MGASA-2024-0190
Updated chromium-browser-stable packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 32 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Updated chromium-browser-stable packages fix security vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
GHSA-p8v3-5hqq-7c5r
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-4947
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4947
CVEs:CVE-2024-4947
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4947
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4947
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Updated chromium-browser-stable packages fix security vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
GHSA-8q82-45v9-cmr9
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-4761
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4761
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4761
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2024-4761
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4761
GHSA-gg58-4q4g-xvcw
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-4671
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
CVEs:CVE-2024-4671
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4671
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4671
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4671
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2024-5274
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Updated chromium-browser-stable packages fix security vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5274
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5274
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5274
CVEs:CVE-2024-30051
Windows DWM Core Library Elevation of Privilege Vulnerability
CVEs:CVE-2024-30051
Windows DWM Core Library Elevation of Privilege Vulnerability
CVEs:CVE-2024-30051
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_21h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_11_23h2 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
Security update for SUSE Manager Client Tools
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ansible | affected | SUSE:Manager Proxy Module 4.3 | ansible | — |
| ansible | affected | openSUSE:Leap 15.5 | ansible | — |
| ansible | affected | SUSE:Manager Client Tools 15 | ansible | — |
| dracut-saltboot | affected | SUSE:Manager Client Tools for SLE Micro 5 | dracut-saltboot | — |
| dracut-saltboot | affected | openSUSE:Leap 15.5 | dracut-saltboot | — |
| dracut-saltboot | affected | SUSE:Manager Client Tools 15 | dracut-saltboot | — |
| golang-github-prometheus-promu | affected | openSUSE:Leap 15.5 | golang-github-prometheus-promu | — |
| golang-github-prometheus-promu | affected | SUSE:Linux Enterprise Module for Package Hub 15 SP5 | golang-github-prometheus-promu | — |
| grafana | affected | SUSE:Manager Client Tools 15 | grafana | — |
| mgr-daemon | affected | SUSE:Manager Client Tools 15 | mgr-daemon | — |
| POS_Image-Graphical7 | affected | openSUSE:Leap 15.5 | POS_Image-Graphical7 | — |
| POS_Image-Graphical7 | affected | SUSE:Manager Client Tools 15 | POS_Image-Graphical7 | — |
| POS_Image-JeOS7 | affected | SUSE:Manager Client Tools 15 | POS_Image-JeOS7 | — |
| POS_Image-JeOS7 | affected | openSUSE:Leap 15.5 | POS_Image-JeOS7 | — |
| spacecmd | affected | openSUSE:Leap 15.5 | spacecmd | — |
| spacecmd | affected | SUSE:Manager Client Tools 15 | spacecmd | — |
| spacewalk-client-tools | affected | SUSE:Manager Client Tools 15 | spacewalk-client-tools | — |
| spacewalk-koan | affected | SUSE:Manager Client Tools 15 | spacewalk-koan | — |
| uyuni-common-libs | affected | SUSE:Manager Client Tools 15 | uyuni-common-libs | — |
| uyuni-proxy-systemd-services | affected | SUSE:Manager Client Tools 15 | uyuni-proxy-systemd-services | — |
| uyuni-proxy-systemd-services | affected | SUSE:Manager Client Tools for SLE Micro 5 | uyuni-proxy-systemd-services | — |
| uyuni-proxy-systemd-services | affected | SUSE:Manager Proxy Module 4.3 | uyuni-proxy-systemd-services | — |
GHSA-23rw-79p3-xgcm
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2024-4058
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVEs:CVE-2024-30056
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
Security update for SUSE Manager Client Tools
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-prometheus-alertmanager | affected | SUSE:Manager Client Tools 12 | golang-github-prometheus-alertmanager | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Manager Client Tools 12 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 12 SP5 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP5 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-promu | affected | SUSE:Manager Client Tools 12 | golang-github-prometheus-promu | — |
| grafana | affected | SUSE:Manager Client Tools 12 | grafana | — |
| mgr-daemon | affected | SUSE:Manager Client Tools 12 | mgr-daemon | — |
| spacecmd | affected | SUSE:Manager Client Tools 12 | spacecmd | — |
| spacewalk-client-tools | affected | SUSE:Manager Client Tools 12 | spacewalk-client-tools | — |
| spacewalk-koan | affected | SUSE:Manager Client Tools 12 | spacewalk-koan | — |
| uyuni-common-libs | affected | SUSE:Manager Client Tools 12 | uyuni-common-libs | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
GHSA-xvp9-87cv-m4fv
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-4948
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-4948
Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4948
Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4948
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
GHSA-h2pj-pf6w-85p2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-4950
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-4950
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2024-4950
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2024-4950
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
GHSA-8mwf-wgf7-7qpx
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-5497
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-5497
Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever...
CVEs:CVE-2024-5497
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5497
Security Beta update for SUSE Manager Client Tools and Salt
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-prometheus-node_exporter | affected | SUSE:Manager Client Tools Beta for SLE Micro 5 | golang-github-prometheus-node_exporter | — |
| grafana | affected | SUSE:Manager Client Tools 15-BETA | grafana | — |
| mgr-push | affected | SUSE:Manager Client Tools 15-BETA | mgr-push | — |
| spacecmd | affected | SUSE:Manager Client Tools 15-BETA | spacecmd | — |
| uyuni-common-libs | affected | SUSE:Manager Client Tools 15-BETA | uyuni-common-libs | — |
| uyuni-tools | affected | SUSE:Manager Client Tools 15-BETA | uyuni-tools | — |
| uyuni-tools | affected | SUSE:Manager Client Tools Beta for SLE Micro 5 | uyuni-tools | — |
Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.
CVEs:CVE-2024-20865
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-20865
Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.
CVEs:CVE-2024-20866
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-20866
azure-file-csi-driver leaks service account tokens in the logs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| azurefile-csi-driver | affected | sigs.k8s.io | sigs.k8s.io/azurefile-csi-driver | — |
azure-file-csi-driver leaks service account tokens in the logs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| azurefile-csi-driver | affected | sigs.k8s.io | sigs.k8s.io/azurefile-csi-driver | — |
A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in clou...
CVEs:CVE-2024-3744
azure-file-csi-driver leaks service account tokens in the logs
CVEs:CVE-2024-3744
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| azurefile-csi-driver | affected | sigs.k8s.io | sigs.k8s.io/azurefile-csi-driver | — |
CVEs:CVE-2024-20862
Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.
CVEs:CVE-2024-20862
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.
CVEs:CVE-2024-20863
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-20863
CVEs:CVE-2024-20861
Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause memory corruption.
CVEs:CVE-2024-20861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-20857
Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.
CVEs:CVE-2024-20857
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: AL...
CVEs:CVE-2024-20021
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-20021
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issu...
CVEs:CVE-2024-20060
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-20060
CVEs:CVE-2024-20064
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...
CVEs:CVE-2024-20064
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-20056
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issu...
CVEs:CVE-2024-20059
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-20059
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0852818...
CVEs:CVE-2024-20056
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| openwrt | affected | openwrt | — | — |
| rdk-b | affected | rdkcentral | — | — |
ASB-A-327973818
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Important: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | AlmaLinux:8 | delve | — |
| golang | affected | AlmaLinux:8 | golang | — |
| golang-bin | affected | AlmaLinux:8 | golang-bin | — |
| golang-docs | affected | AlmaLinux:8 | golang-docs | — |
| golang-misc | affected | AlmaLinux:8 | golang-misc | — |
| golang-src | affected | AlmaLinux:8 | golang-src | — |
| golang-tests | affected | AlmaLinux:8 | golang-tests | — |
| go-toolset | affected | AlmaLinux:8 | go-toolset | — |
Important: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Rocky Linux:9 | golang | — |
Important: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
Privilege Escalation in Kubernetes in k8s.io/apimachinery
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| actions-runner-controller-fips | affected | chainguard | actions-runner-controller-fips | — |
| addon-resizer-fips | affected | chainguard | addon-resizer-fips | — |
| apimachinery | affected | k8s.io | k8s.io/apimachinery | — |
| argo-workflows-fips | affected | chainguard | argo-workflows-fips | — |
| aws-efs-csi-driver-fips | affected | chainguard | aws-efs-csi-driver-fips | — |
| aws-load-balancer-controller-fips | affected | chainguard | aws-load-balancer-controller-fips | — |
| azure-aad-pod-identity-mic | affected | chainguard | azure-aad-pod-identity-mic | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| cass-operator-fips | affected | chainguard | cass-operator-fips | — |
| cass-operator-fips-no-pvc-delete | affected | chainguard | cass-operator-fips-no-pvc-delete | — |
| cert-exporter | affected | wolfi | cert-exporter | — |
| cert-exporter | affected | chainguard | cert-exporter | — |
| cert-exporter-fips | affected | chainguard | cert-exporter-fips | — |
| cert-manager-webhook-pdns-fips | affected | chainguard | cert-manager-webhook-pdns-fips | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cosign-fips | affected | chainguard | cosign-fips | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| eksctl | affected | chainguard | eksctl | — |
| eksctl | affected | wolfi | eksctl | — |
| external-secrets-fips | affected | chainguard | external-secrets-fips | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| falcoctl-fips-0.4 | affected | chainguard | falcoctl-fips-0.4 | — |
| falcosidekick-fips | affected | chainguard | falcosidekick-fips | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| ghaudit | affected | chainguard | ghaudit | — |
| ghaudit | affected | wolfi | ghaudit | — |
| glab | affected | wolfi | glab | — |
| glab | affected | chainguard | glab | — |
| grafana-operator-fips | affected | chainguard | grafana-operator-fips | — |
| harbor-2.9 | affected | chainguard | harbor-2.9 | — |
| helm-fips | affected | chainguard | helm-fips | — |
| helm-fips-3 | affected | chainguard | helm-fips-3 | — |
| helm-fips-4 | affected | chainguard | helm-fips-4 | — |
| helm-operator | affected | wolfi | helm-operator | — |
| helm-operator | affected | chainguard | helm-operator | — |
| helm-operator-fips | affected | chainguard | helm-operator-fips | — |
| hubble | affected | wolfi | hubble | — |
| hubble | affected | chainguard | hubble | — |
| hubble-fips | affected | chainguard | hubble-fips | — |
| hubble-ui-backend-fips | affected | chainguard | hubble-ui-backend-fips | — |
| k8ssandra-operator-fips | affected | chainguard | k8ssandra-operator-fips | — |
| karpenter-0.35 | affected | chainguard | karpenter-0.35 | — |
| karpenter-fips-0.35 | affected | chainguard | karpenter-fips-0.35 | — |
| karpenter-fips-0.36 | affected | chainguard | karpenter-fips-0.36 | — |
| kiam | affected | chainguard | kiam | — |
| kine | affected | wolfi | kine | — |
| kine | affected | chainguard | kine | — |
| ko-fips | affected | chainguard | ko-fips | — |
| kots | affected | wolfi | kots | — |
| kots | affected | chainguard | kots | — |
| kube-bench-fips | affected | chainguard | kube-bench-fips | — |
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kube-logging-logging-operator-3.17 | affected | chainguard | kube-logging-logging-operator-3.17 | — |
| kube-logging-logging-operator-4.1 | affected | chainguard | kube-logging-logging-operator-4.1 | — |
| kube-oidc-proxy | affected | chainguard | kube-oidc-proxy | — |
| kube-rbac-proxy-fips | affected | chainguard | kube-rbac-proxy-fips | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-csi-livenessprobe-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-2.10 | — |
| kubernetes-csi-livenessprobe-fips | affected | chainguard | kubernetes-csi-livenessprobe-fips | — |
| kubernetes-csi-livenessprobe-fips-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-fips-2.10 | — |
| kubernetes-dashboard | affected | chainguard | kubernetes-dashboard | — |
| kubernetes-dashboard | affected | wolfi | kubernetes-dashboard | — |
| kubernetes-dashboard-fips | affected | chainguard | kubernetes-dashboard-fips | — |
| kubernetes-dashboard-metrics-scraper | affected | chainguard | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper | affected | wolfi | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper-fips | affected | chainguard | kubernetes-dashboard-metrics-scraper-fips | — |
| kubernetes-dns-node-cache | affected | wolfi | kubernetes-dns-node-cache | — |
| kubernetes-dns-node-cache | affected | chainguard | kubernetes-dns-node-cache | — |
| kubernetes-secret-generator | affected | chainguard | kubernetes-secret-generator | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| kube-state-metrics-fips | affected | chainguard | kube-state-metrics-fips | — |
| kubevela | affected | wolfi | kubevela | — |
| kubevela | affected | chainguard | kubevela | — |
| kubewatch | affected | wolfi | kubewatch | — |
| kubewatch | affected | chainguard | kubewatch | — |
| kwok | affected | chainguard | kwok | — |
| kwok | affected | wolfi | kwok | — |
| kyverno-policy-reporter | affected | chainguard | kyverno-policy-reporter | — |
| kyverno-policy-reporter | affected | wolfi | kyverno-policy-reporter | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| local-static-provisioner | affected | wolfi | local-static-provisioner | — |
| local-static-provisioner | affected | chainguard | local-static-provisioner | — |
| melange | affected | wolfi | melange | — |
| melange | affected | chainguard | melange | — |
| metallb-fips | affected | chainguard | metallb-fips | — |
| metrics-server-fips | affected | chainguard | metrics-server-fips | — |
| multus-cni-fips | affected | chainguard | multus-cni-fips | — |
| newrelic-infra-operator | affected | chainguard | newrelic-infra-operator | — |
| newrelic-infra-operator | affected | wolfi | newrelic-infra-operator | — |
| newrelic-nri-kube-events | affected | wolfi | newrelic-nri-kube-events | — |
| newrelic-nri-kube-events | affected | chainguard | newrelic-nri-kube-events | — |
| newrelic-nri-statsd | affected | chainguard | newrelic-nri-statsd | — |
| newrelic-nri-statsd | affected | wolfi | newrelic-nri-statsd | — |
| nfs-subdir-external-provisioner-fips | affected | chainguard | nfs-subdir-external-provisioner-fips | — |
| nodetaint | affected | wolfi | nodetaint | — |
| nodetaint | affected | chainguard | nodetaint | — |
| nri-discovery-kubernetes | affected | chainguard | nri-discovery-kubernetes | — |
| nri-discovery-kubernetes | affected | wolfi | nri-discovery-kubernetes | — |
| nri-kubernetes | affected | chainguard | nri-kubernetes | — |
| nri-kubernetes | affected | wolfi | nri-kubernetes | — |
| opentelemetry-collector-contrib | affected | wolfi | opentelemetry-collector-contrib | — |
| opentelemetry-collector-contrib | affected | chainguard | opentelemetry-collector-contrib | — |
| opentelemetry-collector-contrib-fips | affected | chainguard | opentelemetry-collector-contrib-fips | — |
| policy-controller-fips | affected | chainguard | policy-controller-fips | — |
| postgres-operator | affected | chainguard | postgres-operator | — |
| postgres-operator | affected | wolfi | postgres-operator | — |
| postgres-operator-fips | affected | chainguard | postgres-operator-fips | — |
| prometheus-2.51 | affected | chainguard | prometheus-2.51 | — |
| prometheus-adapter | affected | chainguard | prometheus-adapter | — |
| prometheus-adapter | affected | wolfi | prometheus-adapter | — |
| prometheus-adapter-0.10 | affected | chainguard | prometheus-adapter-0.10 | — |
| prometheus-adapter-fips | affected | chainguard | prometheus-adapter-fips | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-operator-fips | affected | chainguard | prometheus-operator-fips | — |
| pulumi-kubernetes-operator | affected | wolfi | pulumi-kubernetes-operator | — |
| pulumi-kubernetes-operator | affected | chainguard | pulumi-kubernetes-operator | — |
| rabbitmq-cluster-operator | affected | wolfi | rabbitmq-cluster-operator | — |
| rabbitmq-cluster-operator | affected | chainguard | rabbitmq-cluster-operator | — |
| rabbitmq-messaging-topology-operator | affected | wolfi | rabbitmq-messaging-topology-operator | — |
| rabbitmq-messaging-topology-operator | affected | chainguard | rabbitmq-messaging-topology-operator | — |
| request-1279 | affected | chainguard | request-1279 | — |
| secrets-store-csi-driver-provider-aws | affected | wolfi | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-aws | affected | chainguard | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-azure | affected | wolfi | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-azure | affected | chainguard | secrets-store-csi-driver-provider-azure | — |
| sigstore-scaffolding-fips | affected | chainguard | sigstore-scaffolding-fips | — |
| skaffold | affected | chainguard | skaffold | — |
| skaffold | affected | wolfi | skaffold | — |
| slsa-verifier | affected | wolfi | slsa-verifier | — |
| slsa-verifier | affected | chainguard | slsa-verifier | — |
| sonobuoy | affected | chainguard | sonobuoy | — |
| sonobuoy | affected | wolfi | sonobuoy | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spire-server | affected | wolfi | spire-server | — |
| spire-server | affected | chainguard | spire-server | — |
| spire-server-fips | affected | chainguard | spire-server-fips | — |
| src | affected | chainguard | src | — |
| src | affected | wolfi | src | — |
| stakater-reloader | affected | wolfi | stakater-reloader | — |
| stakater-reloader | affected | chainguard | stakater-reloader | — |
| stakater-reloader-0.0.119 | affected | chainguard | stakater-reloader-0.0.119 | — |
| stakater-reloader-0.0.128 | affected | chainguard | stakater-reloader-0.0.128 | — |
| step-issuer | affected | wolfi | step-issuer | — |
| step-issuer | affected | chainguard | step-issuer | — |
| step-issuer-fips | affected | chainguard | step-issuer-fips | — |
| stern | affected | wolfi | stern | — |
| stern | affected | chainguard | stern | — |
| tekton-chains | affected | wolfi | tekton-chains | — |
| tekton-chains | affected | chainguard | tekton-chains | — |
| tekton-chains-fips | affected | chainguard | tekton-chains-fips | — |
| terraform | affected | chainguard | terraform | — |
| terraform | affected | wolfi | terraform | — |
| thanos-fips | affected | chainguard | thanos-fips | — |
| thanos-operator | affected | wolfi | thanos-operator | — |
| thanos-operator | affected | chainguard | thanos-operator | — |
| thanos-operator-fips | affected | chainguard | thanos-operator-fips | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| tigera-operator-fips-1.29 | affected | chainguard | tigera-operator-fips-1.29 | — |
| tkn | affected | wolfi | tkn | — |
| tkn | affected | chainguard | tkn | — |
| tkn-fips | affected | chainguard | tkn-fips | — |
| trust-manager | affected | chainguard | trust-manager | — |
| trust-manager | affected | wolfi | trust-manager | — |
| trust-manager-fips | affected | chainguard | trust-manager-fips | — |
| vault-csi-provider | affected | chainguard | vault-csi-provider | — |
| vault-k8s | affected | wolfi | vault-k8s | — |
| vault-k8s | affected | chainguard | vault-k8s | — |
| vault-k8s-fips | affected | chainguard | vault-k8s-fips | — |
| velero-fips | affected | chainguard | velero-fips | — |
| velero-plugin-for-aws-fips | affected | chainguard | velero-plugin-for-aws-fips | — |
| velero-plugin-for-csi | affected | wolfi | velero-plugin-for-csi | — |
| velero-plugin-for-csi | affected | chainguard | velero-plugin-for-csi | — |
| velero-plugin-for-csi-fips | affected | chainguard | velero-plugin-for-csi-fips | — |
| vertical-pod-autoscaler-fips | affected | chainguard | vertical-pod-autoscaler-fips | — |
| volume-modifier-for-k8s | affected | wolfi | volume-modifier-for-k8s | — |
| volume-modifier-for-k8s | affected | chainguard | volume-modifier-for-k8s | — |
| volume-modifier-for-k8s-fips | affected | chainguard | volume-modifier-for-k8s-fips | — |
| wavefront-collector-for-kubernetes-1.12 | affected | chainguard | wavefront-collector-for-kubernetes-1.12 | — |
| wavefront-collector-for-kubernetes-1.13 | affected | chainguard | wavefront-collector-for-kubernetes-1.13 | — |
| zarf | affected | chainguard | zarf | — |
| zarf | affected | wolfi | zarf | — |
| zot | affected | chainguard | zot | — |
| zot | affected | wolfi | zot | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:22.03-LTS-SP3 | kubernetes | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:22.03-LTS-SP1 | kubernetes | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:22.03-LTS-SP2 | kubernetes | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:20.03-LTS-SP4 | kubernetes | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:22.03-LTS | kubernetes | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:20.03-LTS-SP1 | kubernetes | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
GHSA-r4j8-j63p-24j8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4558
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| safari | affected | apple | — | — |
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4558
CVEs:CVE-2024-4558
DEBIAN-CVE-2024-4558
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| webkit2gtk | affected | Debian:11 | webkit2gtk | — |
| webkit2gtk | affected | Debian:12 | webkit2gtk | — |
| webkit2gtk | affected | Debian:13 | webkit2gtk | — |
| webkit2gtk | affected | Debian:14 | webkit2gtk | — |
| wpewebkit | affected | Debian:11 | wpewebkit | — |
| wpewebkit | affected | Debian:12 | wpewebkit | — |
| wpewebkit | affected | Debian:13 | wpewebkit | — |
| wpewebkit | affected | Debian:14 | wpewebkit | — |
DEBIAN-CVE-2024-3727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-containers-image | affected | Debian:11 | golang-github-containers-image | — |
| golang-github-containers-image | affected | Debian:12 | golang-github-containers-image | — |
| golang-github-containers-image | affected | Debian:13 | golang-github-containers-image | — |
| golang-github-containers-image | affected | Debian:14 | golang-github-containers-image | — |
GHSA-7fwm-5rwh-hfg5
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-4559
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-4559
Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4559
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4559
In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
CVEs:CVE-2024-23709
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-23709
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| traefik/traefik | affected | github.com | github.com/traefik/traefik | — |
| traefik/traefik/v2 | affected | github.com | github.com/traefik/traefik/v2 | — |
| traefik/traefik/v3 | affected | github.com | github.com/traefik/traefik/v3 | — |
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| github.com/golang/go | affected | go | — | — |
| github.com/traefik/traefik | affected | Go | github.com/traefik/traefik | — |
| github.com/traefik/traefik/v2 | affected | Go | github.com/traefik/traefik/v2 | — |
| github.com/traefik/traefik/v3 | affected | Go | github.com/traefik/traefik/v3 | — |
| go | affected | go | — | — |
| net/dns | affected | go | — | — |
| traefik | affected | chainguard | traefik | — |
| traefik | affected | wolfi | traefik | — |
| traefik-fips | affected | chainguard | traefik-fips | — |
| traefik/traefik | affected | github.com | github.com/traefik/traefik | — |
| traefik/traefik | affected | github.com | github.com/traefik/traefik | — |
| traefik/traefik | affected | github.com | — | — |
| traefik/traefik/v2 | affected | github.com | github.com/traefik/traefik/v2 | — |
| traefik/traefik/v2 | affected | github.com | github.com/traefik/traefik/v2 | — |
| traefik/traefik/v3 | affected | github.com | github.com/traefik/traefik/v3 | — |
| traefik/traefik/v3 | affected | github.com | github.com/traefik/traefik/v3 | — |
Arbitrary code execution during build on Darwin in cmd/go
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Bitnami | golang | — |
GHSA-5fq7-4mxc-535h
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | wolfi | aactl | — |
| aactl | affected | chainguard | aactl | — |
| actions-runner-controller-fips | affected | chainguard | actions-runner-controller-fips | — |
| addon-resizer-fips | affected | chainguard | addon-resizer-fips | — |
| argo-cd-2.9 | affected | chainguard | argo-cd-2.9 | — |
| argo-cd-2.9 | affected | wolfi | argo-cd-2.9 | — |
| argo-cd-fips-2.10 | affected | chainguard | argo-cd-fips-2.10 | — |
| argo-cd-fips-2.8 | affected | chainguard | argo-cd-fips-2.8 | — |
| argo-cd-fips-2.9 | affected | chainguard | argo-cd-fips-2.9 | — |
| argo-workflows | affected | chainguard | argo-workflows | — |
| argo-workflows | affected | wolfi | argo-workflows | — |
| argo-workflows-fips | affected | chainguard | argo-workflows-fips | — |
| atlantis | affected | wolfi | atlantis | — |
| atlantis | affected | chainguard | atlantis | — |
| atlantis-fips | affected | chainguard | atlantis-fips | — |
| aws-ebs-csi-driver | affected | wolfi | aws-ebs-csi-driver | — |
| aws-ebs-csi-driver | affected | chainguard | aws-ebs-csi-driver | — |
| aws-ebs-csi-driver-1.18 | affected | chainguard | aws-ebs-csi-driver-1.18 | — |
| aws-ebs-csi-driver-1.19 | affected | chainguard | aws-ebs-csi-driver-1.19 | — |
| aws-ebs-csi-driver-fips | affected | chainguard | aws-ebs-csi-driver-fips | — |
| aws-efs-csi-driver | affected | wolfi | aws-efs-csi-driver | — |
| aws-efs-csi-driver | affected | chainguard | aws-efs-csi-driver | — |
| aws-efs-csi-driver-fips | affected | chainguard | aws-efs-csi-driver-fips | — |
| aws-efs-csi-driver-fips-1.6 | affected | chainguard | aws-efs-csi-driver-fips-1.6 | — |
| aws-flb-cloudwatch-fips | affected | chainguard | aws-flb-cloudwatch-fips | — |
| aws-flb-firehose-fips | affected | chainguard | aws-flb-firehose-fips | — |
| aws-flb-kinesis-fips | affected | chainguard | aws-flb-kinesis-fips | — |
| aws-load-balancer-controller-2.4.5 | affected | chainguard | aws-load-balancer-controller-2.4.5 | — |
| aws-load-balancer-controller-2.5 | affected | chainguard | aws-load-balancer-controller-2.5 | — |
| aws-load-balancer-controller-fips | affected | chainguard | aws-load-balancer-controller-fips | — |
| azure-aad-pod-identity-mic | affected | chainguard | azure-aad-pod-identity-mic | — |
| bank-vaults | affected | wolfi | bank-vaults | — |
| bank-vaults | affected | chainguard | bank-vaults | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| bom | affected | chainguard | bom | — |
| bom | affected | wolfi | bom | — |
| boring-registry | affected | wolfi | boring-registry | — |
| boring-registry | affected | chainguard | boring-registry | — |
| boring-registry-fips | affected | chainguard | boring-registry-fips | — |
| buildkitd | affected | chainguard | buildkitd | — |
| buildkitd | affected | wolfi | buildkitd | — |
| caddy | affected | wolfi | caddy | — |
| caddy | affected | chainguard | caddy | — |
| caddy-fips | affected | chainguard | caddy-fips | — |
| cadvisor | affected | wolfi | cadvisor | — |
| cadvisor | affected | chainguard | cadvisor | — |
| cadvisor-fips | affected | chainguard | cadvisor-fips | — |
| calico-fips | affected | chainguard | calico-fips | — |
| calico-fips-3.25 | affected | chainguard | calico-fips-3.25 | — |
| capslock | affected | chainguard | capslock | — |
| capslock | affected | wolfi | capslock | — |
| cass-operator-fips | affected | chainguard | cass-operator-fips | — |
| cass-operator-fips-no-pvc-delete | affected | chainguard | cass-operator-fips-no-pvc-delete | — |
| cert-exporter | affected | wolfi | cert-exporter | — |
| cert-exporter | affected | chainguard | cert-exporter | — |
| cert-exporter-fips | affected | chainguard | cert-exporter-fips | — |
| certificate-transparency | affected | wolfi | certificate-transparency | — |
| certificate-transparency | affected | chainguard | certificate-transparency | — |
| certificate-transparency-fips | affected | chainguard | certificate-transparency-fips | — |
| cert-manager-1.12 | affected | wolfi | cert-manager-1.12 | — |
| cert-manager-1.12 | affected | chainguard | cert-manager-1.12 | — |
| cert-manager-1.14 | affected | chainguard | cert-manager-1.14 | — |
| cert-manager-1.14 | affected | wolfi | cert-manager-1.14 | — |
| cert-manager-fips-1.12 | affected | chainguard | cert-manager-fips-1.12 | — |
| cert-manager-fips-1.13 | affected | chainguard | cert-manager-fips-1.13 | — |
| cert-manager-fips-1.14 | affected | chainguard | cert-manager-fips-1.14 | — |
| cert-manager-webhook-pdns | affected | wolfi | cert-manager-webhook-pdns | — |
| cert-manager-webhook-pdns | affected | chainguard | cert-manager-webhook-pdns | — |
| cert-manager-webhook-pdns-fips | affected | chainguard | cert-manager-webhook-pdns-fips | — |
| cfssl | affected | wolfi | cfssl | — |
| cfssl | affected | chainguard | cfssl | — |
| chainctl | affected | chainguard | chainctl | — |
| chartmuseum | affected | wolfi | chartmuseum | — |
| chartmuseum | affected | chainguard | chartmuseum | — |
| cilium-1.14 | affected | chainguard | cilium-1.14 | — |
| cilium-1.14 | affected | wolfi | cilium-1.14 | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cilium-fips-1.14 | affected | chainguard | cilium-fips-1.14 | — |
| cilium-fips-1.15 | affected | chainguard | cilium-fips-1.15 | — |
| cloudflared | affected | chainguard | cloudflared | — |
| cloudflared | affected | wolfi | cloudflared | — |
| clusterctl | affected | wolfi | clusterctl | — |
| clusterctl | affected | chainguard | clusterctl | — |
| configmap-reload | affected | chainguard | configmap-reload | — |
| configmap-reload | affected | wolfi | configmap-reload | — |
| configmap-reload-fips | affected | chainguard | configmap-reload-fips | — |
| configmap-reload-fips-0.11 | affected | chainguard | configmap-reload-fips-0.11 | — |
| confluent-common-docker | affected | wolfi | confluent-common-docker | — |
| confluent-common-docker | affected | chainguard | confluent-common-docker | — |
| conftest | affected | wolfi | conftest | — |
| conftest | affected | chainguard | conftest | — |
| conftest-fips | affected | chainguard | conftest-fips | — |
| containerd | affected | wolfi | containerd | — |
| containerd | affected | chainguard | containerd | — |
| coredns | affected | chainguard | coredns | — |
| coredns | affected | wolfi | coredns | — |
| coredns-fips | affected | chainguard | coredns-fips | — |
| cortex | affected | chainguard | cortex | — |
| cortex | affected | wolfi | cortex | — |
| cortex-fips | affected | chainguard | cortex-fips | — |
| cosign | affected | wolfi | cosign | — |
| cosign | affected | chainguard | cosign | — |
| cosign-fips | affected | chainguard | cosign-fips | — |
| cosign-fips | affected | wolfi | cosign-fips | — |
| crane | affected | chainguard | crane | — |
| crane | affected | wolfi | crane | — |
| cri-tools | affected | wolfi | cri-tools | — |
| cri-tools | affected | chainguard | cri-tools | — |
| croc | affected | chainguard | croc | — |
| croc | affected | wolfi | croc | — |
| crossplane | affected | wolfi | crossplane | — |
| crossplane | affected | chainguard | crossplane | — |
| crossplane-provider-aws | affected | chainguard | crossplane-provider-aws | — |
| crossplane-provider-aws | affected | wolfi | crossplane-provider-aws | — |
| crossplane-provider-azure | affected | chainguard | crossplane-provider-azure | — |
| crossplane-provider-azure | affected | wolfi | crossplane-provider-azure | — |
| crossplane-provider-gcp | affected | chainguard | crossplane-provider-gcp | — |
| crossplane-provider-gcp | affected | wolfi | crossplane-provider-gcp | — |
| ctop | affected | wolfi | ctop | — |
| ctop | affected | chainguard | ctop | — |
| cue | affected | chainguard | cue | — |
| cue | affected | wolfi | cue | — |
| cue-fips | affected | chainguard | cue-fips | — |
| dask-gateway | affected | wolfi | dask-gateway | — |
| dask-gateway | affected | chainguard | dask-gateway | — |
| datadog-agent-fips | affected | chainguard | datadog-agent-fips | — |
| delve | affected | wolfi | delve | — |
| delve | affected | chainguard | delve | — |
| dex | affected | wolfi | dex | — |
| dex | affected | chainguard | dex | — |
| dex-fips | affected | chainguard | dex-fips | — |
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| dgraph | affected | wolfi | dgraph | — |
| dgraph | affected | chainguard | dgraph | — |
| direnv | affected | chainguard | direnv | — |
| direnv | affected | wolfi | direnv | — |
| dive | affected | chainguard | dive | — |
| dive | affected | wolfi | dive | — |
| docker-compose | affected | wolfi | docker-compose | — |
| docker-compose | affected | chainguard | docker-compose | — |
| docker-credential-acr-env | affected | wolfi | docker-credential-acr-env | — |
| docker-credential-acr-env | affected | chainguard | docker-credential-acr-env | — |
| docker-credential-ecr-login | affected | chainguard | docker-credential-ecr-login | — |
| docker-credential-ecr-login | affected | wolfi | docker-credential-ecr-login | — |
| docker-credential-gcr | affected | wolfi | docker-credential-gcr | — |
| docker-credential-gcr | affected | chainguard | docker-credential-gcr | — |
| dockerize | affected | chainguard | dockerize | — |
| dockerize | affected | wolfi | dockerize | — |
| dockerize-fips | affected | chainguard | dockerize-fips | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| eck-operator | affected | chainguard | eck-operator | — |
| eksctl | affected | wolfi | eksctl | — |
| eksctl | affected | chainguard | eksctl | — |
| etcd-3.4 | affected | chainguard | etcd-3.4 | — |
| etcd-3.5 | affected | chainguard | etcd-3.5 | — |
| etcd-3.5 | affected | wolfi | etcd-3.5 | — |
| etcd-fips-3.4 | affected | chainguard | etcd-fips-3.4 | — |
| etcd-fips-3.5 | affected | chainguard | etcd-fips-3.5 | — |
| external-dns | affected | chainguard | external-dns | — |
| external-dns | affected | wolfi | external-dns | — |
| external-dns-fips | affected | chainguard | external-dns-fips | — |
| external-secrets-0.7 | affected | chainguard | external-secrets-0.7 | — |
| external-secrets-fips | affected | chainguard | external-secrets-fips | — |
| external-secrets-operator | affected | wolfi | external-secrets-operator | — |
| external-secrets-operator | affected | chainguard | external-secrets-operator | — |
| extism | affected | chainguard | extism | — |
| extism | affected | wolfi | extism | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| falcoctl-fips-0.4 | affected | chainguard | falcoctl-fips-0.4 | — |
| falcosidekick | affected | chainguard | falcosidekick | — |
| falcosidekick | affected | wolfi | falcosidekick | — |
| falcosidekick-fips | affected | chainguard | falcosidekick-fips | — |
| ferretdb | affected | wolfi | ferretdb | — |
| ferretdb | affected | chainguard | ferretdb | — |
| filebeat-7.17 | affected | chainguard | filebeat-7.17 | — |
| filebeat-7.17-fips | affected | chainguard | filebeat-7.17-fips | — |
| filebeat-fips | affected | chainguard | filebeat-fips | — |
| flannel | affected | wolfi | flannel | — |
| flannel | affected | chainguard | flannel | — |
| flux-image-reflector-controller | affected | chainguard | flux-image-reflector-controller | — |
| flux-image-reflector-controller | affected | wolfi | flux-image-reflector-controller | — |
| flux-kustomize-controller | affected | chainguard | flux-kustomize-controller | — |
| flux-kustomize-controller | affected | wolfi | flux-kustomize-controller | — |
| flux-notification-controller | affected | wolfi | flux-notification-controller | — |
| flux-notification-controller | affected | chainguard | flux-notification-controller | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flyte | affected | wolfi | flyte | — |
| flyte | affected | chainguard | flyte | — |
| frp | affected | chainguard | frp | — |
| frp | affected | wolfi | frp | — |
| fulcio | affected | wolfi | fulcio | — |
| fulcio | affected | chainguard | fulcio | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| fuse-overlayfs-snapshotter | affected | chainguard | fuse-overlayfs-snapshotter | — |
| fuse-overlayfs-snapshotter | affected | wolfi | fuse-overlayfs-snapshotter | — |
| ghaudit | affected | chainguard | ghaudit | — |
| ghaudit | affected | wolfi | ghaudit | — |
| gitlab-pages | affected | chainguard | gitlab-pages | — |
| gitlab-pages | affected | wolfi | gitlab-pages | — |
| gitlab-rails-ee-17.0 | affected | chainguard | gitlab-rails-ee-17.0 | — |
| gitlab-rails-ee-17.3 | affected | chainguard | gitlab-rails-ee-17.3 | — |
| gitlab-rails-ee-fips-17.0 | affected | chainguard | gitlab-rails-ee-fips-17.0 | — |
| gitlab-rails-ee-fips-17.1 | affected | chainguard | gitlab-rails-ee-fips-17.1 | — |
| gitlab-runner | affected | wolfi | gitlab-runner | — |
| gitlab-runner | affected | chainguard | gitlab-runner | — |
| gitleaks | affected | chainguard | gitleaks | — |
| gitleaks | affected | wolfi | gitleaks | — |
| git-lfs | affected | wolfi | git-lfs | — |
| git-lfs | affected | chainguard | git-lfs | — |
| gitness | affected | wolfi | gitness | — |
| gitness | affected | chainguard | gitness | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| glab | affected | chainguard | glab | — |
| glab | affected | wolfi | glab | — |
| go-1.21 | affected | wolfi | go-1.21 | — |
| go-1.21 | affected | chainguard | go-1.21 | — |
| go-1.22 | affected | wolfi | go-1.22 | — |
| go-1.22 | affected | chainguard | go-1.22 | — |
| go-bindata | affected | chainguard | go-bindata | — |
| go-bindata | affected | wolfi | go-bindata | — |
| gobump | affected | chainguard | gobump | — |
| gobump | affected | wolfi | gobump | — |
| go-fips-1.21 | affected | wolfi | go-fips-1.21 | — |
| go-fips-1.21 | affected | chainguard | go-fips-1.21 | — |
| go-ipfs-fips | affected | chainguard | go-ipfs-fips | — |
| golangci-lint | affected | wolfi | golangci-lint | — |
| golangci-lint | affected | chainguard | golangci-lint | — |
| go-licenses | affected | wolfi | go-licenses | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-md2man | affected | chainguard | go-md2man | — |
| go-md2man | affected | wolfi | go-md2man | — |
| gomplate | affected | wolfi | gomplate | — |
| gomplate | affected | chainguard | gomplate | — |
| gops | affected | chainguard | gops | — |
| gops | affected | wolfi | gops | — |
| gostatsd | affected | chainguard | gostatsd | — |
| gostatsd | affected | wolfi | gostatsd | — |
| gosu | affected | wolfi | gosu | — |
| gosu | affected | chainguard | gosu | — |
| gotenberg | affected | chainguard | gotenberg | — |
| govulncheck | affected | chainguard | govulncheck | — |
| govulncheck | affected | wolfi | govulncheck | — |
| gpu-operator | affected | chainguard | gpu-operator | — |
| grafana-agent-operator | affected | chainguard | grafana-agent-operator | — |
| grafana-agent-operator | affected | wolfi | grafana-agent-operator | — |
| grafana-operator | affected | chainguard | grafana-operator | — |
| grafana-operator | affected | wolfi | grafana-operator | — |
| grafana-rollout-operator-0.14 | affected | chainguard | grafana-rollout-operator-0.14 | — |
| grafana-rollout-operator-0.14 | affected | wolfi | grafana-rollout-operator-0.14 | — |
| grpcurl | affected | chainguard | grpcurl | — |
| grpcurl | affected | wolfi | grpcurl | — |
| guac | affected | chainguard | guac | — |
| guac | affected | wolfi | guac | — |
| harbor-2.10 | affected | chainguard | harbor-2.10 | — |
| harbor-2.10 | affected | wolfi | harbor-2.10 | — |
| harbor-2.8 | affected | chainguard | harbor-2.8 | — |
| harbor-2.9 | affected | chainguard | harbor-2.9 | — |
| harbor-cli | affected | chainguard | harbor-cli | — |
| harbor-cli | affected | wolfi | harbor-cli | — |
| harbor-fips-2.10 | affected | chainguard | harbor-fips-2.10 | — |
| harbor-fips-2.8 | affected | chainguard | harbor-fips-2.8 | — |
| harbor-fips-2.9 | affected | chainguard | harbor-fips-2.9 | — |
| harbor-registry | affected | chainguard | harbor-registry | — |
| harbor-registry | affected | wolfi | harbor-registry | — |
| harbor-registry-fips | affected | chainguard | harbor-registry-fips | — |
| harbor-scanner-trivy | affected | chainguard | harbor-scanner-trivy | — |
| harbor-scanner-trivy | affected | wolfi | harbor-scanner-trivy | — |
| harbor-scanner-trivy-fips | affected | chainguard | harbor-scanner-trivy-fips | — |
| hcloud | affected | wolfi | hcloud | — |
| hcloud | affected | chainguard | hcloud | — |
| hello-world-golang | affected | chainguard | hello-world-golang | — |
| hello-world-golang | affected | wolfi | hello-world-golang | — |
| helm | affected | wolfi | helm | — |
| helm | affected | chainguard | helm | — |
| helm-3 | affected | chainguard | helm-3 | — |
| helm-3 | affected | wolfi | helm-3 | — |
| helm-fips | affected | chainguard | helm-fips | — |
| helm-fips-3 | affected | chainguard | helm-fips-3 | — |
| helm-fips-4 | affected | chainguard | helm-fips-4 | — |
| helm-operator | affected | chainguard | helm-operator | — |
| helm-operator | affected | wolfi | helm-operator | — |
| helm-operator-fips | affected | chainguard | helm-operator-fips | — |
| helm-push | affected | wolfi | helm-push | — |
| helm-push | affected | chainguard | helm-push | — |
| hey | affected | wolfi | hey | — |
| hey | affected | chainguard | hey | — |
| http-echo | affected | wolfi | http-echo | — |
| http-echo | affected | chainguard | http-echo | — |
| hubble-ui | affected | chainguard | hubble-ui | — |
| hubble-ui | affected | wolfi | hubble-ui | — |
| hubble-ui-backend-fips | affected | chainguard | hubble-ui-backend-fips | — |
| influx | affected | wolfi | influx | — |
| influx | affected | chainguard | influx | — |
| influxd | affected | chainguard | influxd | — |
| influxd | affected | wolfi | influxd | — |
| ipfs | affected | chainguard | ipfs | — |
| ipfs | affected | wolfi | ipfs | — |
| ip-masq-agent | affected | wolfi | ip-masq-agent | — |
| ip-masq-agent | affected | chainguard | ip-masq-agent | — |
| istio-operator-1.20 | affected | chainguard | istio-operator-1.20 | — |
| istio-operator-1.20 | affected | wolfi | istio-operator-1.20 | — |
| istio-operator-1.21 | affected | wolfi | istio-operator-1.21 | — |
| istio-operator-1.21 | affected | chainguard | istio-operator-1.21 | — |
| istio-operator-fips-1.19 | affected | chainguard | istio-operator-fips-1.19 | — |
| jitsucom-bulker | affected | wolfi | jitsucom-bulker | — |
| jitsucom-bulker | affected | chainguard | jitsucom-bulker | — |
| jsonnet-bundler | affected | chainguard | jsonnet-bundler | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| k9s | affected | chainguard | k9s | — |
| k9s | affected | wolfi | k9s | — |
| kaf | affected | wolfi | kaf | — |
| kaf | affected | chainguard | kaf | — |
| kafka_exporter | affected | wolfi | kafka_exporter | — |
| kafka_exporter | affected | chainguard | kafka_exporter | — |
| karpenter | affected | wolfi | karpenter | — |
| karpenter | affected | chainguard | karpenter | — |
| karpenter-0.23 | affected | chainguard | karpenter-0.23 | — |
| karpenter-0.35 | affected | chainguard | karpenter-0.35 | — |
| karpenter-fips-0.35 | affected | chainguard | karpenter-fips-0.35 | — |
| karpenter-fips-0.36 | affected | chainguard | karpenter-fips-0.36 | — |
| keda-fips | affected | chainguard | keda-fips | — |
| kind | affected | wolfi | kind | — |
| kind | affected | chainguard | kind | — |
| ko | affected | chainguard | ko | — |
| ko | affected | wolfi | ko | — |
| ko-fips | affected | chainguard | ko-fips | — |
| ko-fips | affected | wolfi | ko-fips | — |
| kpt | affected | chainguard | kpt | — |
| kpt | affected | wolfi | kpt | — |
| ksops | affected | wolfi | ksops | — |
| ksops | affected | chainguard | ksops | — |
| kubeadm-bootstrap-controller | affected | wolfi | kubeadm-bootstrap-controller | — |
| kubeadm-bootstrap-controller | affected | chainguard | kubeadm-bootstrap-controller | — |
| kube-bench | affected | chainguard | kube-bench | — |
| kube-bench | affected | wolfi | kube-bench | — |
| kube-bench-fips | affected | chainguard | kube-bench-fips | — |
| kubebuilder | affected | wolfi | kubebuilder | — |
| kubebuilder | affected | chainguard | kubebuilder | — |
| kubecolor | affected | wolfi | kubecolor | — |
| kubecolor | affected | chainguard | kubecolor | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kube-oidc-proxy | affected | chainguard | kube-oidc-proxy | — |
| kubernetes-1.27 | affected | wolfi | kubernetes-1.27 | — |
| kubernetes-1.27 | affected | chainguard | kubernetes-1.27 | — |
| kubernetes-1.28 | affected | wolfi | kubernetes-1.28 | — |
| kubernetes-1.28 | affected | chainguard | kubernetes-1.28 | — |
| kubernetes-1.29 | affected | wolfi | kubernetes-1.29 | — |
| kubernetes-1.29 | affected | chainguard | kubernetes-1.29 | — |
| kubernetes-csi-driver-hostpath | affected | wolfi | kubernetes-csi-driver-hostpath | — |
| kubernetes-csi-driver-hostpath | affected | chainguard | kubernetes-csi-driver-hostpath | — |
| kubernetes-csi-external-attacher-4.3 | affected | chainguard | kubernetes-csi-external-attacher-4.3 | — |
| kubernetes-csi-external-attacher-4.3 | affected | wolfi | kubernetes-csi-external-attacher-4.3 | — |
| kubernetes-csi-external-attacher-4.4 | affected | wolfi | kubernetes-csi-external-attacher-4.4 | — |
| kubernetes-csi-external-attacher-4.4 | affected | chainguard | kubernetes-csi-external-attacher-4.4 | — |
| kubernetes-csi-external-attacher-fips-4.3 | affected | chainguard | kubernetes-csi-external-attacher-fips-4.3 | — |
| kubernetes-csi-external-attacher-fips-4.4 | affected | chainguard | kubernetes-csi-external-attacher-fips-4.4 | — |
| kubernetes-csi-external-provisioner | affected | chainguard | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-external-provisioner | affected | wolfi | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-external-resizer-1.10 | affected | wolfi | kubernetes-csi-external-resizer-1.10 | — |
| kubernetes-csi-external-resizer-1.10 | affected | chainguard | kubernetes-csi-external-resizer-1.10 | — |
| kubernetes-csi-external-resizer-1.8 | affected | chainguard | kubernetes-csi-external-resizer-1.8 | — |
| kubernetes-csi-external-resizer-1.9 | affected | chainguard | kubernetes-csi-external-resizer-1.9 | — |
| kubernetes-csi-external-resizer-fips-1.10 | affected | chainguard | kubernetes-csi-external-resizer-fips-1.10 | — |
| kubernetes-csi-external-resizer-fips-1.8 | affected | chainguard | kubernetes-csi-external-resizer-fips-1.8 | — |
| kubernetes-csi-external-resizer-fips-1.9 | affected | chainguard | kubernetes-csi-external-resizer-fips-1.9 | — |
| kubernetes-csi-external-snapshotter | affected | wolfi | kubernetes-csi-external-snapshotter | — |
| kubernetes-csi-external-snapshotter | affected | chainguard | kubernetes-csi-external-snapshotter | — |
| kubernetes-csi-external-snapshotter-6.0 | affected | chainguard | kubernetes-csi-external-snapshotter-6.0 | — |
| kubernetes-csi-livenessprobe | affected | wolfi | kubernetes-csi-livenessprobe | — |
| kubernetes-csi-livenessprobe | affected | chainguard | kubernetes-csi-livenessprobe | — |
| kubernetes-csi-livenessprobe-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-2.10 | — |
| kubernetes-csi-livenessprobe-fips | affected | chainguard | kubernetes-csi-livenessprobe-fips | — |
| kubernetes-csi-livenessprobe-fips-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-fips-2.10 | — |
| kubernetes-dashboard | affected | chainguard | kubernetes-dashboard | — |
| kubernetes-dashboard | affected | wolfi | kubernetes-dashboard | — |
| kubernetes-dashboard-fips | affected | chainguard | kubernetes-dashboard-fips | — |
| kubernetes-dashboard-metrics-scraper | affected | chainguard | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper | affected | wolfi | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper-fips | affected | chainguard | kubernetes-dashboard-metrics-scraper-fips | — |
| kubernetes-dns-node-cache | affected | chainguard | kubernetes-dns-node-cache | — |
| kubernetes-dns-node-cache | affected | wolfi | kubernetes-dns-node-cache | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
| kubernetes-fips-1.27 | affected | chainguard | kubernetes-fips-1.27 | — |
| kubernetes-fips-1.28 | affected | chainguard | kubernetes-fips-1.28 | — |
| kubernetes-fips-1.29 | affected | chainguard | kubernetes-fips-1.29 | — |
| kubernetes-ingress-defaultbackend | affected | chainguard | kubernetes-ingress-defaultbackend | — |
| kubernetes-ingress-defaultbackend | affected | wolfi | kubernetes-ingress-defaultbackend | — |
| kubescape | affected | wolfi | kubescape | — |
| kubescape | affected | chainguard | kubescape | — |
| kube-state-metrics | affected | chainguard | kube-state-metrics | — |
| kube-state-metrics | affected | wolfi | kube-state-metrics | — |
| kube-state-metrics-2.2.0 | affected | chainguard | kube-state-metrics-2.2.0 | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| kube-state-metrics-fips | affected | chainguard | kube-state-metrics-fips | — |
| kubewatch | affected | chainguard | kubewatch | — |
| kubewatch | affected | wolfi | kubewatch | — |
| kustomize | affected | chainguard | kustomize | — |
| kustomize | affected | wolfi | kustomize | — |
| kwok | affected | chainguard | kwok | — |
| kwok | affected | wolfi | kwok | — |
| kyverno | affected | chainguard | kyverno | — |
| kyverno | affected | wolfi | kyverno | — |
| kyverno-policy-reporter-kyverno-plugin | affected | wolfi | kyverno-policy-reporter-kyverno-plugin | — |
| kyverno-policy-reporter-kyverno-plugin | affected | chainguard | kyverno-policy-reporter-kyverno-plugin | — |
| kyverno-policy-reporter-ui | affected | chainguard | kyverno-policy-reporter-ui | — |
| kyverno-policy-reporter-ui | affected | wolfi | kyverno-policy-reporter-ui | — |
| lazygit | affected | wolfi | lazygit | — |
| lazygit | affected | chainguard | lazygit | — |
| libnvidia-container | affected | wolfi | libnvidia-container | — |
| libnvidia-container | affected | chainguard | libnvidia-container | — |
| litefs | affected | chainguard | litefs | — |
| litefs | affected | wolfi | litefs | — |
| litestream | affected | wolfi | litestream | — |
| litestream | affected | chainguard | litestream | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| local-static-provisioner | affected | chainguard | local-static-provisioner | — |
| local-static-provisioner | affected | wolfi | local-static-provisioner | — |
| logstash | affected | chainguard | logstash | — |
| logstash | affected | wolfi | logstash | — |
| logstash-exporter | affected | wolfi | logstash-exporter | — |
| logstash-exporter | affected | chainguard | logstash-exporter | — |
| logstash-exporter-fips | affected | chainguard | logstash-exporter-fips | — |
| loki | affected | wolfi | loki | — |
| loki | affected | chainguard | loki | — |
| mage | affected | chainguard | mage | — |
| mage | affected | wolfi | mage | — |
| mc | affected | wolfi | mc | — |
| mc | affected | chainguard | mc | — |
| mc-fips | affected | chainguard | mc-fips | — |
| melange | affected | chainguard | melange | — |
| melange | affected | wolfi | melange | — |
| metacontroller | affected | wolfi | metacontroller | — |
| metacontroller | affected | chainguard | metacontroller | — |
| metrics-server | affected | chainguard | metrics-server | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server-fips | affected | chainguard | metrics-server-fips | — |
| mkcert | affected | chainguard | mkcert | — |
| mkcert | affected | wolfi | mkcert | — |
| mockery | affected | wolfi | mockery | — |
| mockery | affected | chainguard | mockery | — |
| mods | affected | wolfi | mods | — |
| mods | affected | chainguard | mods | — |
| mongo-tools | affected | wolfi | mongo-tools | — |
| mongo-tools | affected | chainguard | mongo-tools | — |
| multus-cni | affected | wolfi | multus-cni | — |
| multus-cni | affected | chainguard | multus-cni | — |
| multus-cni-fips | affected | chainguard | multus-cni-fips | — |
| nats-server | affected | wolfi | nats-server | — |
| nats-server | affected | chainguard | nats-server | — |
| neuvector-scanner | affected | chainguard | neuvector-scanner | — |
| neuvector-scanner | affected | wolfi | neuvector-scanner | — |
| newrelic-fluent-bit-output | affected | wolfi | newrelic-fluent-bit-output | — |
| newrelic-fluent-bit-output | affected | chainguard | newrelic-fluent-bit-output | — |
| newrelic-infra-operator | affected | wolfi | newrelic-infra-operator | — |
| newrelic-infra-operator | affected | chainguard | newrelic-infra-operator | — |
| newrelic-infrastructure-agent-1.43 | affected | chainguard | newrelic-infrastructure-agent-1.43 | — |
| newrelic-nri-kube-events-1.9 | affected | chainguard | newrelic-nri-kube-events-1.9 | — |
| newrelic-nri-statsd | affected | chainguard | newrelic-nri-statsd | — |
| newrelic-nri-statsd | affected | wolfi | newrelic-nri-statsd | — |
| newrelic-prometheus-configurator | affected | chainguard | newrelic-prometheus-configurator | — |
| newrelic-prometheus-configurator | affected | wolfi | newrelic-prometheus-configurator | — |
| nfs-subdir-external-provisioner | affected | wolfi | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner | affected | chainguard | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner-fips | affected | chainguard | nfs-subdir-external-provisioner-fips | — |
| node-feature-discovery-0.14 | affected | chainguard | node-feature-discovery-0.14 | — |
| node-feature-discovery-0.15 | affected | chainguard | node-feature-discovery-0.15 | — |
| node-feature-discovery-0.15 | affected | wolfi | node-feature-discovery-0.15 | — |
| nri-prometheus | affected | wolfi | nri-prometheus | — |
| nri-prometheus | affected | chainguard | nri-prometheus | — |
| nvidia-container-toolkit | affected | chainguard | nvidia-container-toolkit | — |
| nvidia-container-toolkit | affected | wolfi | nvidia-container-toolkit | — |
| oauth2-proxy | affected | chainguard | oauth2-proxy | — |
| oauth2-proxy | affected | wolfi | oauth2-proxy | — |
| opa | affected | wolfi | opa | — |
| opa | affected | chainguard | opa | — |
| opentelemetry-collector-contrib-fips | affected | chainguard | opentelemetry-collector-contrib-fips | — |
| opentelemetry-collector-fips | affected | chainguard | opentelemetry-collector-fips | — |
| oras | affected | wolfi | oras | — |
| oras | affected | chainguard | oras | — |
| osv-scanner | affected | chainguard | osv-scanner | — |
| osv-scanner | affected | wolfi | osv-scanner | — |
| overmind | affected | wolfi | overmind | — |
| overmind | affected | chainguard | overmind | — |
| paranoia | affected | chainguard | paranoia | — |
| paranoia | affected | wolfi | paranoia | — |
| petname | affected | chainguard | petname | — |
| petname | affected | wolfi | petname | — |
| php-fpm_exporter | affected | chainguard | php-fpm_exporter | — |
| php-fpm_exporter | affected | wolfi | php-fpm_exporter | — |
| policy-controller | affected | chainguard | policy-controller | — |
| policy-controller | affected | wolfi | policy-controller | — |
| policy-controller-fips | affected | chainguard | policy-controller-fips | — |
| pombump | affected | wolfi | pombump | — |
| pombump | affected | chainguard | pombump | — |
| prometheus-adapter | affected | chainguard | prometheus-adapter | — |
| prometheus-adapter | affected | wolfi | prometheus-adapter | — |
| prometheus-adapter-0.10 | affected | chainguard | prometheus-adapter-0.10 | — |
| prometheus-adapter-fips | affected | chainguard | prometheus-adapter-fips | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-alertmanager | affected | wolfi | prometheus-alertmanager | — |
| prometheus-alertmanager | affected | chainguard | prometheus-alertmanager | — |
| prometheus-alertmanager-fips | affected | chainguard | prometheus-alertmanager-fips | — |
| prometheus-beat-exporter | affected | chainguard | prometheus-beat-exporter | — |
| prometheus-beat-exporter | affected | wolfi | prometheus-beat-exporter | — |
| prometheus-beat-exporter-fips | affected | chainguard | prometheus-beat-exporter-fips | — |
| prometheus-bind-exporter | affected | wolfi | prometheus-bind-exporter | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-elasticsearch-exporter-fips | affected | chainguard | prometheus-elasticsearch-exporter-fips | — |
| prometheus-fips-2.45 | affected | chainguard | prometheus-fips-2.45 | — |
| prometheus-mongodb-exporter-0.37 | affected | chainguard | prometheus-mongodb-exporter-0.37 | — |
| prometheus-mongodb-exporter-fips | affected | chainguard | prometheus-mongodb-exporter-fips | — |
| prometheus-mongodb-exporter-fips-0.37 | affected | chainguard | prometheus-mongodb-exporter-fips-0.37 | — |
| prometheus-mysqld-exporter | affected | wolfi | prometheus-mysqld-exporter | — |
| prometheus-mysqld-exporter | affected | chainguard | prometheus-mysqld-exporter | — |
| prometheus-nats-exporter | affected | chainguard | prometheus-nats-exporter | — |
| prometheus-nats-exporter | affected | wolfi | prometheus-nats-exporter | — |
| prometheus-node-exporter-fips | affected | chainguard | prometheus-node-exporter-fips | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| prometheus-postgres-exporter-0.13 | affected | chainguard | prometheus-postgres-exporter-0.13 | — |
| prometheus-postgres-exporter-fips | affected | chainguard | prometheus-postgres-exporter-fips | — |
| prometheus-pushgateway | affected | wolfi | prometheus-pushgateway | — |
| prometheus-pushgateway | affected | chainguard | prometheus-pushgateway | — |
| prometheus-pushgateway-fips | affected | chainguard | prometheus-pushgateway-fips | — |
| prometheus-pushgateway-fips-1.4 | affected | chainguard | prometheus-pushgateway-fips-1.4 | — |
| prometheus-redis-exporter | affected | chainguard | prometheus-redis-exporter | — |
| prometheus-redis-exporter | affected | wolfi | prometheus-redis-exporter | — |
| prometheus-redis-exporter-fips | affected | chainguard | prometheus-redis-exporter-fips | — |
| prometheus-redis-exporter-fips-1.44 | affected | chainguard | prometheus-redis-exporter-fips-1.44 | — |
| prometheus-stackdriver-exporter | affected | wolfi | prometheus-stackdriver-exporter | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter | affected | wolfi | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter | affected | chainguard | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter-0.22 | affected | chainguard | prometheus-statsd-exporter-0.22 | — |
| prometheus-statsd-exporter-fips | affected | chainguard | prometheus-statsd-exporter-fips | — |
| prometheus-statsd-exporter-fips-0.22 | affected | chainguard | prometheus-statsd-exporter-fips-0.22 | — |
| pulumi-kubernetes-operator | affected | chainguard | pulumi-kubernetes-operator | — |
| pulumi-kubernetes-operator | affected | wolfi | pulumi-kubernetes-operator | — |
| pulumi-language-dotnet | affected | wolfi | pulumi-language-dotnet | — |
| pulumi-language-dotnet | affected | chainguard | pulumi-language-dotnet | — |
| pulumi-language-yaml | affected | wolfi | pulumi-language-yaml | — |
| pulumi-language-yaml | affected | chainguard | pulumi-language-yaml | — |
| q | affected | wolfi | q | — |
| q | affected | chainguard | q | — |
| rabbitmq-default-user-credential-updater | affected | wolfi | rabbitmq-default-user-credential-updater | — |
| rabbitmq-default-user-credential-updater | affected | chainguard | rabbitmq-default-user-credential-updater | — |
| rclone | affected | wolfi | rclone | — |
| rclone | affected | chainguard | rclone | — |
| redka | affected | wolfi | redka | — |
| redka | affected | chainguard | redka | — |
| regclient | affected | chainguard | regclient | — |
| regclient | affected | wolfi | regclient | — |
| rekor | affected | wolfi | rekor | — |
| rekor | affected | chainguard | rekor | — |
| rekor-fips | affected | chainguard | rekor-fips | — |
| render-template | affected | chainguard | render-template | — |
| render-template | affected | wolfi | render-template | — |
| rootlesskit | affected | wolfi | rootlesskit | — |
| rootlesskit | affected | chainguard | rootlesskit | — |
| runc | affected | wolfi | runc | — |
| runc | affected | chainguard | runc | — |
| s5cmd | affected | chainguard | s5cmd | — |
| s5cmd | affected | wolfi | s5cmd | — |
| scorecard | affected | wolfi | scorecard | — |
| scorecard | affected | chainguard | scorecard | — |
| secrets-store-csi-driver | affected | wolfi | secrets-store-csi-driver | — |
| secrets-store-csi-driver | affected | chainguard | secrets-store-csi-driver | — |
| secrets-store-csi-driver-provider-aws | affected | chainguard | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-aws | affected | wolfi | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-azure | affected | wolfi | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-azure | affected | chainguard | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-gcp | affected | chainguard | secrets-store-csi-driver-provider-gcp | — |
| secrets-store-csi-driver-provider-gcp | affected | wolfi | secrets-store-csi-driver-provider-gcp | — |
| shfmt | affected | wolfi | shfmt | — |
| shfmt | affected | chainguard | shfmt | — |
| skaffold | affected | wolfi | skaffold | — |
| skaffold | affected | chainguard | skaffold | — |
| skopeo | affected | chainguard | skopeo | — |
| skopeo | affected | wolfi | skopeo | — |
| smarter-device-manager | affected | chainguard | smarter-device-manager | — |
| smarter-device-manager | affected | wolfi | smarter-device-manager | — |
| smarter-device-manager-fips | affected | chainguard | smarter-device-manager-fips | — |
| snyk-cli | affected | wolfi | snyk-cli | — |
| snyk-cli | affected | chainguard | snyk-cli | — |
| sonobuoy | affected | chainguard | sonobuoy | — |
| sonobuoy | affected | wolfi | sonobuoy | — |
| sops | affected | wolfi | sops | — |
| sops | affected | chainguard | sops | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spegel | affected | chainguard | spegel | — |
| spegel | affected | wolfi | spegel | — |
| spicedb | affected | chainguard | spicedb | — |
| spicedb | affected | wolfi | spicedb | — |
| spqr | affected | wolfi | spqr | — |
| spqr | affected | chainguard | spqr | — |
| src | affected | wolfi | src | — |
| src | affected | chainguard | src | — |
| src-fingerprint | affected | wolfi | src-fingerprint | — |
| src-fingerprint | affected | chainguard | src-fingerprint | — |
| step | affected | chainguard | step | — |
| step | affected | wolfi | step | — |
| step-ca | affected | chainguard | step-ca | — |
| step-ca | affected | wolfi | step-ca | — |
| step-ca-fips | affected | chainguard | step-ca-fips | — |
| step-fips | affected | chainguard | step-fips | — |
| stern | affected | wolfi | stern | — |
| stern | affected | chainguard | stern | — |
| tekton-chains | affected | chainguard | tekton-chains | — |
| tekton-chains | affected | wolfi | tekton-chains | — |
| tekton-chains-fips | affected | chainguard | tekton-chains-fips | — |
| tekton-pipelines | affected | chainguard | tekton-pipelines | — |
| tekton-pipelines | affected | wolfi | tekton-pipelines | — |
| tekton-pipelines-fips | affected | chainguard | tekton-pipelines-fips | — |
| telegraf-1.29 | affected | wolfi | telegraf-1.29 | — |
| telegraf-1.29 | affected | chainguard | telegraf-1.29 | — |
| telegraf-1.30 | affected | wolfi | telegraf-1.30 | — |
| telegraf-1.30 | affected | chainguard | telegraf-1.30 | — |
| tempo | affected | wolfi | tempo | — |
| tempo | affected | chainguard | tempo | — |
| terraform-docs | affected | wolfi | terraform-docs | — |
| terraform-docs | affected | chainguard | terraform-docs | — |
| tfsec | affected | chainguard | tfsec | — |
| tfsec | affected | wolfi | tfsec | — |
| thanos | affected | chainguard | thanos | — |
| thanos | affected | wolfi | thanos | — |
| thanos-fips | affected | chainguard | thanos-fips | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| tigera-operator-1.30 | affected | wolfi | tigera-operator-1.30 | — |
| tigera-operator-1.30 | affected | chainguard | tigera-operator-1.30 | — |
| tigera-operator-1.31 | affected | chainguard | tigera-operator-1.31 | — |
| tigera-operator-1.31 | affected | wolfi | tigera-operator-1.31 | — |
| tigera-operator-1.32 | affected | chainguard | tigera-operator-1.32 | — |
| tigera-operator-1.32 | affected | wolfi | tigera-operator-1.32 | — |
| tigera-operator-1.33 | affected | chainguard | tigera-operator-1.33 | — |
| tigera-operator-1.33 | affected | wolfi | tigera-operator-1.33 | — |
| tigera-operator-fips-1.29 | affected | chainguard | tigera-operator-fips-1.29 | — |
| timestamp-authority-fips | affected | chainguard | timestamp-authority-fips | — |
| timoni | affected | chainguard | timoni | — |
| timoni | affected | wolfi | timoni | — |
| traefik | affected | chainguard | traefik | — |
| traefik | affected | wolfi | traefik | — |
| traefik-fips | affected | chainguard | traefik-fips | — |
| trillian | affected | wolfi | trillian | — |
| trillian | affected | chainguard | trillian | — |
| trillian-fips | affected | chainguard | trillian-fips | — |
| trivy | affected | chainguard | trivy | — |
| trivy | affected | wolfi | trivy | — |
| trust-manager | affected | chainguard | trust-manager | — |
| trust-manager | affected | wolfi | trust-manager | — |
| trust-manager-fips | affected | chainguard | trust-manager-fips | — |
| vault-1.16 | affected | chainguard | vault-1.16 | — |
| vault-k8s | affected | chainguard | vault-k8s | — |
| vault-k8s | affected | wolfi | vault-k8s | — |
| vault-k8s-fips | affected | chainguard | vault-k8s-fips | — |
| vertical-pod-autoscaler | affected | wolfi | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler | affected | chainguard | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler-fips | affected | chainguard | vertical-pod-autoscaler-fips | — |
| volume-modifier-for-k8s | affected | wolfi | volume-modifier-for-k8s | — |
| volume-modifier-for-k8s | affected | chainguard | volume-modifier-for-k8s | — |
| volume-modifier-for-k8s-fips | affected | chainguard | volume-modifier-for-k8s-fips | — |
| vt-cli | affected | wolfi | vt-cli | — |
| vt-cli | affected | chainguard | vt-cli | — |
| wait-for-port | affected | chainguard | wait-for-port | — |
| wait-for-port | affected | wolfi | wait-for-port | — |
| wave | affected | wolfi | wave | — |
| wave | affected | chainguard | wave | — |
| wave-fips | affected | chainguard | wave-fips | — |
| wavefront-collector-for-kubernetes-1.12 | affected | chainguard | wavefront-collector-for-kubernetes-1.12 | — |
| wavefront-collector-for-kubernetes-1.13 | affected | chainguard | wavefront-collector-for-kubernetes-1.13 | — |
| wgcf | affected | chainguard | wgcf | — |
| wgcf | affected | wolfi | wgcf | — |
| wire-go | affected | chainguard | wire-go | — |
| wire-go | affected | wolfi | wire-go | — |
| wireguard-go | affected | wolfi | wireguard-go | — |
| wireguard-go | affected | chainguard | wireguard-go | — |
| zot | affected | wolfi | zot | — |
| zot | affected | chainguard | zot | — |
CVE-2024-24787 affecting package msft-golang for versions less than 1.22.3
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| msft-golang | affected | Azure Linux:2 | msft-golang | — |
CVE-2024-24787 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
Arbitrary code execution during build on Darwin in cmd/go
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | chainguard | aactl | — |
| aactl | affected | wolfi | aactl | — |
| actions-runner-controller-fips | affected | chainguard | actions-runner-controller-fips | — |
| addon-resizer-fips | affected | chainguard | addon-resizer-fips | — |
| argo-workflows | affected | wolfi | argo-workflows | — |
| argo-workflows | affected | chainguard | argo-workflows | — |
| argo-workflows-fips | affected | chainguard | argo-workflows-fips | — |
| atlantis | affected | wolfi | atlantis | — |
| atlantis | affected | chainguard | atlantis | — |
| atlantis-fips | affected | chainguard | atlantis-fips | — |
| aws-ebs-csi-driver | affected | chainguard | aws-ebs-csi-driver | — |
| aws-efs-csi-driver | affected | chainguard | aws-efs-csi-driver | — |
| aws-efs-csi-driver | affected | wolfi | aws-efs-csi-driver | — |
| aws-efs-csi-driver-fips | affected | chainguard | aws-efs-csi-driver-fips | — |
| aws-flb-cloudwatch-fips | affected | chainguard | aws-flb-cloudwatch-fips | — |
| aws-flb-firehose-fips | affected | chainguard | aws-flb-firehose-fips | — |
| aws-flb-kinesis-fips | affected | chainguard | aws-flb-kinesis-fips | — |
| aws-load-balancer-controller-fips | affected | chainguard | aws-load-balancer-controller-fips | — |
| azure-aad-pod-identity-mic | affected | chainguard | azure-aad-pod-identity-mic | — |
| bank-vaults | affected | chainguard | bank-vaults | — |
| bank-vaults | affected | wolfi | bank-vaults | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| bom | affected | wolfi | bom | — |
| bom | affected | chainguard | bom | — |
| boring-registry | affected | wolfi | boring-registry | — |
| boring-registry | affected | chainguard | boring-registry | — |
| boring-registry-fips | affected | chainguard | boring-registry-fips | — |
| buildkitd | affected | wolfi | buildkitd | — |
| buildkitd | affected | chainguard | buildkitd | — |
| caddy | affected | wolfi | caddy | — |
| caddy | affected | chainguard | caddy | — |
| caddy-fips | affected | chainguard | caddy-fips | — |
| cadvisor | affected | chainguard | cadvisor | — |
| cadvisor | affected | wolfi | cadvisor | — |
| cadvisor-fips | affected | chainguard | cadvisor-fips | — |
| capslock | affected | chainguard | capslock | — |
| capslock | affected | wolfi | capslock | — |
| cass-operator-fips | affected | chainguard | cass-operator-fips | — |
| cass-operator-fips-no-pvc-delete | affected | chainguard | cass-operator-fips-no-pvc-delete | — |
| cert-exporter | affected | wolfi | cert-exporter | — |
| cert-exporter | affected | chainguard | cert-exporter | — |
| cert-exporter-fips | affected | chainguard | cert-exporter-fips | — |
| certificate-transparency | affected | wolfi | certificate-transparency | — |
| certificate-transparency | affected | chainguard | certificate-transparency | — |
| certificate-transparency-fips | affected | chainguard | certificate-transparency-fips | — |
| cert-manager-webhook-pdns | affected | wolfi | cert-manager-webhook-pdns | — |
| cert-manager-webhook-pdns | affected | chainguard | cert-manager-webhook-pdns | — |
| cert-manager-webhook-pdns-fips | affected | chainguard | cert-manager-webhook-pdns-fips | — |
| cfssl | affected | chainguard | cfssl | — |
| cfssl | affected | wolfi | cfssl | — |
| chainctl | affected | chainguard | chainctl | — |
| chartmuseum | affected | chainguard | chartmuseum | — |
| chartmuseum | affected | wolfi | chartmuseum | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cilium-fips-1.15 | affected | chainguard | cilium-fips-1.15 | — |
| cloudflared | affected | wolfi | cloudflared | — |
| cloudflared | affected | chainguard | cloudflared | — |
| configmap-reload | affected | wolfi | configmap-reload | — |
| configmap-reload | affected | chainguard | configmap-reload | — |
| configmap-reload-fips | affected | chainguard | configmap-reload-fips | — |
| configmap-reload-fips-0.11 | affected | chainguard | configmap-reload-fips-0.11 | — |
| confluent-common-docker | affected | wolfi | confluent-common-docker | — |
| confluent-common-docker | affected | chainguard | confluent-common-docker | — |
| conftest | affected | chainguard | conftest | — |
| conftest | affected | wolfi | conftest | — |
| conftest-fips | affected | chainguard | conftest-fips | — |
| cortex | affected | wolfi | cortex | — |
| cortex | affected | chainguard | cortex | — |
| cortex-fips | affected | chainguard | cortex-fips | — |
| cosign | affected | chainguard | cosign | — |
| cosign | affected | wolfi | cosign | — |
| cosign-fips | affected | chainguard | cosign-fips | — |
| crane | affected | wolfi | crane | — |
| crane | affected | chainguard | crane | — |
| cri-tools | affected | chainguard | cri-tools | — |
| cri-tools | affected | wolfi | cri-tools | — |
| croc | affected | wolfi | croc | — |
| croc | affected | chainguard | croc | — |
| crossplane-provider-aws | affected | chainguard | crossplane-provider-aws | — |
| crossplane-provider-aws | affected | wolfi | crossplane-provider-aws | — |
| crossplane-provider-azure | affected | wolfi | crossplane-provider-azure | — |
| crossplane-provider-azure | affected | chainguard | crossplane-provider-azure | — |
| crossplane-provider-gcp | affected | chainguard | crossplane-provider-gcp | — |
| ctop | affected | chainguard | ctop | — |
| ctop | affected | wolfi | ctop | — |
| cue | affected | wolfi | cue | — |
| cue | affected | chainguard | cue | — |
| cue-fips | affected | chainguard | cue-fips | — |
| dask-gateway | affected | chainguard | dask-gateway | — |
| dask-gateway | affected | wolfi | dask-gateway | — |
| delve | affected | wolfi | delve | — |
| delve | affected | chainguard | delve | — |
| dex | affected | wolfi | dex | — |
| dex | affected | chainguard | dex | — |
| dex-fips | affected | chainguard | dex-fips | — |
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| dgraph | affected | chainguard | dgraph | — |
| dgraph | affected | wolfi | dgraph | — |
| direnv | affected | chainguard | direnv | — |
| direnv | affected | wolfi | direnv | — |
| dive | affected | chainguard | dive | — |
| dive | affected | wolfi | dive | — |
| docker-compose | affected | chainguard | docker-compose | — |
| docker-compose | affected | wolfi | docker-compose | — |
| docker-credential-acr-env | affected | wolfi | docker-credential-acr-env | — |
| docker-credential-acr-env | affected | chainguard | docker-credential-acr-env | — |
| docker-credential-ecr-login | affected | wolfi | docker-credential-ecr-login | — |
| docker-credential-ecr-login | affected | chainguard | docker-credential-ecr-login | — |
| docker-credential-gcr | affected | chainguard | docker-credential-gcr | — |
| docker-credential-gcr | affected | wolfi | docker-credential-gcr | — |
| dockerize | affected | wolfi | dockerize | — |
| dockerize | affected | chainguard | dockerize | — |
| dockerize-fips | affected | chainguard | dockerize-fips | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| eck-operator | affected | chainguard | eck-operator | — |
| eksctl | affected | chainguard | eksctl | — |
| eksctl | affected | wolfi | eksctl | — |
| etcd-3.4 | affected | chainguard | etcd-3.4 | — |
| etcd-3.5 | affected | chainguard | etcd-3.5 | — |
| etcd-fips-3.4 | affected | chainguard | etcd-fips-3.4 | — |
| etcd-fips-3.5 | affected | chainguard | etcd-fips-3.5 | — |
| external-secrets-fips | affected | chainguard | external-secrets-fips | — |
| extism | affected | chainguard | extism | — |
| extism | affected | wolfi | extism | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| falcoctl-fips-0.4 | affected | chainguard | falcoctl-fips-0.4 | — |
| falcosidekick | affected | wolfi | falcosidekick | — |
| falcosidekick | affected | chainguard | falcosidekick | — |
| falcosidekick-fips | affected | chainguard | falcosidekick-fips | — |
| ferretdb | affected | chainguard | ferretdb | — |
| ferretdb | affected | wolfi | ferretdb | — |
| flannel | affected | chainguard | flannel | — |
| flannel | affected | wolfi | flannel | — |
| flux-image-reflector-controller | affected | chainguard | flux-image-reflector-controller | — |
| flux-image-reflector-controller | affected | wolfi | flux-image-reflector-controller | — |
| flux-kustomize-controller | affected | wolfi | flux-kustomize-controller | — |
| flux-kustomize-controller | affected | chainguard | flux-kustomize-controller | — |
| flux-notification-controller | affected | chainguard | flux-notification-controller | — |
| flux-notification-controller | affected | wolfi | flux-notification-controller | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flyte | affected | wolfi | flyte | — |
| flyte | affected | chainguard | flyte | — |
| frp | affected | wolfi | frp | — |
| frp | affected | chainguard | frp | — |
| fulcio | affected | wolfi | fulcio | — |
| fulcio | affected | chainguard | fulcio | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| fuse-overlayfs-snapshotter | affected | wolfi | fuse-overlayfs-snapshotter | — |
| fuse-overlayfs-snapshotter | affected | chainguard | fuse-overlayfs-snapshotter | — |
| ghaudit | affected | chainguard | ghaudit | — |
| ghaudit | affected | wolfi | ghaudit | — |
| gitleaks | affected | chainguard | gitleaks | — |
| gitleaks | affected | wolfi | gitleaks | — |
| git-lfs | affected | chainguard | git-lfs | — |
| git-lfs | affected | wolfi | git-lfs | — |
| gitness | affected | wolfi | gitness | — |
| gitness | affected | chainguard | gitness | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| glab | affected | wolfi | glab | — |
| glab | affected | chainguard | glab | — |
| go-1.21 | affected | wolfi | go-1.21 | — |
| go-1.21 | affected | chainguard | go-1.21 | — |
| go-1.22 | affected | chainguard | go-1.22 | — |
| go-1.22 | affected | wolfi | go-1.22 | — |
| go-bindata | affected | chainguard | go-bindata | — |
| go-bindata | affected | wolfi | go-bindata | — |
| gobump | affected | chainguard | gobump | — |
| gobump | affected | wolfi | gobump | — |
| golangci-lint | affected | chainguard | golangci-lint | — |
| golangci-lint | affected | wolfi | golangci-lint | — |
| go-licenses | affected | wolfi | go-licenses | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-md2man | affected | wolfi | go-md2man | — |
| go-md2man | affected | chainguard | go-md2man | — |
| gomplate | affected | wolfi | gomplate | — |
| gomplate | affected | chainguard | gomplate | — |
| gops | affected | wolfi | gops | — |
| gops | affected | chainguard | gops | — |
| gostatsd | affected | wolfi | gostatsd | — |
| gostatsd | affected | chainguard | gostatsd | — |
| gosu | affected | chainguard | gosu | — |
| gosu | affected | wolfi | gosu | — |
| gotenberg | affected | chainguard | gotenberg | — |
| govulncheck | affected | wolfi | govulncheck | — |
| govulncheck | affected | chainguard | govulncheck | — |
| grafana-agent-operator | affected | chainguard | grafana-agent-operator | — |
| grafana-agent-operator | affected | wolfi | grafana-agent-operator | — |
| grafana-operator | affected | chainguard | grafana-operator | — |
| grafana-operator | affected | wolfi | grafana-operator | — |
| grpcurl | affected | wolfi | grpcurl | — |
| grpcurl | affected | chainguard | grpcurl | — |
| guac | affected | wolfi | guac | — |
| guac | affected | chainguard | guac | — |
| harbor-cli | affected | chainguard | harbor-cli | — |
| harbor-cli | affected | wolfi | harbor-cli | — |
| harbor-registry | affected | wolfi | harbor-registry | — |
| harbor-registry | affected | chainguard | harbor-registry | — |
| harbor-registry-fips | affected | chainguard | harbor-registry-fips | — |
| harbor-scanner-trivy | affected | chainguard | harbor-scanner-trivy | — |
| harbor-scanner-trivy | affected | wolfi | harbor-scanner-trivy | — |
| harbor-scanner-trivy-fips | affected | chainguard | harbor-scanner-trivy-fips | — |
| hcloud | affected | chainguard | hcloud | — |
| hcloud | affected | wolfi | hcloud | — |
| hello-world-golang | affected | chainguard | hello-world-golang | — |
| hello-world-golang | affected | wolfi | hello-world-golang | — |
| helm | affected | wolfi | helm | — |
| helm | affected | chainguard | helm | — |
| helm-3 | affected | wolfi | helm-3 | — |
| helm-3 | affected | chainguard | helm-3 | — |
| helm-fips | affected | chainguard | helm-fips | — |
| helm-fips-3 | affected | chainguard | helm-fips-3 | — |
| helm-fips-4 | affected | chainguard | helm-fips-4 | — |
| helm-operator | affected | wolfi | helm-operator | — |
| helm-operator | affected | chainguard | helm-operator | — |
| helm-operator-fips | affected | chainguard | helm-operator-fips | — |
| helm-push | affected | wolfi | helm-push | — |
| helm-push | affected | chainguard | helm-push | — |
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| http-echo | affected | chainguard | http-echo | — |
| http-echo | affected | wolfi | http-echo | — |
| hubble-ui | affected | wolfi | hubble-ui | — |
| hubble-ui | affected | chainguard | hubble-ui | — |
| hubble-ui-backend-fips | affected | chainguard | hubble-ui-backend-fips | — |
| influx | affected | wolfi | influx | — |
| influx | affected | chainguard | influx | — |
| ip-masq-agent | affected | chainguard | ip-masq-agent | — |
| ip-masq-agent | affected | wolfi | ip-masq-agent | — |
| jitsucom-bulker | affected | wolfi | jitsucom-bulker | — |
| jitsucom-bulker | affected | chainguard | jitsucom-bulker | — |
| jsonnet-bundler | affected | chainguard | jsonnet-bundler | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| k9s | affected | chainguard | k9s | — |
| k9s | affected | wolfi | k9s | — |
| kaf | affected | chainguard | kaf | — |
| kaf | affected | wolfi | kaf | — |
| kafka_exporter | affected | chainguard | kafka_exporter | — |
| kafka_exporter | affected | wolfi | kafka_exporter | — |
| karpenter-0.35 | affected | chainguard | karpenter-0.35 | — |
| karpenter-fips-0.35 | affected | chainguard | karpenter-fips-0.35 | — |
| karpenter-fips-0.36 | affected | chainguard | karpenter-fips-0.36 | — |
| kind | affected | wolfi | kind | — |
| kind | affected | chainguard | kind | — |
| ko | affected | chainguard | ko | — |
| ko | affected | wolfi | ko | — |
| ko-fips | affected | chainguard | ko-fips | — |
| kpt | affected | chainguard | kpt | — |
| kpt | affected | wolfi | kpt | — |
| ksops | affected | wolfi | ksops | — |
| ksops | affected | chainguard | ksops | — |
| kube-bench | affected | wolfi | kube-bench | — |
| kube-bench | affected | chainguard | kube-bench | — |
| kube-bench-fips | affected | chainguard | kube-bench-fips | — |
| kubebuilder | affected | chainguard | kubebuilder | — |
| kubebuilder | affected | wolfi | kubebuilder | — |
| kubecolor | affected | wolfi | kubecolor | — |
| kubecolor | affected | chainguard | kubecolor | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kube-oidc-proxy | affected | chainguard | kube-oidc-proxy | — |
| kubernetes-csi-driver-hostpath | affected | wolfi | kubernetes-csi-driver-hostpath | — |
| kubernetes-csi-driver-hostpath | affected | chainguard | kubernetes-csi-driver-hostpath | — |
| kubernetes-csi-external-provisioner | affected | chainguard | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-external-provisioner | affected | wolfi | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-livenessprobe | affected | chainguard | kubernetes-csi-livenessprobe | — |
| kubernetes-csi-livenessprobe | affected | wolfi | kubernetes-csi-livenessprobe | — |
| kubernetes-csi-livenessprobe-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-2.10 | — |
| kubernetes-csi-livenessprobe-fips | affected | chainguard | kubernetes-csi-livenessprobe-fips | — |
| kubernetes-csi-livenessprobe-fips-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-fips-2.10 | — |
| kubernetes-dashboard | affected | wolfi | kubernetes-dashboard | — |
| kubernetes-dashboard | affected | chainguard | kubernetes-dashboard | — |
| kubernetes-dashboard-fips | affected | chainguard | kubernetes-dashboard-fips | — |
| kubernetes-dashboard-metrics-scraper | affected | chainguard | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper | affected | wolfi | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper-fips | affected | chainguard | kubernetes-dashboard-metrics-scraper-fips | — |
| kubernetes-dns-node-cache | affected | wolfi | kubernetes-dns-node-cache | — |
| kubernetes-dns-node-cache | affected | chainguard | kubernetes-dns-node-cache | — |
| kubernetes-ingress-defaultbackend | affected | wolfi | kubernetes-ingress-defaultbackend | — |
| kubernetes-ingress-defaultbackend | affected | chainguard | kubernetes-ingress-defaultbackend | — |
| kubescape | affected | chainguard | kubescape | — |
| kubescape | affected | wolfi | kubescape | — |
| kube-state-metrics | affected | chainguard | kube-state-metrics | — |
| kube-state-metrics | affected | wolfi | kube-state-metrics | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| kube-state-metrics-fips | affected | chainguard | kube-state-metrics-fips | — |
| kubewatch | affected | wolfi | kubewatch | — |
| kubewatch | affected | chainguard | kubewatch | — |
| kustomize | affected | wolfi | kustomize | — |
| kustomize | affected | chainguard | kustomize | — |
| kwok | affected | chainguard | kwok | — |
| kwok | affected | wolfi | kwok | — |
| kyverno-policy-reporter-kyverno-plugin | affected | chainguard | kyverno-policy-reporter-kyverno-plugin | — |
| kyverno-policy-reporter-kyverno-plugin | affected | wolfi | kyverno-policy-reporter-kyverno-plugin | — |
| kyverno-policy-reporter-ui | affected | chainguard | kyverno-policy-reporter-ui | — |
| kyverno-policy-reporter-ui | affected | wolfi | kyverno-policy-reporter-ui | — |
| lazygit | affected | wolfi | lazygit | — |
| lazygit | affected | chainguard | lazygit | — |
| libnvidia-container | affected | chainguard | libnvidia-container | — |
| libnvidia-container | affected | wolfi | libnvidia-container | — |
| litefs | affected | wolfi | litefs | — |
| litefs | affected | chainguard | litefs | — |
| litestream | affected | chainguard | litestream | — |
| litestream | affected | wolfi | litestream | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| local-static-provisioner | affected | wolfi | local-static-provisioner | — |
| local-static-provisioner | affected | chainguard | local-static-provisioner | — |
| logstash-exporter | affected | wolfi | logstash-exporter | — |
| logstash-exporter | affected | chainguard | logstash-exporter | — |
| logstash-exporter-fips | affected | chainguard | logstash-exporter-fips | — |
| mage | affected | chainguard | mage | — |
| mage | affected | wolfi | mage | — |
| mc | affected | chainguard | mc | — |
| mc | affected | wolfi | mc | — |
| mc-fips | affected | chainguard | mc-fips | — |
| melange | affected | wolfi | melange | — |
| melange | affected | chainguard | melange | — |
| metacontroller | affected | wolfi | metacontroller | — |
| metacontroller | affected | chainguard | metacontroller | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server | affected | chainguard | metrics-server | — |
| metrics-server-fips | affected | chainguard | metrics-server-fips | — |
| mkcert | affected | chainguard | mkcert | — |
| mkcert | affected | wolfi | mkcert | — |
| mockery | affected | wolfi | mockery | — |
| mockery | affected | chainguard | mockery | — |
| mods | affected | chainguard | mods | — |
| mods | affected | wolfi | mods | — |
| mongo-tools | affected | wolfi | mongo-tools | — |
| mongo-tools | affected | chainguard | mongo-tools | — |
| multus-cni | affected | chainguard | multus-cni | — |
| multus-cni | affected | wolfi | multus-cni | — |
| multus-cni-fips | affected | chainguard | multus-cni-fips | — |
| nats-server | affected | wolfi | nats-server | — |
| nats-server | affected | chainguard | nats-server | — |
| neuvector-scanner | affected | chainguard | neuvector-scanner | — |
| neuvector-scanner | affected | wolfi | neuvector-scanner | — |
| newrelic-fluent-bit-output | affected | wolfi | newrelic-fluent-bit-output | — |
| newrelic-fluent-bit-output | affected | chainguard | newrelic-fluent-bit-output | — |
| newrelic-infra-operator | affected | chainguard | newrelic-infra-operator | — |
| newrelic-infra-operator | affected | wolfi | newrelic-infra-operator | — |
| newrelic-nri-statsd | affected | wolfi | newrelic-nri-statsd | — |
| newrelic-nri-statsd | affected | chainguard | newrelic-nri-statsd | — |
| newrelic-prometheus-configurator | affected | wolfi | newrelic-prometheus-configurator | — |
| newrelic-prometheus-configurator | affected | chainguard | newrelic-prometheus-configurator | — |
| nfs-subdir-external-provisioner | affected | chainguard | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner | affected | wolfi | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner-fips | affected | chainguard | nfs-subdir-external-provisioner-fips | — |
| nri-prometheus | affected | chainguard | nri-prometheus | — |
| nri-prometheus | affected | wolfi | nri-prometheus | — |
| nvidia-container-toolkit | affected | wolfi | nvidia-container-toolkit | — |
| nvidia-container-toolkit | affected | chainguard | nvidia-container-toolkit | — |
| oauth2-proxy | affected | chainguard | oauth2-proxy | — |
| oauth2-proxy | affected | wolfi | oauth2-proxy | — |
| opa | affected | wolfi | opa | — |
| opa | affected | chainguard | opa | — |
| opentelemetry-collector-contrib-fips | affected | chainguard | opentelemetry-collector-contrib-fips | — |
| opentelemetry-collector-fips | affected | chainguard | opentelemetry-collector-fips | — |
| oras | affected | chainguard | oras | — |
| oras | affected | wolfi | oras | — |
| osv-scanner | affected | chainguard | osv-scanner | — |
| osv-scanner | affected | wolfi | osv-scanner | — |
| overmind | affected | chainguard | overmind | — |
| overmind | affected | wolfi | overmind | — |
| paranoia | affected | wolfi | paranoia | — |
| paranoia | affected | chainguard | paranoia | — |
| petname | affected | chainguard | petname | — |
| petname | affected | wolfi | petname | — |
| php-fpm_exporter | affected | wolfi | php-fpm_exporter | — |
| php-fpm_exporter | affected | chainguard | php-fpm_exporter | — |
| policy-controller | affected | wolfi | policy-controller | — |
| policy-controller | affected | chainguard | policy-controller | — |
| policy-controller-fips | affected | chainguard | policy-controller-fips | — |
| pombump | affected | chainguard | pombump | — |
| pombump | affected | wolfi | pombump | — |
| prometheus-adapter | affected | chainguard | prometheus-adapter | — |
| prometheus-adapter | affected | wolfi | prometheus-adapter | — |
| prometheus-adapter-0.10 | affected | chainguard | prometheus-adapter-0.10 | — |
| prometheus-adapter-fips | affected | chainguard | prometheus-adapter-fips | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-alertmanager | affected | wolfi | prometheus-alertmanager | — |
| prometheus-alertmanager | affected | chainguard | prometheus-alertmanager | — |
| prometheus-alertmanager-fips | affected | chainguard | prometheus-alertmanager-fips | — |
| prometheus-beat-exporter | affected | chainguard | prometheus-beat-exporter | — |
| prometheus-beat-exporter-fips | affected | chainguard | prometheus-beat-exporter-fips | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-elasticsearch-exporter-fips | affected | chainguard | prometheus-elasticsearch-exporter-fips | — |
| prometheus-mongodb-exporter-0.37 | affected | chainguard | prometheus-mongodb-exporter-0.37 | — |
| prometheus-mongodb-exporter-fips | affected | chainguard | prometheus-mongodb-exporter-fips | — |
| prometheus-mongodb-exporter-fips-0.37 | affected | chainguard | prometheus-mongodb-exporter-fips-0.37 | — |
| prometheus-mysqld-exporter | affected | chainguard | prometheus-mysqld-exporter | — |
| prometheus-nats-exporter | affected | chainguard | prometheus-nats-exporter | — |
| prometheus-node-exporter-fips | affected | chainguard | prometheus-node-exporter-fips | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| prometheus-postgres-exporter-fips | affected | chainguard | prometheus-postgres-exporter-fips | — |
| prometheus-pushgateway | affected | chainguard | prometheus-pushgateway | — |
| prometheus-pushgateway | affected | wolfi | prometheus-pushgateway | — |
| prometheus-pushgateway-fips | affected | chainguard | prometheus-pushgateway-fips | — |
| prometheus-pushgateway-fips-1.4 | affected | chainguard | prometheus-pushgateway-fips-1.4 | — |
| prometheus-redis-exporter | affected | chainguard | prometheus-redis-exporter | — |
| prometheus-redis-exporter-fips | affected | chainguard | prometheus-redis-exporter-fips | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter | affected | chainguard | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter-fips | affected | chainguard | prometheus-statsd-exporter-fips | — |
| prometheus-statsd-exporter-fips-0.22 | affected | chainguard | prometheus-statsd-exporter-fips-0.22 | — |
| pulumi-kubernetes-operator | affected | chainguard | pulumi-kubernetes-operator | — |
| pulumi-kubernetes-operator | affected | wolfi | pulumi-kubernetes-operator | — |
| pulumi-language-dotnet | affected | wolfi | pulumi-language-dotnet | — |
| pulumi-language-dotnet | affected | chainguard | pulumi-language-dotnet | — |
| pulumi-language-yaml | affected | wolfi | pulumi-language-yaml | — |
| pulumi-language-yaml | affected | chainguard | pulumi-language-yaml | — |
| q | affected | chainguard | q | — |
| q | affected | wolfi | q | — |
| rabbitmq-default-user-credential-updater | affected | wolfi | rabbitmq-default-user-credential-updater | — |
| rabbitmq-default-user-credential-updater | affected | chainguard | rabbitmq-default-user-credential-updater | — |
| rclone | affected | wolfi | rclone | — |
| rclone | affected | chainguard | rclone | — |
| redka | affected | wolfi | redka | — |
| redka | affected | chainguard | redka | — |
| regclient | affected | chainguard | regclient | — |
| regclient | affected | wolfi | regclient | — |
| rekor | affected | wolfi | rekor | — |
| rekor | affected | chainguard | rekor | — |
| rekor-fips | affected | chainguard | rekor-fips | — |
| render-template | affected | chainguard | render-template | — |
| render-template | affected | wolfi | render-template | — |
| rootlesskit | affected | wolfi | rootlesskit | — |
| rootlesskit | affected | chainguard | rootlesskit | — |
| runc | affected | chainguard | runc | — |
| runc | affected | wolfi | runc | — |
| s5cmd | affected | chainguard | s5cmd | — |
| s5cmd | affected | wolfi | s5cmd | — |
| scorecard | affected | wolfi | scorecard | — |
| scorecard | affected | chainguard | scorecard | — |
| secrets-store-csi-driver | affected | chainguard | secrets-store-csi-driver | — |
| secrets-store-csi-driver | affected | wolfi | secrets-store-csi-driver | — |
| secrets-store-csi-driver-provider-aws | affected | chainguard | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-aws | affected | wolfi | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-azure | affected | chainguard | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-azure | affected | wolfi | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-gcp | affected | chainguard | secrets-store-csi-driver-provider-gcp | — |
| secrets-store-csi-driver-provider-gcp | affected | wolfi | secrets-store-csi-driver-provider-gcp | — |
| shfmt | affected | wolfi | shfmt | — |
| shfmt | affected | chainguard | shfmt | — |
| skaffold | affected | chainguard | skaffold | — |
| skaffold | affected | wolfi | skaffold | — |
| skopeo | affected | chainguard | skopeo | — |
| skopeo | affected | wolfi | skopeo | — |
| smarter-device-manager | affected | chainguard | smarter-device-manager | — |
| smarter-device-manager | affected | wolfi | smarter-device-manager | — |
| smarter-device-manager-fips | affected | chainguard | smarter-device-manager-fips | — |
| snyk-cli | affected | wolfi | snyk-cli | — |
| snyk-cli | affected | chainguard | snyk-cli | — |
| sonobuoy | affected | chainguard | sonobuoy | — |
| sonobuoy | affected | wolfi | sonobuoy | — |
| sops | affected | chainguard | sops | — |
| sops | affected | wolfi | sops | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spegel | affected | chainguard | spegel | — |
| spegel | affected | wolfi | spegel | — |
| spicedb | affected | wolfi | spicedb | — |
| spicedb | affected | chainguard | spicedb | — |
| spqr | affected | wolfi | spqr | — |
| spqr | affected | chainguard | spqr | — |
| src | affected | chainguard | src | — |
| src | affected | wolfi | src | — |
| src-fingerprint | affected | wolfi | src-fingerprint | — |
| src-fingerprint | affected | chainguard | src-fingerprint | — |
| step | affected | wolfi | step | — |
| step | affected | chainguard | step | — |
| step-ca | affected | chainguard | step-ca | — |
| step-ca | affected | wolfi | step-ca | — |
| step-ca-fips | affected | chainguard | step-ca-fips | — |
| step-fips | affected | chainguard | step-fips | — |
| stern | affected | chainguard | stern | — |
| stern | affected | wolfi | stern | — |
| tekton-chains | affected | wolfi | tekton-chains | — |
| tekton-chains | affected | chainguard | tekton-chains | — |
| tekton-chains-fips | affected | chainguard | tekton-chains-fips | — |
| tempo | affected | wolfi | tempo | — |
| tempo | affected | chainguard | tempo | — |
| terraform-docs | affected | wolfi | terraform-docs | — |
| terraform-docs | affected | chainguard | terraform-docs | — |
| tfsec | affected | chainguard | tfsec | — |
| tfsec | affected | wolfi | tfsec | — |
| thanos | affected | chainguard | thanos | — |
| thanos | affected | wolfi | thanos | — |
| thanos-fips | affected | chainguard | thanos-fips | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| tigera-operator-fips-1.29 | affected | chainguard | tigera-operator-fips-1.29 | — |
| timestamp-authority-fips | affected | chainguard | timestamp-authority-fips | — |
| timoni | affected | chainguard | timoni | — |
| timoni | affected | wolfi | timoni | — |
| toolchain | affected | Go | toolchain | — |
| trillian | affected | wolfi | trillian | — |
| trillian | affected | chainguard | trillian | — |
| trillian-fips | affected | chainguard | trillian-fips | — |
| trivy | affected | wolfi | trivy | — |
| trivy | affected | chainguard | trivy | — |
| trust-manager | affected | wolfi | trust-manager | — |
| trust-manager | affected | chainguard | trust-manager | — |
| trust-manager-fips | affected | chainguard | trust-manager-fips | — |
| vault-1.16 | affected | chainguard | vault-1.16 | — |
| vault-k8s | affected | chainguard | vault-k8s | — |
| vault-k8s | affected | wolfi | vault-k8s | — |
| vault-k8s-fips | affected | chainguard | vault-k8s-fips | — |
| vertical-pod-autoscaler | affected | wolfi | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler | affected | chainguard | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler-fips | affected | chainguard | vertical-pod-autoscaler-fips | — |
| volume-modifier-for-k8s | affected | chainguard | volume-modifier-for-k8s | — |
| volume-modifier-for-k8s | affected | wolfi | volume-modifier-for-k8s | — |
| volume-modifier-for-k8s-fips | affected | chainguard | volume-modifier-for-k8s-fips | — |
| vt-cli | affected | chainguard | vt-cli | — |
| vt-cli | affected | wolfi | vt-cli | — |
| wait-for-port | affected | chainguard | wait-for-port | — |
| wait-for-port | affected | wolfi | wait-for-port | — |
| wave | affected | wolfi | wave | — |
| wave | affected | chainguard | wave | — |
| wave-fips | affected | chainguard | wave-fips | — |
| wavefront-collector-for-kubernetes-1.12 | affected | chainguard | wavefront-collector-for-kubernetes-1.12 | — |
| wavefront-collector-for-kubernetes-1.13 | affected | chainguard | wavefront-collector-for-kubernetes-1.13 | — |
| wgcf | affected | wolfi | wgcf | — |
| wgcf | affected | chainguard | wgcf | — |
| wire-go | affected | wolfi | wire-go | — |
| wire-go | affected | chainguard | wire-go | — |
| wireguard-go | affected | wolfi | wireguard-go | — |
| wireguard-go | affected | chainguard | wireguard-go | — |
| zot | affected | chainguard | zot | — |
| zot | affected | wolfi | zot | — |
ASB-A-299123598
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2024-23708
In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privileges needed. U...
CVEs:CVE-2024-23708
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVE-2024-35195 affecting package tensorflow for versions less than 2.16.1-8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
Requests `Session` object does not verify requests after making first request with verify=False
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| requests | affected | PyPI | requests | — |
Requests `Session` object does not verify requests after making first request with verify=False
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| airflow | affected | wolfi | airflow | — |
| airflow | affected | chainguard | airflow | — |
| apache-beam-python-3.11-sdk | affected | chainguard | apache-beam-python-3.11-sdk | — |
| az | affected | chainguard | az | — |
| az | affected | wolfi | az | — |
| checkov | affected | chainguard | checkov | — |
| checkov | affected | wolfi | checkov | — |
| confluent-docker-utils | affected | wolfi | confluent-docker-utils | — |
| confluent-docker-utils | affected | chainguard | confluent-docker-utils | — |
| datadog-agent | affected | wolfi | datadog-agent | — |
| datadog-agent | affected | chainguard | datadog-agent | — |
| datadog-agent-fips | affected | chainguard | datadog-agent-fips | — |
| ggshield | affected | wolfi | ggshield | — |
| ggshield | affected | chainguard | ggshield | — |
| jwt-tool | affected | wolfi | jwt-tool | — |
| jwt-tool | affected | chainguard | jwt-tool | — |
| k8s-sidecar | affected | chainguard | k8s-sidecar | — |
| k8s-sidecar | affected | wolfi | k8s-sidecar | — |
| k8s-sidecar-1.22 | affected | chainguard | k8s-sidecar-1.22 | — |
| kubeflow-jupyter-web-app | affected | chainguard | kubeflow-jupyter-web-app | — |
| kubeflow-jupyter-web-app | affected | wolfi | kubeflow-jupyter-web-app | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubeflow-pipelines-visualization-server | affected | wolfi | kubeflow-pipelines-visualization-server | — |
| kubeflow-pipelines-visualization-server | affected | chainguard | kubeflow-pipelines-visualization-server | — |
| kubeflow-volumes-web-app | affected | chainguard | kubeflow-volumes-web-app | — |
| kubeflow-volumes-web-app | affected | wolfi | kubeflow-volumes-web-app | — |
| mlflow | affected | chainguard | mlflow | — |
| mlflow | affected | wolfi | mlflow | — |
| nvidia-nsight-compute-13.1 | affected | chainguard | nvidia-nsight-compute-13.1 | — |
| nvidia-nsight-compute-13.2 | affected | chainguard | nvidia-nsight-compute-13.2 | — |
| patroni | affected | chainguard | patroni | — |
| patroni | affected | wolfi | patroni | — |
| py3.11-pytorch-cuda-12.3 | affected | chainguard | py3.11-pytorch-cuda-12.3 | — |
| py3.11-torchaudio-cuda-12.3 | affected | chainguard | py3.11-torchaudio-cuda-12.3 | — |
| py3.11-torchvision-cuda-11.8 | affected | chainguard | py3.11-torchvision-cuda-11.8 | — |
| py3.11-torchvision-cuda-12.3 | affected | chainguard | py3.11-torchvision-cuda-12.3 | — |
| py3-cassandra-medusa | affected | wolfi | py3-cassandra-medusa | — |
| py3-cassandra-medusa | affected | chainguard | py3-cassandra-medusa | — |
| py3-pipenv | affected | chainguard | py3-pipenv | — |
| py3-pipenv | affected | wolfi | py3-pipenv | — |
| py3-torchvision-cuda-11.8 | affected | chainguard | py3-torchvision-cuda-11.8 | — |
| reflex | affected | wolfi | reflex | — |
| reflex | affected | chainguard | reflex | — |
| request-1276 | affected | chainguard | request-1276 | — |
| requests | affected | PyPI | requests | — |
| requests | affected | PyPI | requests | — |
| requests | affected | PyPI | — | — |
| superset | affected | wolfi | superset | — |
| superset | affected | chainguard | superset | — |
Updated chromium-browser-stable packages fix security vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
GHSA-jx24-3g7h-4qj2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2024-4331
DEBIAN-CVE-2024-4331
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4331
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4331
Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| caddyserver/caddy | affected | github.com | github.com/caddyserver/caddy | — |
Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| caddyserver/caddy | affected | github.com | github.com/caddyserver/caddy | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
GHSA-5jhr-gg3j-ggcf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2024-4368
DEBIAN-CVE-2024-4368
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4368
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-4368
GHSA-4qw6-vwc8-mh38
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2024-4060
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Updated golang packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:9 | golang | — |
Malformed DNS message can cause infinite loop in net
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Bitnami | golang | — |
GHSA-2jwv-jmq4-4j3r
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | chainguard | aactl | — |
| aactl | affected | wolfi | aactl | — |
| actions-runner-controller-fips | affected | chainguard | actions-runner-controller-fips | — |
| addon-resizer-fips | affected | chainguard | addon-resizer-fips | — |
| argo-cd-2.9 | affected | chainguard | argo-cd-2.9 | — |
| argo-cd-2.9 | affected | wolfi | argo-cd-2.9 | — |
| argo-cd-fips-2.10 | affected | chainguard | argo-cd-fips-2.10 | — |
| argo-cd-fips-2.8 | affected | chainguard | argo-cd-fips-2.8 | — |
| argo-cd-fips-2.9 | affected | chainguard | argo-cd-fips-2.9 | — |
| argo-workflows-fips | affected | chainguard | argo-workflows-fips | — |
| atlantis | affected | chainguard | atlantis | — |
| atlantis | affected | wolfi | atlantis | — |
| atlantis-fips | affected | chainguard | atlantis-fips | — |
| aws-ebs-csi-driver | affected | chainguard | aws-ebs-csi-driver | — |
| aws-ebs-csi-driver | affected | wolfi | aws-ebs-csi-driver | — |
| aws-ebs-csi-driver-1.18 | affected | chainguard | aws-ebs-csi-driver-1.18 | — |
| aws-ebs-csi-driver-1.19 | affected | chainguard | aws-ebs-csi-driver-1.19 | — |
| aws-ebs-csi-driver-fips | affected | chainguard | aws-ebs-csi-driver-fips | — |
| aws-efs-csi-driver | affected | chainguard | aws-efs-csi-driver | — |
| aws-efs-csi-driver | affected | wolfi | aws-efs-csi-driver | — |
| aws-efs-csi-driver-fips | affected | chainguard | aws-efs-csi-driver-fips | — |
| aws-efs-csi-driver-fips-1.6 | affected | chainguard | aws-efs-csi-driver-fips-1.6 | — |
| aws-flb-cloudwatch-fips | affected | chainguard | aws-flb-cloudwatch-fips | — |
| aws-flb-firehose-fips | affected | chainguard | aws-flb-firehose-fips | — |
| aws-flb-kinesis-fips | affected | chainguard | aws-flb-kinesis-fips | — |
| aws-load-balancer-controller-2.4.5 | affected | chainguard | aws-load-balancer-controller-2.4.5 | — |
| aws-load-balancer-controller-2.5 | affected | chainguard | aws-load-balancer-controller-2.5 | — |
| aws-load-balancer-controller-fips | affected | chainguard | aws-load-balancer-controller-fips | — |
| azure-aad-pod-identity-mic | affected | chainguard | azure-aad-pod-identity-mic | — |
| bank-vaults | affected | chainguard | bank-vaults | — |
| bank-vaults | affected | wolfi | bank-vaults | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| bom | affected | wolfi | bom | — |
| bom | affected | chainguard | bom | — |
| boring-registry | affected | chainguard | boring-registry | — |
| boring-registry | affected | wolfi | boring-registry | — |
| boring-registry-fips | affected | chainguard | boring-registry-fips | — |
| buildkitd | affected | wolfi | buildkitd | — |
| buildkitd | affected | chainguard | buildkitd | — |
| caddy | affected | wolfi | caddy | — |
| caddy | affected | chainguard | caddy | — |
| caddy-fips | affected | chainguard | caddy-fips | — |
| cadvisor | affected | chainguard | cadvisor | — |
| cadvisor | affected | wolfi | cadvisor | — |
| cadvisor-fips | affected | chainguard | cadvisor-fips | — |
| calico-fips | affected | chainguard | calico-fips | — |
| calico-fips-3.25 | affected | chainguard | calico-fips-3.25 | — |
| capslock | affected | wolfi | capslock | — |
| capslock | affected | chainguard | capslock | — |
| cass-operator-fips | affected | chainguard | cass-operator-fips | — |
| cass-operator-fips-no-pvc-delete | affected | chainguard | cass-operator-fips-no-pvc-delete | — |
| cert-exporter | affected | chainguard | cert-exporter | — |
| cert-exporter | affected | wolfi | cert-exporter | — |
| cert-exporter-fips | affected | chainguard | cert-exporter-fips | — |
| certificate-transparency | affected | wolfi | certificate-transparency | — |
| certificate-transparency | affected | chainguard | certificate-transparency | — |
| certificate-transparency-fips | affected | chainguard | certificate-transparency-fips | — |
| cert-manager-1.12 | affected | chainguard | cert-manager-1.12 | — |
| cert-manager-1.12 | affected | wolfi | cert-manager-1.12 | — |
| cert-manager-1.13 | affected | chainguard | cert-manager-1.13 | — |
| cert-manager-1.13 | affected | wolfi | cert-manager-1.13 | — |
| cert-manager-1.14 | affected | wolfi | cert-manager-1.14 | — |
| cert-manager-1.14 | affected | chainguard | cert-manager-1.14 | — |
| cert-manager-fips-1.12 | affected | chainguard | cert-manager-fips-1.12 | — |
| cert-manager-fips-1.13 | affected | chainguard | cert-manager-fips-1.13 | — |
| cert-manager-fips-1.14 | affected | chainguard | cert-manager-fips-1.14 | — |
| cert-manager-webhook-pdns | affected | wolfi | cert-manager-webhook-pdns | — |
| cert-manager-webhook-pdns | affected | chainguard | cert-manager-webhook-pdns | — |
| cert-manager-webhook-pdns-fips | affected | chainguard | cert-manager-webhook-pdns-fips | — |
| cfssl | affected | chainguard | cfssl | — |
| cfssl | affected | wolfi | cfssl | — |
| chainctl | affected | chainguard | chainctl | — |
| chartmuseum | affected | wolfi | chartmuseum | — |
| chartmuseum | affected | chainguard | chartmuseum | — |
| cilium-1.14 | affected | wolfi | cilium-1.14 | — |
| cilium-1.14 | affected | chainguard | cilium-1.14 | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cilium-fips-1.14 | affected | chainguard | cilium-fips-1.14 | — |
| cilium-fips-1.15 | affected | chainguard | cilium-fips-1.15 | — |
| cloudflared | affected | wolfi | cloudflared | — |
| cloudflared | affected | chainguard | cloudflared | — |
| clusterctl | affected | wolfi | clusterctl | — |
| clusterctl | affected | chainguard | clusterctl | — |
| configmap-reload | affected | wolfi | configmap-reload | — |
| configmap-reload | affected | chainguard | configmap-reload | — |
| configmap-reload-fips | affected | chainguard | configmap-reload-fips | — |
| configmap-reload-fips-0.11 | affected | chainguard | configmap-reload-fips-0.11 | — |
| confluent-common-docker | affected | chainguard | confluent-common-docker | — |
| confluent-common-docker | affected | wolfi | confluent-common-docker | — |
| conftest | affected | wolfi | conftest | — |
| conftest | affected | chainguard | conftest | — |
| conftest-fips | affected | chainguard | conftest-fips | — |
| containerd | affected | wolfi | containerd | — |
| containerd | affected | chainguard | containerd | — |
| coredns | affected | wolfi | coredns | — |
| coredns | affected | chainguard | coredns | — |
| coredns-fips | affected | chainguard | coredns-fips | — |
| cortex | affected | wolfi | cortex | — |
| cortex | affected | chainguard | cortex | — |
| cortex-fips | affected | chainguard | cortex-fips | — |
| cosign | affected | wolfi | cosign | — |
| cosign | affected | chainguard | cosign | — |
| cosign-fips | affected | chainguard | cosign-fips | — |
| cosign-fips | affected | wolfi | cosign-fips | — |
| crane | affected | chainguard | crane | — |
| crane | affected | wolfi | crane | — |
| cri-tools | affected | wolfi | cri-tools | — |
| cri-tools | affected | chainguard | cri-tools | — |
| croc | affected | chainguard | croc | — |
| croc | affected | wolfi | croc | — |
| crossplane | affected | wolfi | crossplane | — |
| crossplane | affected | chainguard | crossplane | — |
| crossplane-provider-aws | affected | wolfi | crossplane-provider-aws | — |
| crossplane-provider-aws | affected | chainguard | crossplane-provider-aws | — |
| crossplane-provider-azure | affected | wolfi | crossplane-provider-azure | — |
| crossplane-provider-azure | affected | chainguard | crossplane-provider-azure | — |
| crossplane-provider-gcp | affected | wolfi | crossplane-provider-gcp | — |
| crossplane-provider-gcp | affected | chainguard | crossplane-provider-gcp | — |
| ctop | affected | chainguard | ctop | — |
| ctop | affected | wolfi | ctop | — |
| cue | affected | wolfi | cue | — |
| cue | affected | chainguard | cue | — |
| cue-fips | affected | chainguard | cue-fips | — |
| dask-gateway | affected | chainguard | dask-gateway | — |
| dask-gateway | affected | wolfi | dask-gateway | — |
| datadog-agent-fips | affected | chainguard | datadog-agent-fips | — |
| delve | affected | chainguard | delve | — |
| delve | affected | wolfi | delve | — |
| dex | affected | wolfi | dex | — |
| dex | affected | chainguard | dex | — |
| dex-fips | affected | chainguard | dex-fips | — |
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| dgraph | affected | wolfi | dgraph | — |
| dgraph | affected | chainguard | dgraph | — |
| direnv | affected | wolfi | direnv | — |
| direnv | affected | chainguard | direnv | — |
| dive | affected | chainguard | dive | — |
| dive | affected | wolfi | dive | — |
| docker-compose | affected | wolfi | docker-compose | — |
| docker-compose | affected | chainguard | docker-compose | — |
| docker-credential-acr-env | affected | chainguard | docker-credential-acr-env | — |
| docker-credential-acr-env | affected | wolfi | docker-credential-acr-env | — |
| docker-credential-ecr-login | affected | wolfi | docker-credential-ecr-login | — |
| docker-credential-ecr-login | affected | chainguard | docker-credential-ecr-login | — |
| docker-credential-gcr | affected | chainguard | docker-credential-gcr | — |
| docker-credential-gcr | affected | wolfi | docker-credential-gcr | — |
| dockerize | affected | wolfi | dockerize | — |
| dockerize | affected | chainguard | dockerize | — |
| dockerize-fips | affected | chainguard | dockerize-fips | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| eck-operator | affected | chainguard | eck-operator | — |
| eksctl | affected | wolfi | eksctl | — |
| eksctl | affected | chainguard | eksctl | — |
| etcd-3.4 | affected | chainguard | etcd-3.4 | — |
| etcd-3.5 | affected | chainguard | etcd-3.5 | — |
| etcd-3.5 | affected | wolfi | etcd-3.5 | — |
| etcd-fips-3.4 | affected | chainguard | etcd-fips-3.4 | — |
| etcd-fips-3.5 | affected | chainguard | etcd-fips-3.5 | — |
| external-dns | affected | wolfi | external-dns | — |
| external-dns | affected | chainguard | external-dns | — |
| external-dns-fips | affected | chainguard | external-dns-fips | — |
| external-secrets-fips | affected | chainguard | external-secrets-fips | — |
| external-secrets-operator | affected | chainguard | external-secrets-operator | — |
| external-secrets-operator | affected | wolfi | external-secrets-operator | — |
| extism | affected | wolfi | extism | — |
| extism | affected | chainguard | extism | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| falcoctl-fips-0.4 | affected | chainguard | falcoctl-fips-0.4 | — |
| falcosidekick | affected | wolfi | falcosidekick | — |
| falcosidekick | affected | chainguard | falcosidekick | — |
| falcosidekick-fips | affected | chainguard | falcosidekick-fips | — |
| ferretdb | affected | chainguard | ferretdb | — |
| ferretdb | affected | wolfi | ferretdb | — |
| filebeat-7.17 | affected | chainguard | filebeat-7.17 | — |
| filebeat-7.17-fips | affected | chainguard | filebeat-7.17-fips | — |
| filebeat-fips | affected | chainguard | filebeat-fips | — |
| flannel | affected | wolfi | flannel | — |
| flannel | affected | chainguard | flannel | — |
| flux-image-reflector-controller | affected | wolfi | flux-image-reflector-controller | — |
| flux-image-reflector-controller | affected | chainguard | flux-image-reflector-controller | — |
| flux-kustomize-controller | affected | wolfi | flux-kustomize-controller | — |
| flux-kustomize-controller | affected | chainguard | flux-kustomize-controller | — |
| flux-notification-controller | affected | chainguard | flux-notification-controller | — |
| flux-notification-controller | affected | wolfi | flux-notification-controller | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| flyte | affected | chainguard | flyte | — |
| flyte | affected | wolfi | flyte | — |
| frp | affected | chainguard | frp | — |
| frp | affected | wolfi | frp | — |
| fulcio | affected | chainguard | fulcio | — |
| fulcio | affected | wolfi | fulcio | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| fuse-overlayfs-snapshotter | affected | wolfi | fuse-overlayfs-snapshotter | — |
| fuse-overlayfs-snapshotter | affected | chainguard | fuse-overlayfs-snapshotter | — |
| ghaudit | affected | chainguard | ghaudit | — |
| ghaudit | affected | wolfi | ghaudit | — |
| gitlab-pages | affected | chainguard | gitlab-pages | — |
| gitlab-pages | affected | wolfi | gitlab-pages | — |
| gitlab-runner | affected | wolfi | gitlab-runner | — |
| gitlab-runner | affected | chainguard | gitlab-runner | — |
| gitleaks | affected | chainguard | gitleaks | — |
| gitleaks | affected | wolfi | gitleaks | — |
| git-lfs | affected | chainguard | git-lfs | — |
| git-lfs | affected | wolfi | git-lfs | — |
| gitness | affected | wolfi | gitness | — |
| gitness | affected | chainguard | gitness | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| glab | affected | wolfi | glab | — |
| glab | affected | chainguard | glab | — |
| go-1.22 | affected | wolfi | go-1.22 | — |
| go-1.22 | affected | chainguard | go-1.22 | — |
| go-bindata | affected | wolfi | go-bindata | — |
| go-bindata | affected | chainguard | go-bindata | — |
| gobump | affected | wolfi | gobump | — |
| gobump | affected | chainguard | gobump | — |
| go-ipfs-fips | affected | chainguard | go-ipfs-fips | — |
| golangci-lint | affected | chainguard | golangci-lint | — |
| golangci-lint | affected | wolfi | golangci-lint | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-licenses | affected | wolfi | go-licenses | — |
| go-md2man | affected | chainguard | go-md2man | — |
| go-md2man | affected | wolfi | go-md2man | — |
| gomplate | affected | chainguard | gomplate | — |
| gomplate | affected | wolfi | gomplate | — |
| gops | affected | chainguard | gops | — |
| gops | affected | wolfi | gops | — |
| gostatsd | affected | chainguard | gostatsd | — |
| gostatsd | affected | wolfi | gostatsd | — |
| gosu | affected | chainguard | gosu | — |
| gosu | affected | wolfi | gosu | — |
| gotenberg | affected | chainguard | gotenberg | — |
| govulncheck | affected | wolfi | govulncheck | — |
| govulncheck | affected | chainguard | govulncheck | — |
| gpu-operator | affected | chainguard | gpu-operator | — |
| grafana-agent-operator | affected | chainguard | grafana-agent-operator | — |
| grafana-agent-operator | affected | wolfi | grafana-agent-operator | — |
| grafana-operator | affected | wolfi | grafana-operator | — |
| grafana-operator | affected | chainguard | grafana-operator | — |
| grafana-rollout-operator-0.14 | affected | chainguard | grafana-rollout-operator-0.14 | — |
| grafana-rollout-operator-0.14 | affected | wolfi | grafana-rollout-operator-0.14 | — |
| grpcurl | affected | wolfi | grpcurl | — |
| grpcurl | affected | chainguard | grpcurl | — |
| guac | affected | wolfi | guac | — |
| guac | affected | chainguard | guac | — |
| harbor-2.10 | affected | chainguard | harbor-2.10 | — |
| harbor-2.10 | affected | wolfi | harbor-2.10 | — |
| harbor-2.8 | affected | chainguard | harbor-2.8 | — |
| harbor-2.9 | affected | chainguard | harbor-2.9 | — |
| harbor-cli | affected | chainguard | harbor-cli | — |
| harbor-cli | affected | wolfi | harbor-cli | — |
| harbor-fips-2.10 | affected | chainguard | harbor-fips-2.10 | — |
| harbor-fips-2.8 | affected | chainguard | harbor-fips-2.8 | — |
| harbor-fips-2.9 | affected | chainguard | harbor-fips-2.9 | — |
| harbor-registry | affected | wolfi | harbor-registry | — |
| harbor-registry | affected | chainguard | harbor-registry | — |
| harbor-registry-fips | affected | chainguard | harbor-registry-fips | — |
| harbor-scanner-trivy | affected | wolfi | harbor-scanner-trivy | — |
| harbor-scanner-trivy | affected | chainguard | harbor-scanner-trivy | — |
| harbor-scanner-trivy-fips | affected | chainguard | harbor-scanner-trivy-fips | — |
| hcloud | affected | chainguard | hcloud | — |
| hcloud | affected | wolfi | hcloud | — |
| hello-world-golang | affected | wolfi | hello-world-golang | — |
| hello-world-golang | affected | chainguard | hello-world-golang | — |
| helm | affected | chainguard | helm | — |
| helm | affected | wolfi | helm | — |
| helm-3 | affected | wolfi | helm-3 | — |
| helm-3 | affected | chainguard | helm-3 | — |
| helm-4 | affected | chainguard | helm-4 | — |
| helm-4 | affected | wolfi | helm-4 | — |
| helm-fips | affected | chainguard | helm-fips | — |
| helm-fips-3 | affected | chainguard | helm-fips-3 | — |
| helm-fips-4 | affected | chainguard | helm-fips-4 | — |
| helm-operator | affected | chainguard | helm-operator | — |
| helm-operator | affected | wolfi | helm-operator | — |
| helm-operator-fips | affected | chainguard | helm-operator-fips | — |
| helm-push | affected | wolfi | helm-push | — |
| helm-push | affected | chainguard | helm-push | — |
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| http-echo | affected | chainguard | http-echo | — |
| http-echo | affected | wolfi | http-echo | — |
| hubble-ui | affected | chainguard | hubble-ui | — |
| hubble-ui | affected | wolfi | hubble-ui | — |
| hubble-ui-backend-fips | affected | chainguard | hubble-ui-backend-fips | — |
| influx | affected | wolfi | influx | — |
| influx | affected | chainguard | influx | — |
| influxd | affected | wolfi | influxd | — |
| influxd | affected | chainguard | influxd | — |
| ipfs | affected | wolfi | ipfs | — |
| ipfs | affected | chainguard | ipfs | — |
| ip-masq-agent | affected | wolfi | ip-masq-agent | — |
| ip-masq-agent | affected | chainguard | ip-masq-agent | — |
| istio-operator-1.20 | affected | chainguard | istio-operator-1.20 | — |
| istio-operator-1.20 | affected | wolfi | istio-operator-1.20 | — |
| istio-operator-1.21 | affected | wolfi | istio-operator-1.21 | — |
| istio-operator-1.21 | affected | chainguard | istio-operator-1.21 | — |
| istio-operator-fips-1.19 | affected | chainguard | istio-operator-fips-1.19 | — |
| jitsucom-bulker | affected | chainguard | jitsucom-bulker | — |
| jitsucom-bulker | affected | wolfi | jitsucom-bulker | — |
| jsonnet-bundler | affected | chainguard | jsonnet-bundler | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| k9s | affected | wolfi | k9s | — |
| k9s | affected | chainguard | k9s | — |
| kaf | affected | chainguard | kaf | — |
| kaf | affected | wolfi | kaf | — |
| kafka_exporter | affected | chainguard | kafka_exporter | — |
| kafka_exporter | affected | wolfi | kafka_exporter | — |
| karpenter | affected | chainguard | karpenter | — |
| karpenter | affected | wolfi | karpenter | — |
| karpenter-0.23 | affected | chainguard | karpenter-0.23 | — |
| karpenter-0.35 | affected | chainguard | karpenter-0.35 | — |
| karpenter-fips-0.35 | affected | chainguard | karpenter-fips-0.35 | — |
| karpenter-fips-0.36 | affected | chainguard | karpenter-fips-0.36 | — |
| keda-fips | affected | chainguard | keda-fips | — |
| kind | affected | wolfi | kind | — |
| kind | affected | chainguard | kind | — |
| ko | affected | chainguard | ko | — |
| ko | affected | wolfi | ko | — |
| ko-fips | affected | chainguard | ko-fips | — |
| ko-fips | affected | wolfi | ko-fips | — |
| kpt | affected | chainguard | kpt | — |
| kpt | affected | wolfi | kpt | — |
| ksops | affected | wolfi | ksops | — |
| ksops | affected | chainguard | ksops | — |
| kubeadm-bootstrap-controller | affected | chainguard | kubeadm-bootstrap-controller | — |
| kubeadm-bootstrap-controller | affected | wolfi | kubeadm-bootstrap-controller | — |
| kube-bench | affected | chainguard | kube-bench | — |
| kube-bench | affected | wolfi | kube-bench | — |
| kube-bench-fips | affected | chainguard | kube-bench-fips | — |
| kubebuilder | affected | wolfi | kubebuilder | — |
| kubebuilder | affected | chainguard | kubebuilder | — |
| kubecolor | affected | wolfi | kubecolor | — |
| kubecolor | affected | chainguard | kubecolor | — |
| kube-oidc-proxy | affected | chainguard | kube-oidc-proxy | — |
| kubernetes-1.27 | affected | wolfi | kubernetes-1.27 | — |
| kubernetes-1.27 | affected | chainguard | kubernetes-1.27 | — |
| kubernetes-1.28 | affected | wolfi | kubernetes-1.28 | — |
| kubernetes-1.28 | affected | chainguard | kubernetes-1.28 | — |
| kubernetes-1.29 | affected | chainguard | kubernetes-1.29 | — |
| kubernetes-1.29 | affected | wolfi | kubernetes-1.29 | — |
| kubernetes-csi-driver-hostpath | affected | wolfi | kubernetes-csi-driver-hostpath | — |
| kubernetes-csi-driver-hostpath | affected | chainguard | kubernetes-csi-driver-hostpath | — |
| kubernetes-csi-external-attacher-4.3 | affected | chainguard | kubernetes-csi-external-attacher-4.3 | — |
| kubernetes-csi-external-attacher-4.3 | affected | wolfi | kubernetes-csi-external-attacher-4.3 | — |
| kubernetes-csi-external-attacher-4.4 | affected | chainguard | kubernetes-csi-external-attacher-4.4 | — |
| kubernetes-csi-external-attacher-4.4 | affected | wolfi | kubernetes-csi-external-attacher-4.4 | — |
| kubernetes-csi-external-attacher-fips-4.3 | affected | chainguard | kubernetes-csi-external-attacher-fips-4.3 | — |
| kubernetes-csi-external-attacher-fips-4.4 | affected | chainguard | kubernetes-csi-external-attacher-fips-4.4 | — |
| kubernetes-csi-external-provisioner | affected | wolfi | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-external-provisioner | affected | chainguard | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-external-resizer-1.10 | affected | wolfi | kubernetes-csi-external-resizer-1.10 | — |
| kubernetes-csi-external-resizer-1.10 | affected | chainguard | kubernetes-csi-external-resizer-1.10 | — |
| kubernetes-csi-external-resizer-1.8 | affected | chainguard | kubernetes-csi-external-resizer-1.8 | — |
| kubernetes-csi-external-resizer-1.9 | affected | chainguard | kubernetes-csi-external-resizer-1.9 | — |
| kubernetes-csi-external-resizer-fips-1.10 | affected | chainguard | kubernetes-csi-external-resizer-fips-1.10 | — |
| kubernetes-csi-external-resizer-fips-1.8 | affected | chainguard | kubernetes-csi-external-resizer-fips-1.8 | — |
| kubernetes-csi-external-resizer-fips-1.9 | affected | chainguard | kubernetes-csi-external-resizer-fips-1.9 | — |
| kubernetes-csi-external-snapshotter | affected | chainguard | kubernetes-csi-external-snapshotter | — |
| kubernetes-csi-external-snapshotter | affected | wolfi | kubernetes-csi-external-snapshotter | — |
| kubernetes-csi-external-snapshotter-6.0 | affected | chainguard | kubernetes-csi-external-snapshotter-6.0 | — |
| kubernetes-csi-livenessprobe | affected | chainguard | kubernetes-csi-livenessprobe | — |
| kubernetes-csi-livenessprobe | affected | wolfi | kubernetes-csi-livenessprobe | — |
| kubernetes-csi-livenessprobe-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-2.10 | — |
| kubernetes-csi-livenessprobe-fips | affected | chainguard | kubernetes-csi-livenessprobe-fips | — |
| kubernetes-csi-livenessprobe-fips-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-fips-2.10 | — |
| kubernetes-dashboard | affected | wolfi | kubernetes-dashboard | — |
| kubernetes-dashboard | affected | chainguard | kubernetes-dashboard | — |
| kubernetes-dashboard-fips | affected | chainguard | kubernetes-dashboard-fips | — |
| kubernetes-dashboard-metrics-scraper | affected | wolfi | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper | affected | chainguard | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper-fips | affected | chainguard | kubernetes-dashboard-metrics-scraper-fips | — |
| kubernetes-dns-node-cache | affected | chainguard | kubernetes-dns-node-cache | — |
| kubernetes-dns-node-cache | affected | wolfi | kubernetes-dns-node-cache | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
| kubernetes-fips-1.27 | affected | chainguard | kubernetes-fips-1.27 | — |
| kubernetes-fips-1.28 | affected | chainguard | kubernetes-fips-1.28 | — |
| kubernetes-fips-1.29 | affected | chainguard | kubernetes-fips-1.29 | — |
| kubernetes-ingress-defaultbackend | affected | wolfi | kubernetes-ingress-defaultbackend | — |
| kubernetes-ingress-defaultbackend | affected | chainguard | kubernetes-ingress-defaultbackend | — |
| kubescape | affected | wolfi | kubescape | — |
| kubescape | affected | chainguard | kubescape | — |
| kube-state-metrics | affected | wolfi | kube-state-metrics | — |
| kube-state-metrics | affected | chainguard | kube-state-metrics | — |
| kube-state-metrics-2.2.0 | affected | chainguard | kube-state-metrics-2.2.0 | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| kube-state-metrics-fips | affected | chainguard | kube-state-metrics-fips | — |
| kubewatch | affected | wolfi | kubewatch | — |
| kubewatch | affected | chainguard | kubewatch | — |
| kustomize | affected | wolfi | kustomize | — |
| kustomize | affected | chainguard | kustomize | — |
| kwok | affected | wolfi | kwok | — |
| kwok | affected | chainguard | kwok | — |
| kyverno | affected | wolfi | kyverno | — |
| kyverno | affected | chainguard | kyverno | — |
| kyverno-policy-reporter-kyverno-plugin | affected | wolfi | kyverno-policy-reporter-kyverno-plugin | — |
| kyverno-policy-reporter-kyverno-plugin | affected | chainguard | kyverno-policy-reporter-kyverno-plugin | — |
| kyverno-policy-reporter-ui | affected | chainguard | kyverno-policy-reporter-ui | — |
| kyverno-policy-reporter-ui | affected | wolfi | kyverno-policy-reporter-ui | — |
| lazygit | affected | wolfi | lazygit | — |
| lazygit | affected | chainguard | lazygit | — |
| libnvidia-container | affected | chainguard | libnvidia-container | — |
| libnvidia-container | affected | wolfi | libnvidia-container | — |
| litefs | affected | chainguard | litefs | — |
| litefs | affected | wolfi | litefs | — |
| litestream | affected | wolfi | litestream | — |
| litestream | affected | chainguard | litestream | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| local-static-provisioner | affected | wolfi | local-static-provisioner | — |
| local-static-provisioner | affected | chainguard | local-static-provisioner | — |
| logstash | affected | chainguard | logstash | — |
| logstash | affected | wolfi | logstash | — |
| logstash-exporter | affected | chainguard | logstash-exporter | — |
| logstash-exporter | affected | wolfi | logstash-exporter | — |
| logstash-exporter-fips | affected | chainguard | logstash-exporter-fips | — |
| loki | affected | wolfi | loki | — |
| loki | affected | chainguard | loki | — |
| mage | affected | chainguard | mage | — |
| mage | affected | wolfi | mage | — |
| mc | affected | wolfi | mc | — |
| mc | affected | chainguard | mc | — |
| mc-fips | affected | chainguard | mc-fips | — |
| melange | affected | chainguard | melange | — |
| melange | affected | wolfi | melange | — |
| metacontroller | affected | wolfi | metacontroller | — |
| metacontroller | affected | chainguard | metacontroller | — |
| metrics-server | affected | chainguard | metrics-server | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server-fips | affected | chainguard | metrics-server-fips | — |
| mkcert | affected | wolfi | mkcert | — |
| mkcert | affected | chainguard | mkcert | — |
| mockery | affected | chainguard | mockery | — |
| mockery | affected | wolfi | mockery | — |
| mods | affected | wolfi | mods | — |
| mods | affected | chainguard | mods | — |
| mongo-tools | affected | chainguard | mongo-tools | — |
| mongo-tools | affected | wolfi | mongo-tools | — |
| multus-cni | affected | wolfi | multus-cni | — |
| multus-cni | affected | chainguard | multus-cni | — |
| multus-cni-fips | affected | chainguard | multus-cni-fips | — |
| nats-server | affected | wolfi | nats-server | — |
| nats-server | affected | chainguard | nats-server | — |
| neuvector-scanner | affected | chainguard | neuvector-scanner | — |
| neuvector-scanner | affected | wolfi | neuvector-scanner | — |
| newrelic-infra-operator | affected | wolfi | newrelic-infra-operator | — |
| newrelic-infra-operator | affected | chainguard | newrelic-infra-operator | — |
| newrelic-infrastructure-agent-1.43 | affected | chainguard | newrelic-infrastructure-agent-1.43 | — |
| newrelic-nri-kube-events-1.9 | affected | chainguard | newrelic-nri-kube-events-1.9 | — |
| newrelic-nri-statsd | affected | chainguard | newrelic-nri-statsd | — |
| newrelic-nri-statsd | affected | wolfi | newrelic-nri-statsd | — |
| newrelic-prometheus-configurator | affected | chainguard | newrelic-prometheus-configurator | — |
| newrelic-prometheus-configurator | affected | wolfi | newrelic-prometheus-configurator | — |
| nfs-subdir-external-provisioner | affected | wolfi | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner | affected | chainguard | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner-fips | affected | chainguard | nfs-subdir-external-provisioner-fips | — |
| node-feature-discovery-0.14 | affected | chainguard | node-feature-discovery-0.14 | — |
| node-feature-discovery-0.15 | affected | chainguard | node-feature-discovery-0.15 | — |
| node-feature-discovery-0.15 | affected | wolfi | node-feature-discovery-0.15 | — |
| nri-prometheus | affected | chainguard | nri-prometheus | — |
| nri-prometheus | affected | wolfi | nri-prometheus | — |
| nvidia-container-toolkit | affected | chainguard | nvidia-container-toolkit | — |
| nvidia-container-toolkit | affected | wolfi | nvidia-container-toolkit | — |
| oauth2-proxy | affected | wolfi | oauth2-proxy | — |
| oauth2-proxy | affected | chainguard | oauth2-proxy | — |
| opa | affected | chainguard | opa | — |
| opa | affected | wolfi | opa | — |
| opentelemetry-collector-contrib-fips | affected | chainguard | opentelemetry-collector-contrib-fips | — |
| opentelemetry-collector-fips | affected | chainguard | opentelemetry-collector-fips | — |
| oras | affected | chainguard | oras | — |
| oras | affected | wolfi | oras | — |
| osv-scanner | affected | wolfi | osv-scanner | — |
| osv-scanner | affected | chainguard | osv-scanner | — |
| overmind | affected | chainguard | overmind | — |
| overmind | affected | wolfi | overmind | — |
| paranoia | affected | wolfi | paranoia | — |
| paranoia | affected | chainguard | paranoia | — |
| petname | affected | wolfi | petname | — |
| petname | affected | chainguard | petname | — |
| php-fpm_exporter | affected | chainguard | php-fpm_exporter | — |
| php-fpm_exporter | affected | wolfi | php-fpm_exporter | — |
| policy-controller | affected | wolfi | policy-controller | — |
| policy-controller | affected | chainguard | policy-controller | — |
| policy-controller-fips | affected | chainguard | policy-controller-fips | — |
| pombump | affected | wolfi | pombump | — |
| pombump | affected | chainguard | pombump | — |
| prometheus-adapter | affected | wolfi | prometheus-adapter | — |
| prometheus-adapter | affected | chainguard | prometheus-adapter | — |
| prometheus-adapter-0.10 | affected | chainguard | prometheus-adapter-0.10 | — |
| prometheus-adapter-fips | affected | chainguard | prometheus-adapter-fips | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-alertmanager | affected | chainguard | prometheus-alertmanager | — |
| prometheus-alertmanager | affected | wolfi | prometheus-alertmanager | — |
| prometheus-alertmanager-fips | affected | chainguard | prometheus-alertmanager-fips | — |
| prometheus-beat-exporter | affected | chainguard | prometheus-beat-exporter | — |
| prometheus-beat-exporter | affected | wolfi | prometheus-beat-exporter | — |
| prometheus-beat-exporter-fips | affected | chainguard | prometheus-beat-exporter-fips | — |
| prometheus-bind-exporter | affected | wolfi | prometheus-bind-exporter | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-elasticsearch-exporter-fips | affected | chainguard | prometheus-elasticsearch-exporter-fips | — |
| prometheus-fips-2.45 | affected | chainguard | prometheus-fips-2.45 | — |
| prometheus-mongodb-exporter-0.37 | affected | chainguard | prometheus-mongodb-exporter-0.37 | — |
| prometheus-mongodb-exporter-fips | affected | chainguard | prometheus-mongodb-exporter-fips | — |
| prometheus-mongodb-exporter-fips-0.37 | affected | chainguard | prometheus-mongodb-exporter-fips-0.37 | — |
| prometheus-mysqld-exporter | affected | chainguard | prometheus-mysqld-exporter | — |
| prometheus-mysqld-exporter | affected | wolfi | prometheus-mysqld-exporter | — |
| prometheus-nats-exporter | affected | wolfi | prometheus-nats-exporter | — |
| prometheus-nats-exporter | affected | chainguard | prometheus-nats-exporter | — |
| prometheus-node-exporter-fips | affected | chainguard | prometheus-node-exporter-fips | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| prometheus-postgres-exporter-0.13 | affected | chainguard | prometheus-postgres-exporter-0.13 | — |
| prometheus-postgres-exporter-fips | affected | chainguard | prometheus-postgres-exporter-fips | — |
| prometheus-pushgateway | affected | wolfi | prometheus-pushgateway | — |
| prometheus-pushgateway | affected | chainguard | prometheus-pushgateway | — |
| prometheus-pushgateway-fips | affected | chainguard | prometheus-pushgateway-fips | — |
| prometheus-pushgateway-fips-1.4 | affected | chainguard | prometheus-pushgateway-fips-1.4 | — |
| prometheus-redis-exporter | affected | wolfi | prometheus-redis-exporter | — |
| prometheus-redis-exporter | affected | chainguard | prometheus-redis-exporter | — |
| prometheus-redis-exporter-fips | affected | chainguard | prometheus-redis-exporter-fips | — |
| prometheus-redis-exporter-fips-1.44 | affected | chainguard | prometheus-redis-exporter-fips-1.44 | — |
| prometheus-stackdriver-exporter | affected | wolfi | prometheus-stackdriver-exporter | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter | affected | wolfi | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter | affected | chainguard | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter-0.22 | affected | chainguard | prometheus-statsd-exporter-0.22 | — |
| prometheus-statsd-exporter-fips | affected | chainguard | prometheus-statsd-exporter-fips | — |
| prometheus-statsd-exporter-fips-0.22 | affected | chainguard | prometheus-statsd-exporter-fips-0.22 | — |
| pulumi-kubernetes-operator | affected | wolfi | pulumi-kubernetes-operator | — |
| pulumi-kubernetes-operator | affected | chainguard | pulumi-kubernetes-operator | — |
| pulumi-language-dotnet | affected | chainguard | pulumi-language-dotnet | — |
| pulumi-language-dotnet | affected | wolfi | pulumi-language-dotnet | — |
| pulumi-language-yaml | affected | chainguard | pulumi-language-yaml | — |
| pulumi-language-yaml | affected | wolfi | pulumi-language-yaml | — |
| q | affected | chainguard | q | — |
| q | affected | wolfi | q | — |
| rabbitmq-default-user-credential-updater | affected | chainguard | rabbitmq-default-user-credential-updater | — |
| rabbitmq-default-user-credential-updater | affected | wolfi | rabbitmq-default-user-credential-updater | — |
| rclone | affected | wolfi | rclone | — |
| rclone | affected | chainguard | rclone | — |
| redka | affected | wolfi | redka | — |
| redka | affected | chainguard | redka | — |
| regclient | affected | chainguard | regclient | — |
| regclient | affected | wolfi | regclient | — |
| rekor | affected | wolfi | rekor | — |
| rekor | affected | chainguard | rekor | — |
| rekor-fips | affected | chainguard | rekor-fips | — |
| render-template | affected | wolfi | render-template | — |
| render-template | affected | chainguard | render-template | — |
| rootlesskit | affected | wolfi | rootlesskit | — |
| rootlesskit | affected | chainguard | rootlesskit | — |
| runc | affected | chainguard | runc | — |
| runc | affected | wolfi | runc | — |
| s5cmd | affected | chainguard | s5cmd | — |
| s5cmd | affected | wolfi | s5cmd | — |
| scorecard | affected | chainguard | scorecard | — |
| scorecard | affected | wolfi | scorecard | — |
| secrets-store-csi-driver | affected | chainguard | secrets-store-csi-driver | — |
| secrets-store-csi-driver | affected | wolfi | secrets-store-csi-driver | — |
| secrets-store-csi-driver-provider-aws | affected | wolfi | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-aws | affected | chainguard | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-azure | affected | wolfi | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-azure | affected | chainguard | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-gcp | affected | chainguard | secrets-store-csi-driver-provider-gcp | — |
| secrets-store-csi-driver-provider-gcp | affected | wolfi | secrets-store-csi-driver-provider-gcp | — |
| shfmt | affected | chainguard | shfmt | — |
| shfmt | affected | wolfi | shfmt | — |
| skaffold | affected | chainguard | skaffold | — |
| skaffold | affected | wolfi | skaffold | — |
| skopeo | affected | chainguard | skopeo | — |
| skopeo | affected | wolfi | skopeo | — |
| smarter-device-manager | affected | chainguard | smarter-device-manager | — |
| smarter-device-manager | affected | wolfi | smarter-device-manager | — |
| smarter-device-manager-fips | affected | chainguard | smarter-device-manager-fips | — |
| snyk-cli | affected | wolfi | snyk-cli | — |
| snyk-cli | affected | chainguard | snyk-cli | — |
| sonobuoy | affected | wolfi | sonobuoy | — |
| sonobuoy | affected | chainguard | sonobuoy | — |
| sops | affected | wolfi | sops | — |
| sops | affected | chainguard | sops | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spegel | affected | wolfi | spegel | — |
| spegel | affected | chainguard | spegel | — |
| spicedb | affected | wolfi | spicedb | — |
| spicedb | affected | chainguard | spicedb | — |
| spqr | affected | chainguard | spqr | — |
| spqr | affected | wolfi | spqr | — |
| src | affected | chainguard | src | — |
| src | affected | wolfi | src | — |
| src-fingerprint | affected | chainguard | src-fingerprint | — |
| src-fingerprint | affected | wolfi | src-fingerprint | — |
| step | affected | wolfi | step | — |
| step | affected | chainguard | step | — |
| step-ca | affected | wolfi | step-ca | — |
| step-ca | affected | chainguard | step-ca | — |
| step-ca-fips | affected | chainguard | step-ca-fips | — |
| step-fips | affected | chainguard | step-fips | — |
| stern | affected | chainguard | stern | — |
| stern | affected | wolfi | stern | — |
| tekton-chains | affected | wolfi | tekton-chains | — |
| tekton-chains | affected | chainguard | tekton-chains | — |
| tekton-chains-fips | affected | chainguard | tekton-chains-fips | — |
| tekton-pipelines | affected | wolfi | tekton-pipelines | — |
| tekton-pipelines | affected | chainguard | tekton-pipelines | — |
| tekton-pipelines-fips | affected | chainguard | tekton-pipelines-fips | — |
| telegraf-1.29 | affected | wolfi | telegraf-1.29 | — |
| telegraf-1.29 | affected | chainguard | telegraf-1.29 | — |
| telegraf-1.30 | affected | wolfi | telegraf-1.30 | — |
| telegraf-1.30 | affected | chainguard | telegraf-1.30 | — |
| tempo | affected | chainguard | tempo | — |
| tempo | affected | wolfi | tempo | — |
| terraform-docs | affected | chainguard | terraform-docs | — |
| terraform-docs | affected | wolfi | terraform-docs | — |
| tfsec | affected | chainguard | tfsec | — |
| tfsec | affected | wolfi | tfsec | — |
| thanos | affected | wolfi | thanos | — |
| thanos | affected | chainguard | thanos | — |
| thanos-fips | affected | chainguard | thanos-fips | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| tigera-operator-1.30 | affected | wolfi | tigera-operator-1.30 | — |
| tigera-operator-1.30 | affected | chainguard | tigera-operator-1.30 | — |
| tigera-operator-1.31 | affected | chainguard | tigera-operator-1.31 | — |
| tigera-operator-1.31 | affected | wolfi | tigera-operator-1.31 | — |
| tigera-operator-1.32 | affected | wolfi | tigera-operator-1.32 | — |
| tigera-operator-1.32 | affected | chainguard | tigera-operator-1.32 | — |
| tigera-operator-1.33 | affected | chainguard | tigera-operator-1.33 | — |
| tigera-operator-1.33 | affected | wolfi | tigera-operator-1.33 | — |
| tigera-operator-fips-1.29 | affected | chainguard | tigera-operator-fips-1.29 | — |
| timestamp-authority-fips | affected | chainguard | timestamp-authority-fips | — |
| timoni | affected | wolfi | timoni | — |
| timoni | affected | chainguard | timoni | — |
| traefik | affected | chainguard | traefik | — |
| traefik | affected | wolfi | traefik | — |
| traefik-fips | affected | chainguard | traefik-fips | — |
| trillian | affected | chainguard | trillian | — |
| trillian | affected | wolfi | trillian | — |
| trillian-fips | affected | chainguard | trillian-fips | — |
| trivy | affected | wolfi | trivy | — |
| trivy | affected | chainguard | trivy | — |
| trust-manager | affected | chainguard | trust-manager | — |
| trust-manager | affected | wolfi | trust-manager | — |
| trust-manager-fips | affected | chainguard | trust-manager-fips | — |
| vault-1.16 | affected | chainguard | vault-1.16 | — |
| vault-k8s | affected | chainguard | vault-k8s | — |
| vault-k8s | affected | wolfi | vault-k8s | — |
| vault-k8s-fips | affected | chainguard | vault-k8s-fips | — |
| vertical-pod-autoscaler | affected | wolfi | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler | affected | chainguard | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler-fips | affected | chainguard | vertical-pod-autoscaler-fips | — |
| volume-modifier-for-k8s | affected | wolfi | volume-modifier-for-k8s | — |
| volume-modifier-for-k8s | affected | chainguard | volume-modifier-for-k8s | — |
| vt-cli | affected | wolfi | vt-cli | — |
| vt-cli | affected | chainguard | vt-cli | — |
| wait-for-port | affected | chainguard | wait-for-port | — |
| wait-for-port | affected | wolfi | wait-for-port | — |
| wave | affected | chainguard | wave | — |
| wave | affected | wolfi | wave | — |
| wave-fips | affected | chainguard | wave-fips | — |
| wavefront-collector-for-kubernetes-1.12 | affected | chainguard | wavefront-collector-for-kubernetes-1.12 | — |
| wavefront-collector-for-kubernetes-1.13 | affected | chainguard | wavefront-collector-for-kubernetes-1.13 | — |
| wgcf | affected | chainguard | wgcf | — |
| wgcf | affected | wolfi | wgcf | — |
| wire-go | affected | wolfi | wire-go | — |
| wire-go | affected | chainguard | wire-go | — |
| wireguard-go | affected | chainguard | wireguard-go | — |
| wireguard-go | affected | wolfi | wireguard-go | — |
| zot | affected | wolfi | zot | — |
| zot | affected | chainguard | zot | — |
CVE-2024-24788 affecting package golang for versions less than 1.22.3-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVE-2024-24788 affecting package msft-golang for versions less than 1.22.3
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| msft-golang | affected | Azure Linux:2 | msft-golang | — |
CVE-2024-24788 affecting package golang for versions less than 1.22.3
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2024-24788 affecting package golang for versions less than 1.22.3-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2024-24788 affecting package golang for versions less than 1.22.3
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2024-24788 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
Malformed DNS message can cause infinite loop in net
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | wolfi | aactl | — |
| aactl | affected | chainguard | aactl | — |
| actions-runner-controller-fips | affected | chainguard | actions-runner-controller-fips | — |
| addon-resizer-fips | affected | chainguard | addon-resizer-fips | — |
| argo-workflows-fips | affected | chainguard | argo-workflows-fips | — |
| atlantis | affected | chainguard | atlantis | — |
| atlantis | affected | wolfi | atlantis | — |
| atlantis-fips | affected | chainguard | atlantis-fips | — |
| aws-ebs-csi-driver | affected | chainguard | aws-ebs-csi-driver | — |
| aws-efs-csi-driver | affected | chainguard | aws-efs-csi-driver | — |
| aws-efs-csi-driver | affected | wolfi | aws-efs-csi-driver | — |
| aws-efs-csi-driver-fips | affected | chainguard | aws-efs-csi-driver-fips | — |
| aws-flb-cloudwatch-fips | affected | chainguard | aws-flb-cloudwatch-fips | — |
| aws-flb-firehose-fips | affected | chainguard | aws-flb-firehose-fips | — |
| aws-flb-kinesis-fips | affected | chainguard | aws-flb-kinesis-fips | — |
| aws-load-balancer-controller-fips | affected | chainguard | aws-load-balancer-controller-fips | — |
| azure-aad-pod-identity-mic | affected | chainguard | azure-aad-pod-identity-mic | — |
| bank-vaults | affected | chainguard | bank-vaults | — |
| bank-vaults | affected | wolfi | bank-vaults | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| bom | affected | chainguard | bom | — |
| bom | affected | wolfi | bom | — |
| boring-registry | affected | wolfi | boring-registry | — |
| boring-registry | affected | chainguard | boring-registry | — |
| boring-registry-fips | affected | chainguard | boring-registry-fips | — |
| buildkitd | affected | chainguard | buildkitd | — |
| buildkitd | affected | wolfi | buildkitd | — |
| caddy | affected | chainguard | caddy | — |
| caddy | affected | wolfi | caddy | — |
| caddy-fips | affected | chainguard | caddy-fips | — |
| cadvisor | affected | wolfi | cadvisor | — |
| cadvisor | affected | chainguard | cadvisor | — |
| cadvisor-fips | affected | chainguard | cadvisor-fips | — |
| capslock | affected | wolfi | capslock | — |
| capslock | affected | chainguard | capslock | — |
| cass-operator-fips | affected | chainguard | cass-operator-fips | — |
| cass-operator-fips-no-pvc-delete | affected | chainguard | cass-operator-fips-no-pvc-delete | — |
| cert-exporter | affected | wolfi | cert-exporter | — |
| cert-exporter | affected | chainguard | cert-exporter | — |
| cert-exporter-fips | affected | chainguard | cert-exporter-fips | — |
| certificate-transparency | affected | chainguard | certificate-transparency | — |
| certificate-transparency | affected | wolfi | certificate-transparency | — |
| certificate-transparency-fips | affected | chainguard | certificate-transparency-fips | — |
| cert-manager-webhook-pdns | affected | wolfi | cert-manager-webhook-pdns | — |
| cert-manager-webhook-pdns | affected | chainguard | cert-manager-webhook-pdns | — |
| cert-manager-webhook-pdns-fips | affected | chainguard | cert-manager-webhook-pdns-fips | — |
| cfssl | affected | chainguard | cfssl | — |
| cfssl | affected | wolfi | cfssl | — |
| chainctl | affected | chainguard | chainctl | — |
| chartmuseum | affected | wolfi | chartmuseum | — |
| chartmuseum | affected | chainguard | chartmuseum | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cilium-fips-1.15 | affected | chainguard | cilium-fips-1.15 | — |
| cloudflared | affected | wolfi | cloudflared | — |
| cloudflared | affected | chainguard | cloudflared | — |
| configmap-reload | affected | chainguard | configmap-reload | — |
| configmap-reload | affected | wolfi | configmap-reload | — |
| configmap-reload-fips | affected | chainguard | configmap-reload-fips | — |
| configmap-reload-fips-0.11 | affected | chainguard | configmap-reload-fips-0.11 | — |
| confluent-common-docker | affected | wolfi | confluent-common-docker | — |
| confluent-common-docker | affected | chainguard | confluent-common-docker | — |
| conftest | affected | wolfi | conftest | — |
| conftest | affected | chainguard | conftest | — |
| conftest-fips | affected | chainguard | conftest-fips | — |
| cortex | affected | wolfi | cortex | — |
| cortex | affected | chainguard | cortex | — |
| cortex-fips | affected | chainguard | cortex-fips | — |
| cosign | affected | wolfi | cosign | — |
| cosign | affected | chainguard | cosign | — |
| cosign-fips | affected | chainguard | cosign-fips | — |
| crane | affected | chainguard | crane | — |
| crane | affected | wolfi | crane | — |
| cri-tools | affected | wolfi | cri-tools | — |
| cri-tools | affected | chainguard | cri-tools | — |
| croc | affected | wolfi | croc | — |
| croc | affected | chainguard | croc | — |
| crossplane-provider-aws | affected | wolfi | crossplane-provider-aws | — |
| crossplane-provider-aws | affected | chainguard | crossplane-provider-aws | — |
| crossplane-provider-azure | affected | wolfi | crossplane-provider-azure | — |
| crossplane-provider-azure | affected | chainguard | crossplane-provider-azure | — |
| crossplane-provider-gcp | affected | chainguard | crossplane-provider-gcp | — |
| ctop | affected | chainguard | ctop | — |
| ctop | affected | wolfi | ctop | — |
| cue | affected | wolfi | cue | — |
| cue | affected | chainguard | cue | — |
| cue-fips | affected | chainguard | cue-fips | — |
| dask-gateway | affected | chainguard | dask-gateway | — |
| dask-gateway | affected | wolfi | dask-gateway | — |
| delve | affected | chainguard | delve | — |
| delve | affected | wolfi | delve | — |
| dex | affected | wolfi | dex | — |
| dex | affected | chainguard | dex | — |
| dex-fips | affected | chainguard | dex-fips | — |
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| dgraph | affected | chainguard | dgraph | — |
| dgraph | affected | wolfi | dgraph | — |
| direnv | affected | chainguard | direnv | — |
| direnv | affected | wolfi | direnv | — |
| dive | affected | wolfi | dive | — |
| dive | affected | chainguard | dive | — |
| docker-compose | affected | wolfi | docker-compose | — |
| docker-compose | affected | chainguard | docker-compose | — |
| docker-credential-acr-env | affected | chainguard | docker-credential-acr-env | — |
| docker-credential-acr-env | affected | wolfi | docker-credential-acr-env | — |
| docker-credential-ecr-login | affected | wolfi | docker-credential-ecr-login | — |
| docker-credential-ecr-login | affected | chainguard | docker-credential-ecr-login | — |
| docker-credential-gcr | affected | chainguard | docker-credential-gcr | — |
| docker-credential-gcr | affected | wolfi | docker-credential-gcr | — |
| dockerize | affected | chainguard | dockerize | — |
| dockerize | affected | wolfi | dockerize | — |
| dockerize-fips | affected | chainguard | dockerize-fips | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| eck-operator | affected | chainguard | eck-operator | — |
| eksctl | affected | wolfi | eksctl | — |
| eksctl | affected | chainguard | eksctl | — |
| etcd-3.4 | affected | chainguard | etcd-3.4 | — |
| etcd-3.5 | affected | chainguard | etcd-3.5 | — |
| etcd-fips-3.4 | affected | chainguard | etcd-fips-3.4 | — |
| etcd-fips-3.5 | affected | chainguard | etcd-fips-3.5 | — |
| external-secrets-fips | affected | chainguard | external-secrets-fips | — |
| extism | affected | chainguard | extism | — |
| extism | affected | wolfi | extism | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| falcoctl-fips-0.4 | affected | chainguard | falcoctl-fips-0.4 | — |
| falcosidekick | affected | wolfi | falcosidekick | — |
| falcosidekick | affected | chainguard | falcosidekick | — |
| falcosidekick-fips | affected | chainguard | falcosidekick-fips | — |
| ferretdb | affected | chainguard | ferretdb | — |
| ferretdb | affected | wolfi | ferretdb | — |
| flannel | affected | chainguard | flannel | — |
| flannel | affected | wolfi | flannel | — |
| flux-image-reflector-controller | affected | chainguard | flux-image-reflector-controller | — |
| flux-image-reflector-controller | affected | wolfi | flux-image-reflector-controller | — |
| flux-kustomize-controller | affected | wolfi | flux-kustomize-controller | — |
| flux-kustomize-controller | affected | chainguard | flux-kustomize-controller | — |
| flux-notification-controller | affected | chainguard | flux-notification-controller | — |
| flux-notification-controller | affected | wolfi | flux-notification-controller | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flyte | affected | wolfi | flyte | — |
| flyte | affected | chainguard | flyte | — |
| frp | affected | wolfi | frp | — |
| frp | affected | chainguard | frp | — |
| fulcio | affected | chainguard | fulcio | — |
| fulcio | affected | wolfi | fulcio | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| fuse-overlayfs-snapshotter | affected | wolfi | fuse-overlayfs-snapshotter | — |
| fuse-overlayfs-snapshotter | affected | chainguard | fuse-overlayfs-snapshotter | — |
| ghaudit | affected | wolfi | ghaudit | — |
| ghaudit | affected | chainguard | ghaudit | — |
| gitleaks | affected | wolfi | gitleaks | — |
| gitleaks | affected | chainguard | gitleaks | — |
| git-lfs | affected | wolfi | git-lfs | — |
| git-lfs | affected | chainguard | git-lfs | — |
| gitness | affected | chainguard | gitness | — |
| gitness | affected | wolfi | gitness | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| glab | affected | chainguard | glab | — |
| glab | affected | wolfi | glab | — |
| go-1.22 | affected | wolfi | go-1.22 | — |
| go-1.22 | affected | chainguard | go-1.22 | — |
| go-bindata | affected | chainguard | go-bindata | — |
| go-bindata | affected | wolfi | go-bindata | — |
| gobump | affected | wolfi | gobump | — |
| gobump | affected | chainguard | gobump | — |
| golangci-lint | affected | chainguard | golangci-lint | — |
| golangci-lint | affected | wolfi | golangci-lint | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-licenses | affected | wolfi | go-licenses | — |
| go-md2man | affected | chainguard | go-md2man | — |
| go-md2man | affected | wolfi | go-md2man | — |
| gomplate | affected | wolfi | gomplate | — |
| gomplate | affected | chainguard | gomplate | — |
| gops | affected | wolfi | gops | — |
| gops | affected | chainguard | gops | — |
| gostatsd | affected | wolfi | gostatsd | — |
| gostatsd | affected | chainguard | gostatsd | — |
| gosu | affected | wolfi | gosu | — |
| gosu | affected | chainguard | gosu | — |
| gotenberg | affected | chainguard | gotenberg | — |
| govulncheck | affected | chainguard | govulncheck | — |
| govulncheck | affected | wolfi | govulncheck | — |
| grafana-agent-operator | affected | chainguard | grafana-agent-operator | — |
| grafana-agent-operator | affected | wolfi | grafana-agent-operator | — |
| grafana-operator | affected | wolfi | grafana-operator | — |
| grafana-operator | affected | chainguard | grafana-operator | — |
| grpcurl | affected | wolfi | grpcurl | — |
| grpcurl | affected | chainguard | grpcurl | — |
| guac | affected | chainguard | guac | — |
| guac | affected | wolfi | guac | — |
| harbor-cli | affected | chainguard | harbor-cli | — |
| harbor-cli | affected | wolfi | harbor-cli | — |
| harbor-registry | affected | chainguard | harbor-registry | — |
| harbor-registry | affected | wolfi | harbor-registry | — |
| harbor-registry-fips | affected | chainguard | harbor-registry-fips | — |
| harbor-scanner-trivy | affected | chainguard | harbor-scanner-trivy | — |
| harbor-scanner-trivy | affected | wolfi | harbor-scanner-trivy | — |
| harbor-scanner-trivy-fips | affected | chainguard | harbor-scanner-trivy-fips | — |
| hcloud | affected | wolfi | hcloud | — |
| hcloud | affected | chainguard | hcloud | — |
| hello-world-golang | affected | wolfi | hello-world-golang | — |
| hello-world-golang | affected | chainguard | hello-world-golang | — |
| helm | affected | wolfi | helm | — |
| helm | affected | chainguard | helm | — |
| helm-3 | affected | chainguard | helm-3 | — |
| helm-3 | affected | wolfi | helm-3 | — |
| helm-4 | affected | wolfi | helm-4 | — |
| helm-4 | affected | chainguard | helm-4 | — |
| helm-fips | affected | chainguard | helm-fips | — |
| helm-fips-3 | affected | chainguard | helm-fips-3 | — |
| helm-fips-4 | affected | chainguard | helm-fips-4 | — |
| helm-operator | affected | chainguard | helm-operator | — |
| helm-operator | affected | wolfi | helm-operator | — |
| helm-operator-fips | affected | chainguard | helm-operator-fips | — |
| helm-push | affected | chainguard | helm-push | — |
| helm-push | affected | wolfi | helm-push | — |
| hey | affected | wolfi | hey | — |
| hey | affected | chainguard | hey | — |
| http-echo | affected | chainguard | http-echo | — |
| http-echo | affected | wolfi | http-echo | — |
| hubble-ui | affected | chainguard | hubble-ui | — |
| hubble-ui | affected | wolfi | hubble-ui | — |
| hubble-ui-backend-fips | affected | chainguard | hubble-ui-backend-fips | — |
| influx | affected | wolfi | influx | — |
| influx | affected | chainguard | influx | — |
| ip-masq-agent | affected | wolfi | ip-masq-agent | — |
| ip-masq-agent | affected | chainguard | ip-masq-agent | — |
| jitsucom-bulker | affected | wolfi | jitsucom-bulker | — |
| jitsucom-bulker | affected | chainguard | jitsucom-bulker | — |
| jsonnet-bundler | affected | chainguard | jsonnet-bundler | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| k9s | affected | chainguard | k9s | — |
| k9s | affected | wolfi | k9s | — |
| kaf | affected | wolfi | kaf | — |
| kaf | affected | chainguard | kaf | — |
| kafka_exporter | affected | wolfi | kafka_exporter | — |
| kafka_exporter | affected | chainguard | kafka_exporter | — |
| karpenter-0.35 | affected | chainguard | karpenter-0.35 | — |
| karpenter-fips-0.35 | affected | chainguard | karpenter-fips-0.35 | — |
| karpenter-fips-0.36 | affected | chainguard | karpenter-fips-0.36 | — |
| kind | affected | wolfi | kind | — |
| kind | affected | chainguard | kind | — |
| ko | affected | chainguard | ko | — |
| ko | affected | wolfi | ko | — |
| ko-fips | affected | chainguard | ko-fips | — |
| kpt | affected | chainguard | kpt | — |
| kpt | affected | wolfi | kpt | — |
| ksops | affected | wolfi | ksops | — |
| ksops | affected | chainguard | ksops | — |
| kube-bench | affected | wolfi | kube-bench | — |
| kube-bench | affected | chainguard | kube-bench | — |
| kube-bench-fips | affected | chainguard | kube-bench-fips | — |
| kubebuilder | affected | chainguard | kubebuilder | — |
| kubebuilder | affected | wolfi | kubebuilder | — |
| kubecolor | affected | chainguard | kubecolor | — |
| kubecolor | affected | wolfi | kubecolor | — |
| kube-oidc-proxy | affected | chainguard | kube-oidc-proxy | — |
| kubernetes-csi-driver-hostpath | affected | wolfi | kubernetes-csi-driver-hostpath | — |
| kubernetes-csi-driver-hostpath | affected | chainguard | kubernetes-csi-driver-hostpath | — |
| kubernetes-csi-external-provisioner | affected | wolfi | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-external-provisioner | affected | chainguard | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-livenessprobe | affected | wolfi | kubernetes-csi-livenessprobe | — |
| kubernetes-csi-livenessprobe | affected | chainguard | kubernetes-csi-livenessprobe | — |
| kubernetes-csi-livenessprobe-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-2.10 | — |
| kubernetes-csi-livenessprobe-fips | affected | chainguard | kubernetes-csi-livenessprobe-fips | — |
| kubernetes-csi-livenessprobe-fips-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-fips-2.10 | — |
| kubernetes-dashboard | affected | wolfi | kubernetes-dashboard | — |
| kubernetes-dashboard | affected | chainguard | kubernetes-dashboard | — |
| kubernetes-dashboard-fips | affected | chainguard | kubernetes-dashboard-fips | — |
| kubernetes-dashboard-metrics-scraper | affected | wolfi | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper | affected | chainguard | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper-fips | affected | chainguard | kubernetes-dashboard-metrics-scraper-fips | — |
| kubernetes-dns-node-cache | affected | wolfi | kubernetes-dns-node-cache | — |
| kubernetes-dns-node-cache | affected | chainguard | kubernetes-dns-node-cache | — |
| kubernetes-ingress-defaultbackend | affected | chainguard | kubernetes-ingress-defaultbackend | — |
| kubernetes-ingress-defaultbackend | affected | wolfi | kubernetes-ingress-defaultbackend | — |
| kubescape | affected | wolfi | kubescape | — |
| kubescape | affected | chainguard | kubescape | — |
| kube-state-metrics | affected | wolfi | kube-state-metrics | — |
| kube-state-metrics | affected | chainguard | kube-state-metrics | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| kube-state-metrics-fips | affected | chainguard | kube-state-metrics-fips | — |
| kubewatch | affected | chainguard | kubewatch | — |
| kubewatch | affected | wolfi | kubewatch | — |
| kustomize | affected | wolfi | kustomize | — |
| kustomize | affected | chainguard | kustomize | — |
| kwok | affected | chainguard | kwok | — |
| kwok | affected | wolfi | kwok | — |
| kyverno-policy-reporter-kyverno-plugin | affected | chainguard | kyverno-policy-reporter-kyverno-plugin | — |
| kyverno-policy-reporter-kyverno-plugin | affected | wolfi | kyverno-policy-reporter-kyverno-plugin | — |
| kyverno-policy-reporter-ui | affected | wolfi | kyverno-policy-reporter-ui | — |
| kyverno-policy-reporter-ui | affected | chainguard | kyverno-policy-reporter-ui | — |
| lazygit | affected | wolfi | lazygit | — |
| lazygit | affected | chainguard | lazygit | — |
| libnvidia-container | affected | wolfi | libnvidia-container | — |
| libnvidia-container | affected | chainguard | libnvidia-container | — |
| litefs | affected | chainguard | litefs | — |
| litefs | affected | wolfi | litefs | — |
| litestream | affected | wolfi | litestream | — |
| litestream | affected | chainguard | litestream | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| local-static-provisioner | affected | wolfi | local-static-provisioner | — |
| local-static-provisioner | affected | chainguard | local-static-provisioner | — |
| logstash-exporter | affected | chainguard | logstash-exporter | — |
| logstash-exporter | affected | wolfi | logstash-exporter | — |
| logstash-exporter-fips | affected | chainguard | logstash-exporter-fips | — |
| mage | affected | chainguard | mage | — |
| mage | affected | wolfi | mage | — |
| mc | affected | chainguard | mc | — |
| mc | affected | wolfi | mc | — |
| mc-fips | affected | chainguard | mc-fips | — |
| melange | affected | chainguard | melange | — |
| melange | affected | wolfi | melange | — |
| metacontroller | affected | chainguard | metacontroller | — |
| metacontroller | affected | wolfi | metacontroller | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server | affected | chainguard | metrics-server | — |
| metrics-server-fips | affected | chainguard | metrics-server-fips | — |
| mkcert | affected | chainguard | mkcert | — |
| mkcert | affected | wolfi | mkcert | — |
| mockery | affected | wolfi | mockery | — |
| mockery | affected | chainguard | mockery | — |
| mods | affected | wolfi | mods | — |
| mods | affected | chainguard | mods | — |
| mongo-tools | affected | chainguard | mongo-tools | — |
| mongo-tools | affected | wolfi | mongo-tools | — |
| multus-cni | affected | wolfi | multus-cni | — |
| multus-cni | affected | chainguard | multus-cni | — |
| multus-cni-fips | affected | chainguard | multus-cni-fips | — |
| nats-server | affected | chainguard | nats-server | — |
| nats-server | affected | wolfi | nats-server | — |
| neuvector-scanner | affected | wolfi | neuvector-scanner | — |
| neuvector-scanner | affected | chainguard | neuvector-scanner | — |
| newrelic-infra-operator | affected | wolfi | newrelic-infra-operator | — |
| newrelic-infra-operator | affected | chainguard | newrelic-infra-operator | — |
| newrelic-nri-statsd | affected | wolfi | newrelic-nri-statsd | — |
| newrelic-nri-statsd | affected | chainguard | newrelic-nri-statsd | — |
| newrelic-prometheus-configurator | affected | chainguard | newrelic-prometheus-configurator | — |
| newrelic-prometheus-configurator | affected | wolfi | newrelic-prometheus-configurator | — |
| nfs-subdir-external-provisioner | affected | wolfi | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner | affected | chainguard | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner-fips | affected | chainguard | nfs-subdir-external-provisioner-fips | — |
| nri-prometheus | affected | wolfi | nri-prometheus | — |
| nri-prometheus | affected | chainguard | nri-prometheus | — |
| nvidia-container-toolkit | affected | wolfi | nvidia-container-toolkit | — |
| nvidia-container-toolkit | affected | chainguard | nvidia-container-toolkit | — |
| oauth2-proxy | affected | chainguard | oauth2-proxy | — |
| oauth2-proxy | affected | wolfi | oauth2-proxy | — |
| opa | affected | wolfi | opa | — |
| opa | affected | chainguard | opa | — |
| opentelemetry-collector-contrib-fips | affected | chainguard | opentelemetry-collector-contrib-fips | — |
| opentelemetry-collector-fips | affected | chainguard | opentelemetry-collector-fips | — |
| oras | affected | chainguard | oras | — |
| oras | affected | wolfi | oras | — |
| osv-scanner | affected | chainguard | osv-scanner | — |
| osv-scanner | affected | wolfi | osv-scanner | — |
| overmind | affected | wolfi | overmind | — |
| overmind | affected | chainguard | overmind | — |
| paranoia | affected | wolfi | paranoia | — |
| paranoia | affected | chainguard | paranoia | — |
| petname | affected | chainguard | petname | — |
| petname | affected | wolfi | petname | — |
| php-fpm_exporter | affected | chainguard | php-fpm_exporter | — |
| php-fpm_exporter | affected | wolfi | php-fpm_exporter | — |
| policy-controller | affected | wolfi | policy-controller | — |
| policy-controller | affected | chainguard | policy-controller | — |
| policy-controller-fips | affected | chainguard | policy-controller-fips | — |
| pombump | affected | wolfi | pombump | — |
| pombump | affected | chainguard | pombump | — |
| prometheus-adapter | affected | wolfi | prometheus-adapter | — |
| prometheus-adapter | affected | chainguard | prometheus-adapter | — |
| prometheus-adapter-0.10 | affected | chainguard | prometheus-adapter-0.10 | — |
| prometheus-adapter-fips | affected | chainguard | prometheus-adapter-fips | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-alertmanager | affected | wolfi | prometheus-alertmanager | — |
| prometheus-alertmanager | affected | chainguard | prometheus-alertmanager | — |
| prometheus-alertmanager-fips | affected | chainguard | prometheus-alertmanager-fips | — |
| prometheus-beat-exporter | affected | chainguard | prometheus-beat-exporter | — |
| prometheus-beat-exporter-fips | affected | chainguard | prometheus-beat-exporter-fips | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-elasticsearch-exporter-fips | affected | chainguard | prometheus-elasticsearch-exporter-fips | — |
| prometheus-mongodb-exporter-0.37 | affected | chainguard | prometheus-mongodb-exporter-0.37 | — |
| prometheus-mongodb-exporter-fips | affected | chainguard | prometheus-mongodb-exporter-fips | — |
| prometheus-mongodb-exporter-fips-0.37 | affected | chainguard | prometheus-mongodb-exporter-fips-0.37 | — |
| prometheus-mysqld-exporter | affected | chainguard | prometheus-mysqld-exporter | — |
| prometheus-nats-exporter | affected | chainguard | prometheus-nats-exporter | — |
| prometheus-node-exporter-fips | affected | chainguard | prometheus-node-exporter-fips | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| prometheus-postgres-exporter-fips | affected | chainguard | prometheus-postgres-exporter-fips | — |
| prometheus-pushgateway | affected | chainguard | prometheus-pushgateway | — |
| prometheus-pushgateway | affected | wolfi | prometheus-pushgateway | — |
| prometheus-pushgateway-fips | affected | chainguard | prometheus-pushgateway-fips | — |
| prometheus-pushgateway-fips-1.4 | affected | chainguard | prometheus-pushgateway-fips-1.4 | — |
| prometheus-redis-exporter | affected | chainguard | prometheus-redis-exporter | — |
| prometheus-redis-exporter-fips | affected | chainguard | prometheus-redis-exporter-fips | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter | affected | chainguard | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter-fips | affected | chainguard | prometheus-statsd-exporter-fips | — |
| prometheus-statsd-exporter-fips-0.22 | affected | chainguard | prometheus-statsd-exporter-fips-0.22 | — |
| pulumi-kubernetes-operator | affected | wolfi | pulumi-kubernetes-operator | — |
| pulumi-kubernetes-operator | affected | chainguard | pulumi-kubernetes-operator | — |
| pulumi-language-dotnet | affected | wolfi | pulumi-language-dotnet | — |
| pulumi-language-dotnet | affected | chainguard | pulumi-language-dotnet | — |
| pulumi-language-yaml | affected | chainguard | pulumi-language-yaml | — |
| pulumi-language-yaml | affected | wolfi | pulumi-language-yaml | — |
| q | affected | chainguard | q | — |
| q | affected | wolfi | q | — |
| rabbitmq-default-user-credential-updater | affected | chainguard | rabbitmq-default-user-credential-updater | — |
| rabbitmq-default-user-credential-updater | affected | wolfi | rabbitmq-default-user-credential-updater | — |
| rclone | affected | chainguard | rclone | — |
| rclone | affected | wolfi | rclone | — |
| redka | affected | chainguard | redka | — |
| redka | affected | wolfi | redka | — |
| regclient | affected | chainguard | regclient | — |
| regclient | affected | wolfi | regclient | — |
| rekor | affected | wolfi | rekor | — |
| rekor | affected | chainguard | rekor | — |
| rekor-fips | affected | chainguard | rekor-fips | — |
| render-template | affected | chainguard | render-template | — |
| render-template | affected | wolfi | render-template | — |
| rootlesskit | affected | wolfi | rootlesskit | — |
| rootlesskit | affected | chainguard | rootlesskit | — |
| runc | affected | chainguard | runc | — |
| runc | affected | wolfi | runc | — |
| s5cmd | affected | chainguard | s5cmd | — |
| s5cmd | affected | wolfi | s5cmd | — |
| scorecard | affected | wolfi | scorecard | — |
| scorecard | affected | chainguard | scorecard | — |
| secrets-store-csi-driver | affected | wolfi | secrets-store-csi-driver | — |
| secrets-store-csi-driver | affected | chainguard | secrets-store-csi-driver | — |
| secrets-store-csi-driver-provider-aws | affected | chainguard | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-aws | affected | wolfi | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-azure | affected | wolfi | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-azure | affected | chainguard | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-gcp | affected | wolfi | secrets-store-csi-driver-provider-gcp | — |
| secrets-store-csi-driver-provider-gcp | affected | chainguard | secrets-store-csi-driver-provider-gcp | — |
| shfmt | affected | wolfi | shfmt | — |
| shfmt | affected | chainguard | shfmt | — |
| skaffold | affected | wolfi | skaffold | — |
| skaffold | affected | chainguard | skaffold | — |
| skopeo | affected | wolfi | skopeo | — |
| skopeo | affected | chainguard | skopeo | — |
| smarter-device-manager | affected | wolfi | smarter-device-manager | — |
| smarter-device-manager | affected | chainguard | smarter-device-manager | — |
| smarter-device-manager-fips | affected | chainguard | smarter-device-manager-fips | — |
| snyk-cli | affected | wolfi | snyk-cli | — |
| snyk-cli | affected | chainguard | snyk-cli | — |
| sonobuoy | affected | wolfi | sonobuoy | — |
| sonobuoy | affected | chainguard | sonobuoy | — |
| sops | affected | wolfi | sops | — |
| sops | affected | chainguard | sops | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spegel | affected | wolfi | spegel | — |
| spegel | affected | chainguard | spegel | — |
| spicedb | affected | wolfi | spicedb | — |
| spicedb | affected | chainguard | spicedb | — |
| spqr | affected | wolfi | spqr | — |
| spqr | affected | chainguard | spqr | — |
| src | affected | chainguard | src | — |
| src | affected | wolfi | src | — |
| src-fingerprint | affected | wolfi | src-fingerprint | — |
| src-fingerprint | affected | chainguard | src-fingerprint | — |
| stdlib | affected | Go | stdlib | — |
| step | affected | chainguard | step | — |
| step | affected | wolfi | step | — |
| step-ca | affected | wolfi | step-ca | — |
| step-ca | affected | chainguard | step-ca | — |
| step-ca-fips | affected | chainguard | step-ca-fips | — |
| step-fips | affected | chainguard | step-fips | — |
| stern | affected | wolfi | stern | — |
| stern | affected | chainguard | stern | — |
| tekton-chains | affected | wolfi | tekton-chains | — |
| tekton-chains | affected | chainguard | tekton-chains | — |
| tekton-chains-fips | affected | chainguard | tekton-chains-fips | — |
| tempo | affected | wolfi | tempo | — |
| tempo | affected | chainguard | tempo | — |
| terraform-docs | affected | chainguard | terraform-docs | — |
| terraform-docs | affected | wolfi | terraform-docs | — |
| tfsec | affected | chainguard | tfsec | — |
| tfsec | affected | wolfi | tfsec | — |
| thanos | affected | wolfi | thanos | — |
| thanos | affected | chainguard | thanos | — |
| thanos-fips | affected | chainguard | thanos-fips | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| tigera-operator-fips-1.29 | affected | chainguard | tigera-operator-fips-1.29 | — |
| timestamp-authority-fips | affected | chainguard | timestamp-authority-fips | — |
| timoni | affected | wolfi | timoni | — |
| timoni | affected | chainguard | timoni | — |
| trillian | affected | chainguard | trillian | — |
| trillian | affected | wolfi | trillian | — |
| trillian-fips | affected | chainguard | trillian-fips | — |
| trivy | affected | chainguard | trivy | — |
| trivy | affected | wolfi | trivy | — |
| trust-manager | affected | chainguard | trust-manager | — |
| trust-manager | affected | wolfi | trust-manager | — |
| trust-manager-fips | affected | chainguard | trust-manager-fips | — |
| vault-1.16 | affected | chainguard | vault-1.16 | — |
| vault-k8s | affected | chainguard | vault-k8s | — |
| vault-k8s | affected | wolfi | vault-k8s | — |
| vault-k8s-fips | affected | chainguard | vault-k8s-fips | — |
| vertical-pod-autoscaler | affected | wolfi | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler | affected | chainguard | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler-fips | affected | chainguard | vertical-pod-autoscaler-fips | — |
| volume-modifier-for-k8s | affected | wolfi | volume-modifier-for-k8s | — |
| volume-modifier-for-k8s | affected | chainguard | volume-modifier-for-k8s | — |
| vt-cli | affected | wolfi | vt-cli | — |
| vt-cli | affected | chainguard | vt-cli | — |
| wait-for-port | affected | chainguard | wait-for-port | — |
| wait-for-port | affected | wolfi | wait-for-port | — |
| wave | affected | chainguard | wave | — |
| wave | affected | wolfi | wave | — |
| wave-fips | affected | chainguard | wave-fips | — |
| wavefront-collector-for-kubernetes-1.12 | affected | chainguard | wavefront-collector-for-kubernetes-1.12 | — |
| wavefront-collector-for-kubernetes-1.13 | affected | chainguard | wavefront-collector-for-kubernetes-1.13 | — |
| wgcf | affected | chainguard | wgcf | — |
| wgcf | affected | wolfi | wgcf | — |
| wire-go | affected | wolfi | wire-go | — |
| wire-go | affected | chainguard | wire-go | — |
| wireguard-go | affected | chainguard | wireguard-go | — |
| wireguard-go | affected | wolfi | wireguard-go | — |
| zot | affected | wolfi | zot | — |
| zot | affected | chainguard | zot | — |
CVE-2024-24788
CVEs:CVE-2024-24788
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.22 | affected | Debian:13 | golang-1.22 | — |
CVEs:CVE-2024-24788
A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.
CVEs:CVE-2024-24788
GHSA-hqfv-mf6j-g3j6
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-5499
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5499
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2024-5499
Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5499
GHSA-p76p-6f26-4vgq
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-4949
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-4949
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-4949
CVEs:CVE-2024-4949
GHSA-9xrg-j488-68qq
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2024-4059
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
GHSA-8xgv-q88p-ghq4
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-5496
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5496
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2024-5496
Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5496
GHSA-f6rr-qfxh-hcf9
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2024-5493
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5493
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5493
CVEs:CVE-2024-5493
Updated chromium-browser-stable packages fix security vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP5 | chromium | — |
| chromium | affected | openSUSE:Leap 15.5 | chromium | — |
GHSA-w7g4-69hj-jcrq
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-5157
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5157
CVEs:CVE-2024-5157
Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5157
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
GHSA-wrxh-8wc3-33rm
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-5495
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5495
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2024-5495
Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5495
GHSA-fv2x-w8xf-gxpq
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2024-5494
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5494
Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5494
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2024-5494
GHSA-fqjc-cfjx-7rv8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2024-5498
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-5498
Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5498
Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5498
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
GHSA-qmp7-vwf7-6g2g
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2024-5159
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5159
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5159
CVEs:CVE-2024-5159
CVEs:CVE-2024-30055
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2024-30055
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
GHSA-c24q-2hx9-mjpc
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-5160
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5160
CVEs:CVE-2024-5160
Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5160
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
GHSA-4433-jwm9-48r5
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2024-5158
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-5158
Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-5158
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2024-1584
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up...
CVEs:CVE-2024-1584
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| analytify_-_google_analytics_dashboard | affected | analytify | — | — |
BELL-CVE-2024-2410
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | Alpaquita:23 | protobuf | — |
| protobuf | affected | Alpaquita:stream | protobuf | — |
The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken up into separate chunks in a certain way, the parser will attempt to read bytes from a chunk that has already been freed.
CVEs:CVE-2024-2410
The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken up into separate chunks in a certain way, the parser will attempt to read bytes from a chunk that has ...
CVEs:CVE-2024-2410
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | — | — |
CVEs:CVE-2024-2410
In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for...
CVEs:CVE-2024-23705
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-23705
Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.
CVEs:CVE-2024-20856
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-20856
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions...
CVEs:CVE-2024-1809
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| analytify_-_google_analytics_dashboard | affected | analytify | — | — |
CVEs:CVE-2024-1809
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Iss...
CVEs:CVE-2024-20057
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-20057
ASB-A-327973819
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.
CVEs:CVE-2024-20855
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-20855
There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3. * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input that is not an encoded JSON object, but still a valid encoded JSON element, for example a number or an array. This will crash as Tink just assumes any valid JSON input will contain an object. * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input containing many nested JSON objects. This may result in a stack overflow. We recommend upgrading to version 2.1.3 or above
CVEs:CVE-2024-4420
There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3. * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input that is not an encoded JSON object, but still a valid ...
CVEs:CVE-2024-4420
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tink_c\+\+ | affected | — | — |
CVEs:CVE-2024-4420
CVEs:CVE-2024-32929
In gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-32929
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-324565943
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Credential leakage in github.com/aquasecurity/trivy
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aquasecurity/trivy | affected | github.com | github.com/aquasecurity/trivy | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| kubescape | affected | chainguard | kubescape | — |
| kubescape | affected | wolfi | kubescape | — |
| zot | affected | wolfi | zot | — |
| zot | affected | chainguard | zot | — |
Trivy possibly leaks registry credential when scanning images from malicious registries
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aquasecurity/trivy | affected | github.com | github.com/aquasecurity/trivy | — |
Trivy possibly leaks registry credential when scanning images from malicious registries
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aquasecurity/trivy | affected | github.com | github.com/aquasecurity/trivy | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| kubescape | affected | chainguard | kubescape | — |
| kubescape | affected | wolfi | kubescape | — |
| zot | affected | wolfi | zot | — |
| zot | affected | chainguard | zot | — |
Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.
CVEs:CVE-2024-20864
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-20864
ASB-A-303632069
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-7258
DEBIAN-CVE-2023-7258
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-gvisor-gvisor | affected | Debian:12 | golang-gvisor-gvisor | — |
| golang-gvisor-gvisor | affected | Debian:13 | golang-gvisor-gvisor | — |
| golang-gvisor-gvisor | affected | Debian:14 | golang-gvisor-gvisor | — |
A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6
CVEs:CVE-2023-7258
A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend...
CVEs:CVE-2023-7258
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| gvisor | affected | — | — |
An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.
CVEs:CVE-2024-5166
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| looker | affected | — | — |
CVEs:CVE-2024-5166
ASB-A-329506905
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-323919320
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
| vendor/qcom/opensource/graphics-kernel | affected | platform | platform/vendor/qcom/opensource/graphics-kernel | — |
Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.
CVEs:CVE-2024-20859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-20859
ASB-A-329506991
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-20858
Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.
CVEs:CVE-2024-20858
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-0043
In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2024-0043
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.
CVEs:CVE-2024-20872
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-20872
CVEs:CVE-2024-20860
Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.
CVEs:CVE-2024-20860
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
ASB-A-323918714
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
| vendor/qcom/opensource/graphics-kernel | affected | platform | platform/vendor/qcom/opensource/graphics-kernel | — |
Firebase vulnerable to CRSF attack
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firebase-tools | affected | npm | firebase-tools | — |
Firebase vulnerable to CRSF attack
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firebase-tools | affected | npm | firebase-tools | — |
Firebase vulnerable to CRSF attack
CVEs:CVE-2024-4128
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firebase-tools | affected | npm | firebase-tools | — |
This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website ...
CVEs:CVE-2024-4128
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firebase_command_line_interface | affected | — | — |
Firebase vulnerable to CRSF attack
CVEs:CVE-2024-4128
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firebase-tools | affected | npm | firebase-tools | — |
CVEs:CVE-2024-0024
In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User ...
CVEs:CVE-2024-0024
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-323919078
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
PUB-A-309462068
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-309462484
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-309463056
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-309462901
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2024-0025
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-0025
CVEs:CVE-2024-20058
In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580204; Issue...
CVEs:CVE-2024-20058
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-23706
In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2024-23706
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-23707
In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CVEs:CVE-2024-23707
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08583919; Iss...
CVEs:CVE-2023-32873
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-32873
ASB-A-327972597
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-32871
In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Iss...
CVEs:CVE-2023-32871
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| openwrt | affected | openwrt | — | — |
| rdk-b | affected | rdkcentral | — | — |
| yocto | affected | linuxfoundation | — | — |
ASB-A-309364193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Recommended update for google-cloud SDK
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libcrc32c | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | libcrc32c | — |
| libcrc32c | affected | openSUSE:Leap 15.5 | libcrc32c | — |
| libcrc32c | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | libcrc32c | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Basesystem 15 SP5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Micro 5.5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Micro 5.4 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Micro 5.3 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Package Hub 15 SP5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Installer Updates 15 SP4 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Development Tools 15 SP5 | protobuf | — |
| protobuf | affected | openSUSE:Leap Micro 5.3 | protobuf | — |
| protobuf | affected | openSUSE:Leap Micro 5.4 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Installer Updates 15 SP5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | protobuf | — |
| protobuf | affected | openSUSE:Leap 15.5 | protobuf | — |
| python-apipkg | affected | openSUSE:Leap 15.5 | python-apipkg | — |
| python-apipkg | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-apipkg | — |
| python-apipkg | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-apipkg | — |
| python-cachetools | affected | openSUSE:Leap 15.5 | python-cachetools | — |
| python-cachetools | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-cachetools | — |
| python-cachetools | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-cachetools | — |
| python-certifi | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-certifi | — |
| python-certifi | affected | openSUSE:Leap 15.5 | python-certifi | — |
| python-certifi | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-certifi | — |
| python-cffi | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-cffi | — |
| python-cffi | affected | openSUSE:Leap 15.5 | python-cffi | — |
| python-cffi | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-cffi | — |
| python-charset-normalizer | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-charset-normalizer | — |
| python-charset-normalizer | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-charset-normalizer | — |
| python-charset-normalizer | affected | openSUSE:Leap 15.5 | python-charset-normalizer | — |
| python-cryptography | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-cryptography | — |
| python-cryptography | affected | openSUSE:Leap 15.5 | python-cryptography | — |
| python-cryptography | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-cryptography | — |
| python-google-api-core | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-api-core | — |
| python-google-api-core | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-api-core | — |
| python-google-api-core | affected | openSUSE:Leap 15.5 | python-google-api-core | — |
| python-googleapis-common-protos | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-googleapis-common-protos | — |
| python-googleapis-common-protos | affected | openSUSE:Leap 15.5 | python-googleapis-common-protos | — |
| python-googleapis-common-protos | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-googleapis-common-protos | — |
| python-google-auth | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-google-auth | — |
| python-google-auth | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-auth | — |
| python-google-auth | affected | openSUSE:Leap 15.5 | python-google-auth | — |
| python-google-auth | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-auth | — |
| python-google-cloud-appengine-logging | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-appengine-logging | — |
| python-google-cloud-appengine-logging | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-appengine-logging | — |
| python-google-cloud-appengine-logging | affected | openSUSE:Leap 15.5 | python-google-cloud-appengine-logging | — |
| python-google-cloud-artifact-registry | affected | openSUSE:Leap 15.5 | python-google-cloud-artifact-registry | — |
| python-google-cloud-artifact-registry | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-artifact-registry | — |
| python-google-cloud-artifact-registry | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-artifact-registry | — |
| python-google-cloud-audit-log | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-audit-log | — |
| python-google-cloud-audit-log | affected | openSUSE:Leap 15.5 | python-google-cloud-audit-log | — |
| python-google-cloud-audit-log | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-audit-log | — |
| python-google-cloud-build | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-build | — |
| python-google-cloud-build | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-build | — |
| python-google-cloud-build | affected | openSUSE:Leap 15.5 | python-google-cloud-build | — |
| python-google-cloud-compute | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-compute | — |
| python-google-cloud-compute | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-compute | — |
| python-google-cloud-compute | affected | openSUSE:Leap 15.5 | python-google-cloud-compute | — |
| python-google-cloud-core | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-core | — |
| python-google-cloud-core | affected | openSUSE:Leap 15.5 | python-google-cloud-core | — |
| python-google-cloud-core | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-core | — |
| python-google-cloud-dns | affected | openSUSE:Leap 15.5 | python-google-cloud-dns | — |
| python-google-cloud-dns | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-dns | — |
| python-google-cloud-dns | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-dns | — |
| python-google-cloud-domains | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-domains | — |
| python-google-cloud-domains | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-domains | — |
| python-google-cloud-domains | affected | openSUSE:Leap 15.5 | python-google-cloud-domains | — |
| python-google-cloud-iam | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-iam | — |
| python-google-cloud-iam | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-iam | — |
| python-google-cloud-iam | affected | openSUSE:Leap 15.5 | python-google-cloud-iam | — |
| python-google-cloud-kms | affected | openSUSE:Leap 15.5 | python-google-cloud-kms | — |
| python-google-cloud-kms | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-kms | — |
| python-google-cloud-kms | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-kms | — |
| python-google-cloud-kms-inventory | affected | openSUSE:Leap 15.5 | python-google-cloud-kms-inventory | — |
| python-google-cloud-kms-inventory | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-kms-inventory | — |
| python-google-cloud-kms-inventory | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-kms-inventory | — |
| python-google-cloud-logging | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-logging | — |
| python-google-cloud-logging | affected | openSUSE:Leap 15.5 | python-google-cloud-logging | — |
| python-google-cloud-logging | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-logging | — |
| python-google-cloud-run | affected | openSUSE:Leap 15.5 | python-google-cloud-run | — |
| python-google-cloud-run | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-run | — |
| python-google-cloud-run | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-run | — |
| python-google-cloud-secret-manager | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-secret-manager | — |
| python-google-cloud-secret-manager | affected | openSUSE:Leap 15.5 | python-google-cloud-secret-manager | — |
| python-google-cloud-secret-manager | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-secret-manager | — |
| python-google-cloud-service-directory | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-service-directory | — |
| python-google-cloud-service-directory | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-service-directory | — |
| python-google-cloud-service-directory | affected | openSUSE:Leap 15.5 | python-google-cloud-service-directory | — |
| python-google-cloud-spanner | affected | openSUSE:Leap 15.5 | python-google-cloud-spanner | — |
| python-google-cloud-spanner | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-spanner | — |
| python-google-cloud-spanner | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-spanner | — |
| python-google-cloud-storage | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-storage | — |
| python-google-cloud-storage | affected | openSUSE:Leap 15.5 | python-google-cloud-storage | — |
| python-google-cloud-storage | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-storage | — |
| python-google-cloud-vpc-access | affected | openSUSE:Leap 15.5 | python-google-cloud-vpc-access | — |
| python-google-cloud-vpc-access | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-cloud-vpc-access | — |
| python-google-cloud-vpc-access | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-cloud-vpc-access | — |
| python-google-crc32c | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-crc32c | — |
| python-google-crc32c | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-crc32c | — |
| python-google-crc32c | affected | openSUSE:Leap 15.5 | python-google-crc32c | — |
| python-google-resumable-media | affected | openSUSE:Leap 15.5 | python-google-resumable-media | — |
| python-google-resumable-media | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-google-resumable-media | — |
| python-google-resumable-media | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-google-resumable-media | — |
| python-grpc-google-iam-v1 | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-grpc-google-iam-v1 | — |
| python-grpc-google-iam-v1 | affected | openSUSE:Leap 15.5 | python-grpc-google-iam-v1 | — |
| python-grpc-google-iam-v1 | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-grpc-google-iam-v1 | — |
| python-grpcio | affected | openSUSE:Leap 15.5 | python-grpcio | — |
| python-grpcio | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-grpcio | — |
| python-grpcio | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-grpcio | — |
| python-grpcio | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-grpcio | — |
| python-grpcio-status | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-grpcio-status | — |
| python-grpcio-status | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-grpcio-status | — |
| python-grpcio-status | affected | openSUSE:Leap 15.5 | python-grpcio-status | — |
| python-idna | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-idna | — |
| python-idna | affected | openSUSE:Leap 15.5 | python-idna | — |
| python-idna | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-idna | — |
| python-iniconfig | affected | openSUSE:Leap 15.5 | python-iniconfig | — |
| python-iniconfig | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-iniconfig | — |
| python-iniconfig | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-iniconfig | — |
| python-proto-plus | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-proto-plus | — |
| python-proto-plus | affected | openSUSE:Leap 15.5 | python-proto-plus | — |
| python-proto-plus | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-proto-plus | — |
| python-py | affected | openSUSE:Leap 15.5 | python-py | — |
| python-py | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-py | — |
| python-py | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-py | — |
| python-pyasn1 | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-pyasn1 | — |
| python-pyasn1 | affected | openSUSE:Leap 15.5 | python-pyasn1 | — |
| python-pyasn1 | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-pyasn1 | — |
| python-pyasn1-modules | affected | openSUSE:Leap 15.5 | python-pyasn1-modules | — |
| python-pyasn1-modules | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-pyasn1-modules | — |
| python-pyasn1-modules | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-pyasn1-modules | — |
| python-pycparser | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-pycparser | — |
| python-pycparser | affected | openSUSE:Leap 15.5 | python-pycparser | — |
| python-pycparser | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-pycparser | — |
| python-pyOpenSSL | affected | openSUSE:Leap 15.5 | python-pyOpenSSL | — |
| python-pyOpenSSL | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-pyOpenSSL | — |
| python-pyOpenSSL | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-pyOpenSSL | — |
| python-pytz | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-pytz | — |
| python-pytz | affected | openSUSE:Leap 15.5 | python-pytz | — |
| python-pytz | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-pytz | — |
| python-requests | affected | openSUSE:Leap 15.5 | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-requests | — |
| python-rsa | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-rsa | — |
| python-rsa | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-rsa | — |
| python-rsa | affected | openSUSE:Leap 15.5 | python-rsa | — |
| python-setuptools | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-setuptools | — |
| python-setuptools | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-setuptools | — |
| python-setuptools | affected | openSUSE:Leap 15.5 | python-setuptools | — |
| python-sqlparse | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-sqlparse | — |
| python-sqlparse | affected | openSUSE:Leap 15.5 | python-sqlparse | — |
| python-sqlparse | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-sqlparse | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | python-urllib3 | — |
| python-urllib3 | affected | openSUSE:Leap 15.5 | python-urllib3 | — |
firebase/php-jwt: "None" Algorithm treated as valid on tokens
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php-jwt | affected | firebase | firebase/php-jwt | — |
firebase/php-jwt: "None" Algorithm treated as valid on tokens
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php-jwt | affected | firebase | firebase/php-jwt | — |
GO-2021-0157
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
Stack-buffer-overflow in SwiftProtobuf.TextFormatScanner.
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| swift-protobuf | affected | OSS-Fuzz | swift-protobuf | — |
PUB-A-329067188
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.