Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3159

Upstream advisory

GHSA-2cgq-h8xw-2v5j

GooglePoC exploitHIGH2024-04-30

CRI-O vulnerable to an arbitrary systemd property injection

Affected products

ProductStatusVendorPackageEcosystem
cri-o/cri-o affected github.com github.com/cri-o/cri-o
Upstream advisory

GHSA-2cgq-h8xw-2v5j

Open SourcePoC exploitHIGH2024-04-30

CRI-O vulnerable to an arbitrary systemd property injection

Affected products

ProductStatusVendorPackageEcosystem
buildah affected chainguard buildah
buildah affected wolfi buildah
cadvisor affected chainguard cadvisor
cadvisor affected wolfi cadvisor
cadvisor-fips affected chainguard cadvisor-fips
cri-o/cri-o affected github.com github.com/cri-o/cri-o
ctop affected chainguard ctop
ctop affected wolfi ctop
grype affected wolfi grype
grype affected chainguard grype
ingress-nginx-controller-fips-1.9 affected chainguard ingress-nginx-controller-fips-1.9
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-fips-1.28 affected chainguard kubernetes-fips-1.28
kubernetes-fips-1.29 affected chainguard kubernetes-fips-1.29
neuvector-scanner affected wolfi neuvector-scanner
neuvector-scanner affected chainguard neuvector-scanner
newrelic-infrastructure-agent-1.43 affected chainguard newrelic-infrastructure-agent-1.43
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
wolfictl affected chainguard wolfictl
wolfictl affected wolfi wolfictl
Upstream advisory

GHSA-jjg7-2v4v-x38h

GooglePoC exploitCRITICAL2024-04-11

Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode

Affected products

ProductStatusVendorPackageEcosystem
idna affected PyPI idna
Upstream advisory

GHSA-jjg7-2v4v-x38h

Open SourcePoC exploitCRITICAL2024-04-11

Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode

Affected products

ProductStatusVendorPackageEcosystem
az affected chainguard az
az affected wolfi az
checkov affected wolfi checkov
checkov affected chainguard checkov
confluent-docker-utils affected chainguard confluent-docker-utils
confluent-docker-utils affected wolfi confluent-docker-utils
dask-gateway affected chainguard dask-gateway
dask-gateway affected wolfi dask-gateway
datadog-agent affected chainguard datadog-agent
datadog-agent affected wolfi datadog-agent
datadog-agent-fips affected chainguard datadog-agent-fips
ggshield affected wolfi ggshield
ggshield affected chainguard ggshield
idna affected PyPI idna
idna affected PyPI idna
jwt-tool affected wolfi jwt-tool
jwt-tool affected chainguard jwt-tool
k8s-sidecar affected chainguard k8s-sidecar
k8s-sidecar affected wolfi k8s-sidecar
k8s-sidecar-1.22 affected chainguard k8s-sidecar-1.22
kserve affected chainguard kserve
kserve affected wolfi kserve
kubeflow-jupyter-web-app affected wolfi kubeflow-jupyter-web-app
kubeflow-jupyter-web-app affected chainguard kubeflow-jupyter-web-app
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines-visualization-server affected wolfi kubeflow-pipelines-visualization-server
kubeflow-pipelines-visualization-server affected chainguard kubeflow-pipelines-visualization-server
kubeflow-volumes-web-app affected wolfi kubeflow-volumes-web-app
kubeflow-volumes-web-app affected chainguard kubeflow-volumes-web-app
nvidia-nsight-compute-13.1 affected chainguard nvidia-nsight-compute-13.1
nvidia-nsight-compute-13.2 affected chainguard nvidia-nsight-compute-13.2
py3.11-pytorch-cuda-12.3 affected chainguard py3.11-pytorch-cuda-12.3
py3.11-torchaudio-cuda-12.3 affected chainguard py3.11-torchaudio-cuda-12.3
py3.11-torchvision-cuda-11.8 affected chainguard py3.11-torchvision-cuda-11.8
py3.11-torchvision-cuda-12.3 affected chainguard py3.11-torchvision-cuda-12.3
py3-cassandra-medusa affected wolfi py3-cassandra-medusa
py3-cassandra-medusa affected chainguard py3-cassandra-medusa
py3-idna affected chainguard py3-idna
py3-idna affected wolfi py3-idna
py3-pipenv affected chainguard py3-pipenv
py3-pipenv affected wolfi py3-pipenv
py3-torchvision-cuda-11.8 affected chainguard py3-torchvision-cuda-11.8
request-1276 affected chainguard request-1276
Upstream advisory

GHSA-jjff-q3q4-5hh8

Open SourcePoC exploitCRITICAL2024-04-18

@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability

Affected products

ProductStatusVendorPackageEcosystem
nora-firebase-common affected andrei-tatar @andrei-tatar/nora-firebase-common
nora-firebase-common affected andrei-tatar
Upstream advisory

GHSA-jjff-q3q4-5hh8

Open SourcePoC exploitCRITICAL2024-04-18

@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability

Affected products

ProductStatusVendorPackageEcosystem
nora-firebase-common affected andrei-tatar @andrei-tatar/nora-firebase-common
Upstream advisory

CVE-2024-30564

GooglePoC exploitCRITICAL2024-04-18

An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary code via a crafted script to the updateState parameter of the updateStateInternal method.

CVEs:CVE-2024-30564

Upstream advisory

CVE-2024-30564

Open SourcePoC exploitHIGH2024-04-18

@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability

CVEs:CVE-2024-30564

Affected products

ProductStatusVendorPackageEcosystem
nora-firebase-common affected andrei-tatar @andrei-tatar/nora-firebase-common
Upstream advisory

CVE-2024-30564

Open SourcePoC exploit2024-04-18

@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability

CVEs:CVE-2024-30564

Affected products

ProductStatusVendorPackageEcosystem
nora-firebase-common affected andrei-tatar @andrei-tatar/nora-firebase-common
Upstream advisory

OESA-2024-1432

Open SourcePoC exploit2024-04-12

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP4 golang
golang affected openEuler:22.03-LTS golang
golang affected openEuler:22.03-LTS-SP1 golang
golang affected openEuler:22.03-LTS-SP2 golang
golang affected openEuler:22.03-LTS-SP3 golang
Upstream advisory

GHSA-r76g-g87f-vw8f

Open SourcePoC exploitMEDIUM2024-04-24

Kubelet Incorrect Privilege Assignment

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/cmd/kubelet affected k8s.io k8s.io/kubernetes/cmd/kubelet
Upstream advisory

GHSA-r76g-g87f-vw8f

Open SourcePoC exploitMEDIUM2024-04-24

Kubelet Incorrect Privilege Assignment

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/cmd/kubelet affected k8s.io k8s.io/kubernetes/cmd/kubelet
Upstream advisory

GHSA-5x96-j797-5qqw

Open SourcePoC exploitHIGH2024-04-24

Sensitive Information leak via Log File in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-5x96-j797-5qqw

Open SourcePoC exploitHIGH2024-04-24

Sensitive Information leak via Log File in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-5xfg-wv98-264m

Open SourcePoC exploitHIGH2024-04-24

Sensitive Information leak via Log File in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-5xfg-wv98-264m

Open SourcePoC exploitHIGH2024-04-24

Sensitive Information leak via Log File in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-55qj-gj3x-jq9r

Open SourcePoC exploitHIGH2024-04-24

Denial of service in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/pkg/kubelet affected k8s.io k8s.io/kubernetes/pkg/kubelet
Upstream advisory

GHSA-55qj-gj3x-jq9r

Open SourcePoC exploitHIGH2024-04-24

Denial of service in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/pkg/kubelet affected k8s.io k8s.io/kubernetes/pkg/kubelet
Upstream advisory

CVE-2024-7018

GooglePoC exploitCRITICAL2024-04-24

Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

CVEs:CVE-2024-7018

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-7018

GooglePoC exploit2024-04-24

Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

CVEs:CVE-2024-7018

Upstream advisory

CVE-2024-0042

Open SourcePoC exploitHIGH2024-04-01

In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content protection with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2024-0042

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-312543200

GooglePoC exploitNONE2024-04-01

ASB-A-312543200

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-29990

Open SourceCoalition ESS < 30%CRITICAL2024-04-09

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

CVEs:CVE-2024-29990

Affected products

ProductStatusVendorPackageEcosystem
azure_kubernetes_service_confidential_containers affected microsoft
Upstream advisory

DEBIAN-CVE-2024-3817

Open SourceCoalition ESS < 30%CRITICAL2024-04-17

DEBIAN-CVE-2024-3817

Affected products

ProductStatusVendorPackageEcosystem
golang-github-hashicorp-go-getter affected Debian:11 golang-github-hashicorp-go-getter
golang-github-hashicorp-go-getter affected Debian:12 golang-github-hashicorp-go-getter
Upstream advisory

CVE-2024-29987

Open SourceCoalition ESS < 30%HIGH2024-04-09

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVEs:CVE-2024-29987

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-5r57-jcc8-jhh3

Open SourceCoalition ESS < 30%CRITICAL2024-04-17

GHSA-5r57-jcc8-jhh3

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3834

Open SourceCoalition ESS < 30%CRITICAL2024-04-17

DEBIAN-CVE-2024-3834

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3834

GoogleCoalition ESS < 30%2024-04-16

Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3834

Upstream advisory

CVE-2024-3834

GoogleCoalition ESS < 30%CRITICAL2024-04-16

Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3834

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-h5wc-jv87-367w

Open SourceCoalition ESS < 30%CRITICAL2024-04-17

GHSA-h5wc-jv87-367w

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3837

Open SourceCoalition ESS < 30%CRITICAL2024-04-17

DEBIAN-CVE-2024-3837

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3837

GoogleCoalition ESS < 30%CRITICAL2024-04-16

Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-3837

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-3837

GoogleCoalition ESS < 30%2024-04-16

Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-3837

Upstream advisory

DEBIAN-CVE-2024-22189

Open SourceCoalition ESS < 30%HIGH2024-04-04

DEBIAN-CVE-2024-22189

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lucas-clemente-quic-go affected Debian:13 golang-github-lucas-clemente-quic-go
golang-github-lucas-clemente-quic-go affected Debian:11 golang-github-lucas-clemente-quic-go
golang-github-lucas-clemente-quic-go affected Debian:12 golang-github-lucas-clemente-quic-go
golang-github-lucas-clemente-quic-go affected Debian:14 golang-github-lucas-clemente-quic-go
Upstream advisory

CVE-2024-4060

GoogleCoalition ESS < 30%CRITICAL2024-04-24

Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-4060

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-4060

GoogleCoalition ESS < 30%2024-04-24

Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-4060

Upstream advisory

GHSA-cq73-mwp9-qgj2

Open SourceCoalition ESS < 30%MEDIUM2024-04-17

GHSA-cq73-mwp9-qgj2

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3846

Open SourceCoalition ESS < 30%MEDIUM2024-04-17

DEBIAN-CVE-2024-3846

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3846

GoogleCoalition ESS < 30%MEDIUM2024-04-16

Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-3846

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-4059

GoogleCoalition ESS < 30%MEDIUM2024-04-24

Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-4059

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-4059

GoogleCoalition ESS < 30%2024-04-24

Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-4059

Upstream advisory

GHSA-r8fc-3gvg-wxxf

Open SourceCoalition ESS < 30%CRITICAL2024-04-17

GHSA-r8fc-3gvg-wxxf

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3847

Open SourceCoalition ESS < 30%CRITICAL2024-04-17

DEBIAN-CVE-2024-3847

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3847

GoogleCoalition ESS < 30%CRITICAL2024-04-16

Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-3847

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

ASB-A-323462011

GoogleCoalition ESS < 30%2024-04-01

ASB-A-323462011

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-c47q-h9w3-rcwg

Open SourceCoalition ESS < 30%CRITICAL2024-04-17

GHSA-c47q-h9w3-rcwg

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3845

Open SourceCoalition ESS < 30%MEDIUM2024-04-17

DEBIAN-CVE-2024-3845

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3845

GoogleCoalition ESS < 30%CRITICAL2024-04-16

Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-3845

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-3845

GoogleCoalition ESS < 30%2024-04-16

Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-3845

Upstream advisory

GHSA-gmx8-9854-xjqr

Open SourceCoalition ESS < 30%CRITICAL2024-04-17

GHSA-gmx8-9854-xjqr

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3840

Open SourceCoalition ESS < 30%CRITICAL2024-04-17

DEBIAN-CVE-2024-3840

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3840

GoogleCoalition ESS < 30%CRITICAL2024-04-16

Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-3840

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-3840

GoogleCoalition ESS < 30%2024-04-16

Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-3840

Upstream advisory

GHSA-5mvp-3rph-rfxg

Open SourceCoalition ESS < 30%HIGH2024-04-17

GHSA-5mvp-3rph-rfxg

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3839

Open SourceCoalition ESS < 30%HIGH2024-04-17

DEBIAN-CVE-2024-3839

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3839

GoogleCoalition ESS < 30%2024-04-16

Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-3839

Upstream advisory

CVE-2024-3839

GoogleCoalition ESS < 30%HIGH2024-04-16

Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-3839

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

ASB-A-323469023

GoogleCoalition ESS < 30%2024-04-01

ASB-A-323469023

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-gxh7-r3qj-jmff

Open SourceCoalition ESS < 30%HIGH2024-04-17

GHSA-gxh7-r3qj-jmff

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3841

Open SourceCoalition ESS < 30%MEDIUM2024-04-17

DEBIAN-CVE-2024-3841

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3841

GoogleCoalition ESS < 30%HIGH2024-04-16

Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)

CVEs:CVE-2024-3841

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-7jw6-8f8g-469v

Open SourceCoalition ESS < 30%MEDIUM2024-04-17

GHSA-7jw6-8f8g-469v

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3844

Open SourceCoalition ESS < 30%MEDIUM2024-04-17

DEBIAN-CVE-2024-3844

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3844

GoogleCoalition ESS < 30%2024-04-16

Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)

CVEs:CVE-2024-3844

Upstream advisory

CVE-2024-3844

GoogleCoalition ESS < 30%MEDIUM2024-04-16

Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)

CVEs:CVE-2024-3844

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-29981

Open SourceCoalition ESS < 30%MEDIUM2024-04-04

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2024-29981

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2024-3067

GoogleCoalition ESS < 30%HIGH2024-04-16

The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...

CVEs:CVE-2024-3067

Affected products

ProductStatusVendorPackageEcosystem
woocommerce_google_feed_manager affected wpmarketingrobot
Upstream advisory

CVE-2024-29049

Open SourceCoalition ESS < 30%MEDIUM2024-04-04

Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability

CVEs:CVE-2024-29049

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2024-29991

Open SourceCoalition ESS < 30%MEDIUM2024-04-09

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVEs:CVE-2024-29991

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-gqmf-j3fp-9x2f

Open SourceCoalition ESS < 30%MEDIUM2024-04-17

GHSA-gqmf-j3fp-9x2f

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-3843

Open SourceCoalition ESS < 30%MEDIUM2024-04-17

DEBIAN-CVE-2024-3843

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3843

GoogleCoalition ESS < 30%MEDIUM2024-04-16

Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-3843

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-3843

GoogleCoalition ESS < 30%2024-04-16

Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-3843

Upstream advisory

CVE-2024-29986

Open SourceCoalition ESS < 30%HIGH2024-04-09

Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability

CVEs:CVE-2024-29986

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-52533

Open SourceCoalition ESS < 30%HIGH2024-04-08

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

CVEs:CVE-2023-52533

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-32145

GoogleCoalition ESS < 30%CRITICAL2024-04-15

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PineWise WP Google Analytics Events allows Reflected XSS.This issue affects WP Google Analytics Events: from n/a through 2.8.0.

CVEs:CVE-2024-32145

Affected products

ProductStatusVendorPackageEcosystem
wp_google_analytics_events affected wpgoaltracker
Upstream advisory

CVE-2023-52344

Open SourceCoalition ESS < 30%HIGH2024-04-08

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

CVEs:CVE-2023-52344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-52341

Open SourceCoalition ESS < 30%HIGH2024-04-08

In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed

CVEs:CVE-2023-52341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-52342

Open SourceCoalition ESS < 30%HIGH2024-04-08

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

CVEs:CVE-2023-52342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-52534

Open SourceCoalition ESS < 30%HIGH2024-04-08

In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed

CVEs:CVE-2023-52534

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-2310

GoogleCoalition ESS < 30%CRITICAL2024-04-26

The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ...

CVEs:CVE-2024-2310

Affected products

ProductStatusVendorPackageEcosystem
wp_google_review_slider affected ljapps
Upstream advisory

CVE-2024-29756

Open SourceCoalition ESS < 30%CRITICAL2024-04-02

In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29756

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-322896109

GoogleCoalition ESS < 30%HIGH2024-04-01

PUB-A-322896109

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-52343

Open SourceCoalition ESS < 30%HIGH2024-04-08

In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional execution privileges needed

CVEs:CVE-2023-52343

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-7019

GoogleCoalition ESS < 30%2024-04-16

Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-7019

Upstream advisory

CVE-2024-7019

GoogleCoalition ESS < 30%MEDIUM2024-04-16

Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-7019

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-7020

GoogleCoalition ESS < 30%2024-04-16

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-7020

Upstream advisory

CVE-2024-7020

GoogleCoalition ESS < 30%MEDIUM2024-04-16

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-7020

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-20044

Open SourceCoalition ESS < 30%HIGH2024-04-01

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541784; Issue ID: A...

CVEs:CVE-2024-20044

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20042

Open SourceCoalition ESS < 30%HIGH2024-04-01

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541780; Issue ID: A...

CVEs:CVE-2024-20042

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20054

GoogleCoalition ESS < 30%2024-04-01

In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.

CVEs:CVE-2024-20054

Upstream advisory

CVE-2024-20054

Open SourceCoalition ESS < 30%MEDIUM2024-04-01

In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue...

CVEs:CVE-2024-20054

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2024-20046

Open SourceCoalition ESS < 30%HIGH2024-04-01

In battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08485622; Issue...

CVEs:CVE-2024-20046

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20043

Open SourceCoalition ESS < 30%HIGH2024-04-01

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541781; Issue ID: A...

CVEs:CVE-2024-20043

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-22004

GoogleCoalition ESS < 30%CRITICAL2024-04-05

Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application

CVEs:CVE-2024-22004

Affected products

ProductStatusVendorPackageEcosystem
nest_wifi_point_firmware affected google
nest_wifi_pro_firmware affected google
nest_wifi_router_firmware affected google
Upstream advisory

CVE-2023-48426

GoogleCoalition ESS < 30%CRITICAL2024-04-05

u-boot bug that allows for u-boot shell and interrupt over UART

CVEs:CVE-2023-48426

Affected products

ProductStatusVendorPackageEcosystem
chromecast_firmware affected google
Upstream advisory

CVE-2024-31269

GoogleCoalition ESS < 30%HIGH2024-04-12

Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps.This issue affects Easy Google Maps: from n/a through 1.11.11.

CVEs:CVE-2024-31269

Affected products

ProductStatusVendorPackageEcosystem
easy_google_maps affected supsystic
Upstream advisory

CVE-2024-20845

Open SourceCoalition ESS < 30%HIGH2024-04-01

Out-of-bounds write vulnerability while releasing memory in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2024-20845

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20041

Open SourceCoalition ESS < 30%MEDIUM2024-04-01

In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541746; Issue ID: ALP...

CVEs:CVE-2024-20041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20047

Open SourceCoalition ESS < 30%HIGH2024-04-01

In battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587865; Issue ID: A...

CVEs:CVE-2024-20047

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20849

Open SourceCoalition ESS < 30%HIGH2024-04-01

Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 allows local attackers to execute arbitrary code.

CVEs:CVE-2024-20849

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20040

GoogleCoalition ESS < 30%2024-04-01

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08360153 (for MT6XXX chipsets) / WCNCR00363530 (for MT79XX chipsets); Issue ID: MSV-979.

CVEs:CVE-2024-20040

Upstream advisory

CVE-2024-20040

Open SourceCoalition ESS < 30%HIGH2024-04-01

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP...

CVEs:CVE-2024-20040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

ASB-A-323465955

GoogleCoalition ESS < 30%2024-04-01

ASB-A-323465955

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20846

Open SourceCoalition ESS < 30%HIGH2024-04-01

Out-of-bounds write vulnerability while decoding hcr of libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2024-20846

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20843

Open SourceCoalition ESS < 30%HIGH2024-04-01

Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code.

CVEs:CVE-2024-20843

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20848

Open SourceCoalition ESS < 30%HIGH2024-04-01

Improper Input Validation vulnerability in text parsing implementation of libsdffextractor prior to SMR Apr-2024 Release 1 allows local attackers to write out-of-bounds memory.

CVEs:CVE-2024-20848

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20847

Open SourceCoalition ESS < 30%MEDIUM2024-04-01

Improper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allows local attackers to read sdcard information.

CVEs:CVE-2024-20847

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-318393412

GoogleCoalition ESS < 30%2024-04-01

ASB-A-318393412

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-318393741

GoogleCoalition ESS < 30%2024-04-01

ASB-A-318393741

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-303107287

GoogleCoalition ESS < 30%2024-04-01

PUB-A-303107287

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-29741

Open SourceCoalition ESS < 30%HIGH2024-04-02

In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29741

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-283803605

GoogleCoalition ESS < 30%NONE2024-04-01

PUB-A-283803605

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-0022

Open SourceCoalition ESS < 30%MEDIUM2024-04-01

In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional ...

CVEs:CVE-2024-0022

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0027

Open SourceCoalition ESS < 30%HIGH2024-04-01

In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2024-0027

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29740

Open SourceCoalition ESS < 30%HIGH2024-04-02

In tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29740

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-315316882

GoogleCoalition ESS < 30%HIGH2024-04-01

PUB-A-315316882

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20052

GoogleCoalition ESS < 30%2024-04-01

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541761.

CVEs:CVE-2024-20052

Upstream advisory

CVE-2024-20052

Open SourceCoalition ESS < 30%MEDIUM2024-04-01

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ...

CVEs:CVE-2024-20052

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2024-20050

GoogleCoalition ESS < 30%2024-04-01

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757.

CVEs:CVE-2024-20050

Upstream advisory

CVE-2024-20050

Open SourceCoalition ESS < 30%MEDIUM2024-04-01

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ...

CVEs:CVE-2024-20050

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2024-20049

GoogleCoalition ESS < 30%2024-04-01

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ID: ALPS08541765.

CVEs:CVE-2024-20049

Upstream advisory

CVE-2024-20049

Open SourceCoalition ESS < 30%MEDIUM2024-04-01

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ...

CVEs:CVE-2024-20049

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2024-0026

Open SourceCoalition ESS < 30%HIGH2024-04-01

In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2024-0026

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29749

Open SourceCoalition ESS < 30%HIGH2024-04-02

In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29749

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-315318821

GoogleCoalition ESS < 30%HIGH2024-04-01

PUB-A-315318821

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-29753

Open SourceCoalition ESS < 30%HIGH2024-04-02

In tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29753

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29754

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29754

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-23704

Open SourceCoalition ESS < 30%HIGH2024-04-01

In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User ...

CVEs:CVE-2024-23704

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-315316499

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-315316499

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-315316911

GoogleCoalition ESS < 30%HIGH2024-04-01

PUB-A-315316911

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-29746

Open SourceCoalition ESS < 30%HIGH2024-04-02

In lpm_req_handler of lpm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29746

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29752

Open SourceCoalition ESS < 30%HIGH2024-04-02

In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29752

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-315319015

GoogleCoalition ESS < 30%HIGH2024-04-01

PUB-A-315319015

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-318345662

GoogleCoalition ESS < 30%HIGH2024-04-01

PUB-A-318345662

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-23710

Open SourceCoalition ESS < 30%HIGH2024-04-01

In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code. This could lead to local escalation of privilege with no additional exe...

CVEs:CVE-2024-23710

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20053

GoogleCoalition ESS < 30%2024-04-01

In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764.

CVEs:CVE-2024-20053

Upstream advisory

CVE-2024-20053

Open SourceCoalition ESS < 30%HIGH2024-04-01

In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID...

CVEs:CVE-2024-20053

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2024-27231

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-27231

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-315321005

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-315321005

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-52351

Open SourceCoalition ESS < 30%CRITICAL2024-04-08

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-52351

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-27232

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-27232

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29744

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29744

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29751

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29751

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-308409494

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-308409494

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-308409713

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-308409713

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-315322436

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-315322436

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-52345

Open SourceCoalition ESS < 30%HIGH2024-04-08

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed

CVEs:CVE-2023-52345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29747

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29747

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29755

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29755

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-315315914

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-315315914

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-318345650

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-318345650

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-52346

Open SourceCoalition ESS < 30%HIGH2024-04-08

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed

CVEs:CVE-2023-52346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29738

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29738

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29739

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In tmu_get_temp_lut of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29739

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29742

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29742

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29750

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29750

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29782

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29782

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-23712

Open SourceCoalition ESS < 30%HIGH2024-04-01

In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User...

CVEs:CVE-2024-23712

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-308932295

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-308932295

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-315319017

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-315319017

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-315323409

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-315323409

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-318294347

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-318294347

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-318322946

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-318322946

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-23658

Open SourceCoalition ESS < 30%CRITICAL2024-04-08

In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2024-23658

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-52348

Open SourceCoalition ESS < 30%CRITICAL2024-04-08

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-52348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29783

Open SourceCoalition ESS < 30%MEDIUM2024-04-02

In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29783

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-23713

Open SourceCoalition ESS < 30%HIGH2024-04-01

In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges ne...

CVEs:CVE-2024-23713

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-315319006

GoogleCoalition ESS < 30%MEDIUM2024-04-01

PUB-A-315319006

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-52347

Open SourceCoalition ESS < 30%CRITICAL2024-04-08

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-52347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20051

GoogleCoalition ESS < 30%2024-04-01

In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758.

CVEs:CVE-2024-20051

Upstream advisory

CVE-2024-20051

Open SourceCoalition ESS < 30%MEDIUM2024-04-01

In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758.

CVEs:CVE-2024-20051

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2023-52536

Open SourceCoalition ESS < 30%HIGH2024-04-08

In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-52536

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-52350

Open SourceCoalition ESS < 30%CRITICAL2024-04-08

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-52350

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-29757

Open SourceCoalition ESS < 30%HIGH2024-04-02

there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-29757

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-306627047

GoogleCoalition ESS < 30%NONE2024-04-01

PUB-A-306627047

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20055

Open SourceCoalition ESS < 30%MEDIUM2024-04-01

In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: ...

CVEs:CVE-2024-20055

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
yocto affected linuxfoundation
Upstream advisory

CVE-2024-20055

GoogleCoalition ESS < 30%2024-04-01

In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.

CVEs:CVE-2024-20055

Upstream advisory

CVE-2023-52535

Open SourceCoalition ESS < 30%HIGH2024-04-08

In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-52535

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.