Google Security Advisories · July 2024 — Google Security Advisories
334 advisories 204 CVEs 4 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2024-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 4 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2024-38080

GoogleExploitedCISA KEV listedCRITICAL2024-07-09

Windows Hyper-V Elevation of Privilege Vulnerability

CVEs:CVE-2024-38080

Affected products

ProductStatusVendorPackageEcosystem
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_11_23h2 affected microsoft
windows_server_2022 affected microsoft
windows_server_2022_23h2 affected microsoft
Upstream advisory

ASB-A-260126994

GoogleExploitedCISA KEV listed2024-07-01

ASB-A-260126994

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DSA-5732-1

Open SourceActive exploitation (sightings)2024-07-18

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

openSUSE-SU-2024:0204-1

Open SourceActive exploitation (sightings)CRITICAL2024-07-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.6 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected SUSE:Package Hub 15 SP6 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

openSUSE-SU-2024:14122-1

Open SourceActive exploitation (sightings)2024-07-12

chromedriver-126.0.6478.126-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

MGASA-2024-0254

Open SourceActive exploitation (sightings)CRITICAL2024-07-04

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

GHSA-gjh7-xx4r-x345

Open SourceActive exploitation (sightings)HIGH2024-07-30

TensorFlow has segfault in array_ops.upper_bound

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gjh7-xx4r-x345

Open SourceActive exploitation (sightings)HIGH2024-07-30

TensorFlow has segfault in array_ops.upper_bound

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-47242

Open SourceActive exploitation (sightings)CRITICAL2024-07-30

CVE-2023-33976 affecting package tensorflow for versions less than 2.11.1-2

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2023-33976

Open SourceActive exploitation (sightings)HIGH2024-07-30

TensorFlow has segfault in array_ops.upper_bound

CVEs:CVE-2023-33976

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-33976

Open SourceActive exploitation (sightings)HIGH2024-07-30

TensorFlow has segfault in array_ops.upper_bound

CVEs:CVE-2023-33976

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-33976

Open SourceActive exploitation (sightings)CRITICAL2024-07-30

TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. The fix will be included in TensorFlow 2.13 and will also cherrypick this commit on TensorFlow 2.12.

CVEs:CVE-2023-33976

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

DEBIAN-CVE-2024-3172

Open SourceActive exploitation (sightings)CRITICAL2024-07-16

DEBIAN-CVE-2024-3172

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2024-3174

Open SourceActive exploitation (sightings)HIGH2024-07-16

DEBIAN-CVE-2024-3174

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3174

GoogleActive exploitation (sightings)2024-07-16

Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3174

Upstream advisory

CVE-2024-3174

GoogleActive exploitation (sightings)HIGH2024-07-16

Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3174

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-3176

Open SourceActive exploitation (sightings)CRITICAL2024-07-16

DEBIAN-CVE-2024-3176

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2024-3169

Open SourceActive exploitation (sightings)CRITICAL2024-07-16

DEBIAN-CVE-2024-3169

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2024-3170

Open SourceActive exploitation (sightings)CRITICAL2024-07-16

DEBIAN-CVE-2024-3170

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3176

GoogleActive exploitation (sightings)CRITICAL2024-07-16

Out of bounds write in SwiftShader in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3176

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-3176

GoogleActive exploitation (sightings)2024-07-16

Out of bounds write in SwiftShader in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3176

Upstream advisory

CVE-2024-3170

GoogleActive exploitation (sightings)2024-07-16

Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3170

Upstream advisory

CVE-2024-3170

GoogleActive exploitation (sightings)CRITICAL2024-07-16

Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3170

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-cmpj-4482-wc34

Open SourceActive exploitation (sightings)CRITICAL2024-07-17

GHSA-cmpj-4482-wc34

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-3168

Open SourceActive exploitation (sightings)CRITICAL2024-07-16

DEBIAN-CVE-2024-3168

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3168

GoogleActive exploitation (sightings)CRITICAL2024-07-16

Use after free in DevTools in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-3168

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-3168

GoogleActive exploitation (sightings)2024-07-16

Use after free in DevTools in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-3168

Upstream advisory

GO-2024-2994

Open SourceActive exploitation (sightings)2024-07-22

Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes

Affected products

ProductStatusVendorPackageEcosystem
argocd-image-updater affected chainguard argocd-image-updater
argocd-image-updater affected wolfi argocd-image-updater
argocd-image-updater-fips affected chainguard argocd-image-updater-fips
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
cri-tools affected wolfi cri-tools
cri-tools affected chainguard cri-tools
ip-masq-agent affected chainguard ip-masq-agent
ip-masq-agent affected wolfi ip-masq-agent
k8s-device-plugin affected chainguard k8s-device-plugin
k8s-device-plugin affected wolfi k8s-device-plugin
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache-fips affected chainguard kubernetes-dns-node-cache-fips
local-static-provisioner affected wolfi local-static-provisioner
local-static-provisioner affected chainguard local-static-provisioner
node-feature-discovery-0.16 affected chainguard node-feature-discovery-0.16
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
rancher-webhook-0.4 affected chainguard rancher-webhook-0.4
rancher-webhook-0.5 affected chainguard rancher-webhook-0.5
rancher-webhook-fips-0.4 affected chainguard rancher-webhook-fips-0.4
rancher-webhook-fips-0.5 affected chainguard rancher-webhook-fips-0.5
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
Upstream advisory

GHSA-82m2-cv7p-4m75

Open SourceActive exploitation (sightings)HIGH2024-07-18

Kubernetes sets incorrect permissions on Windows containers logs

Affected products

ProductStatusVendorPackageEcosystem
argo-cd-2.12 affected wolfi argo-cd-2.12
argo-cd-2.12 affected chainguard argo-cd-2.12
argo-cd-fips-2.12 affected chainguard argo-cd-fips-2.12
argocd-image-updater affected chainguard argocd-image-updater
argocd-image-updater affected wolfi argocd-image-updater
argocd-image-updater-fips affected chainguard argocd-image-updater-fips
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver-fips affected chainguard aws-ebs-csi-driver-fips
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
calico-3.27 affected chainguard calico-3.27
calico-fips-3.27 affected chainguard calico-fips-3.27
calico-fips-3.28 affected chainguard calico-fips-3.28
cluster-autoscaler-1.28 affected wolfi cluster-autoscaler-1.28
cluster-autoscaler-1.28 affected chainguard cluster-autoscaler-1.28
cluster-autoscaler-1.29 affected chainguard cluster-autoscaler-1.29
cluster-autoscaler-1.29 affected wolfi cluster-autoscaler-1.29
cluster-autoscaler-1.30 affected chainguard cluster-autoscaler-1.30
cluster-autoscaler-1.30 affected wolfi cluster-autoscaler-1.30
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
cluster-autoscaler-fips-1.29 affected chainguard cluster-autoscaler-fips-1.29
cluster-autoscaler-fips-1.30 affected chainguard cluster-autoscaler-fips-1.30
cri-tools affected wolfi cri-tools
cri-tools affected chainguard cri-tools
gpu-feature-discovery affected chainguard gpu-feature-discovery
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
k8s-device-plugin affected wolfi k8s-device-plugin
k8s-device-plugin affected chainguard k8s-device-plugin
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-dns-node-cache-fips affected chainguard kubernetes-dns-node-cache-fips
kubernetes-fips-1.28 affected chainguard kubernetes-fips-1.28
kubernetes-fips-1.29 affected chainguard kubernetes-fips-1.29
kubernetes-fips-1.30 affected chainguard kubernetes-fips-1.30
local-static-provisioner affected wolfi local-static-provisioner
local-static-provisioner affected chainguard local-static-provisioner
node-feature-discovery-0.15 affected chainguard node-feature-discovery-0.15
node-feature-discovery-0.15 affected wolfi node-feature-discovery-0.15
node-feature-discovery-0.16 affected chainguard node-feature-discovery-0.16
node-feature-discovery-0.16 affected wolfi node-feature-discovery-0.16
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
rancher-webhook-0.4 affected chainguard rancher-webhook-0.4
rancher-webhook-0.5 affected chainguard rancher-webhook-0.5
rancher-webhook-fips-0.4 affected chainguard rancher-webhook-fips-0.4
rancher-webhook-fips-0.5 affected chainguard rancher-webhook-fips-0.5
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
Upstream advisory

GHSA-82m2-cv7p-4m75

Open SourceActive exploitation (sightings)HIGH2024-07-18

Kubernetes sets incorrect permissions on Windows containers logs

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2024-5321

GoogleActive exploitation (sightings)MEDIUM2024-07-17

A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.

CVEs:CVE-2024-5321

Upstream advisory

CVE-2024-5321

Open SourceActive exploitation (sightings)HIGH2024-07-17

Kubernetes sets incorrect permissions on Windows containers logs

CVEs:CVE-2024-5321

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-f2wx-vcrf-76pc

Open SourceActive exploitation (sightings)CRITICAL2024-07-17

GHSA-f2wx-vcrf-76pc

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-3171

Open SourceActive exploitation (sightings)CRITICAL2024-07-16

DEBIAN-CVE-2024-3171

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-3171

GoogleActive exploitation (sightings)CRITICAL2024-07-16

Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

CVEs:CVE-2024-3171

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-3171

GoogleActive exploitation (sightings)2024-07-16

Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

CVEs:CVE-2024-3171

Upstream advisory

GHSA-7jr6-fvm5-h86m

Open SourceActive exploitation (sightings)MEDIUM2024-07-17

GHSA-7jr6-fvm5-h86m

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-5500

Open SourceActive exploitation (sightings)MEDIUM2024-07-16

DEBIAN-CVE-2024-5500

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-5500

GoogleActive exploitation (sightings)2024-07-16

Inappropriate implementation in Sign-In in Google Chrome prior to 1.3.36.351 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-5500

Upstream advisory

CVE-2024-5500

GoogleActive exploitation (sightings)MEDIUM2024-07-16

Inappropriate implementation in Sign-In in Google Chrome prior to 1.3.36.351 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-5500

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-31320

Open SourceActive exploitation (sightings)HIGH2024-07-01

In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User...

CVEs:CVE-2024-31320

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2024-2884

Open SourceActive exploitation (sightings)MEDIUM2024-07-16

DEBIAN-CVE-2024-2884

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-20081

Open SourceActive exploitation (sightings)CRITICAL2024-07-01

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08719602...

CVEs:CVE-2024-20081

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2024-20081

GoogleActive exploitation (sightings)2024-07-01

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08719602; Issue ID: MSV-1412.

CVEs:CVE-2024-20081

Upstream advisory

DEBIAN-CVE-2024-3173

Open SourceActive exploitation (sightings)CRITICAL2024-07-16

DEBIAN-CVE-2024-3173

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

ASB-A-332315362

GoogleActive exploitation (sightings)2024-07-01

ASB-A-332315362

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom/opensource/graphics-kernel affected platform platform/vendor/qcom/opensource/graphics-kernel
Upstream advisory

CVE-2024-34602

Open SourceActive exploitation (sightings)MEDIUM2024-07-08

Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34602

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34603

Open SourceActive exploitation (sightings)MEDIUM2024-07-08

Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.

CVEs:CVE-2024-34603

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-31335

Open SourceActive exploitation (sightings)HIGH2024-07-01

In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interact...

CVEs:CVE-2024-31335

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-337951645

GoogleActive exploitation (sightings)HIGH2024-07-01

ASB-A-337951645

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-31331

Open SourceActive exploitation (sightings)HIGH2024-07-01

In setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Settings due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is neede...

CVEs:CVE-2024-31331

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-31339

Open SourceActive exploitation (sightings)HIGH2024-07-01

In multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-31339

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-34723

Open SourceActive exploitation (sightings)HIGH2024-07-01

In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges ne...

CVEs:CVE-2024-34723

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-34726

Open SourceActive exploitation (sightings)HIGH2024-07-01

In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2024-34726

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-331439207

GoogleActive exploitation (sightings)HIGH2024-07-01

ASB-A-331439207

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-34720

Open SourceActive exploitation (sightings)HIGH2024-07-01

In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, there is a possible method to perform arbitrary code execution in any app zygote processes due to a logic error in the code. This co...

CVEs:CVE-2024-34720

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-34721

Open SourceActive exploitation (sightings)MEDIUM2024-07-01

In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction...

CVEs:CVE-2024-34721

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-31334

Open SourceActive exploitation (sightings)HIGH2024-07-01

In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User int...

CVEs:CVE-2024-31334

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-337947582

GoogleActive exploitation (sightings)HIGH2024-07-01

ASB-A-337947582

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-34724

Open SourceActive exploitation (sightings)HIGH2024-07-01

In _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2024-34724

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-331437482

GoogleActive exploitation (sightings)HIGH2024-07-01

ASB-A-331437482

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-34725

Open SourceActive exploitation (sightings)HIGH2024-07-01

In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2024-34725

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-331438755

GoogleActive exploitation (sightings)HIGH2024-07-01

ASB-A-331438755

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-v23v-6jw2-98fq

GooglePoC exploitCRITICAL2024-07-30

Authz zero length regression

Affected products

ProductStatusVendorPackageEcosystem
docker/docker affected github.com github.com/docker/docker
Upstream advisory

GHSA-v23v-6jw2-98fq

Open SourcePoC exploitCRITICAL2024-07-30

Authz zero length regression

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
apko affected wolfi apko
apko affected chainguard apko
argo-workflows affected chainguard argo-workflows
argo-workflows affected wolfi argo-workflows
argo-workflows-fips affected chainguard argo-workflows-fips
bom affected wolfi bom
bom affected chainguard bom
buf affected chainguard buf
buf affected wolfi buf
buildah affected wolfi buildah
buildah affected chainguard buildah
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
cadvisor affected wolfi cadvisor
cadvisor affected chainguard cadvisor
cadvisor-fips affected chainguard cadvisor-fips
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.14 affected wolfi cert-manager-1.14
cert-manager-1.14 affected chainguard cert-manager-1.14
cert-manager-cmctl affected wolfi cert-manager-cmctl
cert-manager-cmctl affected chainguard cert-manager-cmctl
cert-manager-cmctl-fips affected chainguard cert-manager-cmctl-fips
cert-manager-fips-1.12 affected chainguard cert-manager-fips-1.12
cert-manager-fips-1.14 affected chainguard cert-manager-fips-1.14
chainctl affected chainguard chainctl
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
chartmuseum-fips affected chainguard chartmuseum-fips
cilium-cli affected wolfi cilium-cli
cilium-cli affected chainguard cilium-cli
commercial-chainloop-backend affected chainguard commercial-chainloop-backend
cosign affected wolfi cosign
cosign affected chainguard cosign
cosign-fips affected wolfi cosign-fips
cosign-fips affected chainguard cosign-fips
crane affected wolfi crane
crane affected chainguard crane
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
crossplane affected wolfi crossplane
crossplane affected chainguard crossplane
ctop affected wolfi ctop
ctop affected chainguard ctop
dagdotdev affected chainguard dagdotdev
dagdotdev affected wolfi dagdotdev
dagger affected chainguard dagger
dagger affected wolfi dagger
datadog-agent affected chainguard datadog-agent
datadog-agent affected wolfi datadog-agent
datadog-agent-fips affected chainguard datadog-agent-fips
dive affected wolfi dive
dive affected chainguard dive
docker affected wolfi docker
docker affected chainguard docker
docker-compose affected wolfi docker-compose
docker-compose affected chainguard docker-compose
docker-credential-gcr affected wolfi docker-credential-gcr
docker-credential-gcr affected chainguard docker-credential-gcr
docker/docker affected github.com github.com/docker/docker
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
filebeat affected chainguard filebeat
filebeat affected wolfi filebeat
filebeat-fips affected chainguard filebeat-fips
flux affected wolfi flux
flux affected chainguard flux
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
gatekeeper-3.15 affected chainguard gatekeeper-3.15
gatekeeper-3.15 affected wolfi gatekeeper-3.15
gatekeeper-3.16 affected wolfi gatekeeper-3.16
gatekeeper-3.16 affected chainguard gatekeeper-3.16
gh affected wolfi gh
gh affected chainguard gh
gitlab-rails-ce-18.1 affected chainguard gitlab-rails-ce-18.1
gitlab-rails-ce-fips-18.1 affected chainguard gitlab-rails-ce-fips-18.1
gitlab-rails-ee-17.0 affected chainguard gitlab-rails-ee-17.0
gitlab-rails-ee-17.3 affected chainguard gitlab-rails-ee-17.3
gitlab-rails-ee-fips-17.0 affected chainguard gitlab-rails-ee-fips-17.0
gitlab-rails-ee-fips-17.3 affected chainguard gitlab-rails-ee-fips-17.3
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
goreleaser affected wolfi goreleaser
goreleaser affected chainguard goreleaser
grafana-alloy affected wolfi grafana-alloy
grafana-alloy affected chainguard grafana-alloy
grafana-alloy-fips affected chainguard grafana-alloy-fips
grype affected wolfi grype
grype affected chainguard grype
guac affected chainguard guac
guac affected wolfi guac
harbor-2.11 affected chainguard harbor-2.11
harbor-2.11 affected wolfi harbor-2.11
harbor-fips-2.11 affected chainguard harbor-fips-2.11
harbor-scanner-trivy affected wolfi harbor-scanner-trivy
harbor-scanner-trivy affected chainguard harbor-scanner-trivy
harbor-scanner-trivy-fips affected chainguard harbor-scanner-trivy-fips
helm affected chainguard helm
helm affected wolfi helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected chainguard helm-operator
helm-operator affected wolfi helm-operator
helm-operator-fips affected chainguard helm-operator-fips
helm-operator-fips-1.33 affected chainguard helm-operator-fips-1.33
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
istio-fips-1.21 affected chainguard istio-fips-1.21
istio-fips-1.22 affected chainguard istio-fips-1.22
istio-operator-1.22 affected chainguard istio-operator-1.22
istio-operator-1.22 affected wolfi istio-operator-1.22
istio-pilot-agent-1.21 affected wolfi istio-pilot-agent-1.21
istio-pilot-agent-1.21 affected chainguard istio-pilot-agent-1.21
istio-pilot-agent-1.22 affected chainguard istio-pilot-agent-1.22
istio-pilot-agent-1.22 affected wolfi istio-pilot-agent-1.22
istio-pilot-discovery-1.21 affected wolfi istio-pilot-discovery-1.21
istio-pilot-discovery-1.21 affected chainguard istio-pilot-discovery-1.21
istio-pilot-discovery-1.22 affected chainguard istio-pilot-discovery-1.22
istio-pilot-discovery-1.22 affected wolfi istio-pilot-discovery-1.22
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected wolfi k3s
k3s affected chainguard k3s
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k9s affected chainguard k9s
k9s affected wolfi k9s
kaniko affected wolfi kaniko
kaniko affected chainguard kaniko
kaniko-fips affected chainguard kaniko-fips
kargo affected chainguard kargo
kargo affected wolfi kargo
ko affected wolfi ko
ko affected chainguard ko
ko-fips affected chainguard ko-fips
ko-fips affected wolfi ko-fips
kots affected wolfi kots
kots affected chainguard kots
kots-compat affected chainguard kots-compat
kpt affected wolfi kpt
kpt affected chainguard kpt
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
kubevela-fips affected chainguard kubevela-fips
kyverno-1.11 affected chainguard kyverno-1.11
kyverno-1.12 affected chainguard kyverno-1.12
kyverno-1.12 affected wolfi kyverno-1.12
kyverno-fips-1.11 affected chainguard kyverno-fips-1.11
kyverno-fips-1.12 affected chainguard kyverno-fips-1.12
loki-2.9 affected chainguard loki-2.9
loki-3 affected wolfi loki-3
loki-3 affected chainguard loki-3
loki-3.1 affected wolfi loki-3.1
loki-3.1 affected chainguard loki-3.1
loki-fips-2.9 affected chainguard loki-fips-2.9
loki-fips-3.0 affected chainguard loki-fips-3.0
longhorn-engine-1.10 affected chainguard longhorn-engine-1.10
longhorn-engine-1.8 affected chainguard longhorn-engine-1.8
longhorn-engine-1.9 affected chainguard longhorn-engine-1.9
melange affected chainguard melange
melange affected wolfi melange
nerdctl affected wolfi nerdctl
nerdctl affected chainguard nerdctl
neuvector affected wolfi neuvector
neuvector affected chainguard neuvector
neuvector-fips affected chainguard neuvector-fips
neuvector-scanner affected wolfi neuvector-scanner
neuvector-scanner affected chainguard neuvector-scanner
neuvector-scanner-fips affected chainguard neuvector-scanner-fips
neuvector-sigstore-interface affected wolfi neuvector-sigstore-interface
neuvector-sigstore-interface affected chainguard neuvector-sigstore-interface
neuvector-sigstore-interface-fips affected chainguard neuvector-sigstore-interface-fips
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
paranoia affected wolfi paranoia
paranoia affected chainguard paranoia
policy-controller affected wolfi policy-controller
policy-controller affected chainguard policy-controller
policy-controller-fips affected chainguard policy-controller-fips
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-2.51 affected wolfi prometheus-2.51
prometheus-2.53 affected wolfi prometheus-2.53
prometheus-2.53 affected chainguard prometheus-2.53
prometheus-2.54 affected wolfi prometheus-2.54
prometheus-2.54 affected chainguard prometheus-2.54
prometheus-fips affected chainguard prometheus-fips
prometheus-fips-2.53 affected chainguard prometheus-fips-2.53
rancher-2.10 affected wolfi rancher-2.10
rancher-2.10 affected chainguard rancher-2.10
rancher-agent-2.10 affected wolfi rancher-agent-2.10
rancher-agent-2.10 affected chainguard rancher-agent-2.10
rancher-agent-2.11 affected wolfi rancher-agent-2.11
rancher-agent-2.11 affected chainguard rancher-agent-2.11
rancher-agent-2.9 affected wolfi rancher-agent-2.9
rancher-agent-2.9 affected chainguard rancher-agent-2.9
rancher-fleet affected chainguard rancher-fleet
rancher-fleet affected wolfi rancher-fleet
rke2-runtime-1.33 affected chainguard rke2-runtime-1.33
rke2-runtime-1.36 affected chainguard rke2-runtime-1.36
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
skopeo affected wolfi skopeo
skopeo affected chainguard skopeo
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
syft affected chainguard syft
syft affected wolfi syft
tekton-chains affected chainguard tekton-chains
tekton-chains affected wolfi tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
tekton-pipelines-fips affected chainguard tekton-pipelines-fips
telegraf-1.30 affected chainguard telegraf-1.30
telegraf-1.30 affected wolfi telegraf-1.30
telegraf-1.31 affected wolfi telegraf-1.31
telegraf-1.31 affected chainguard telegraf-1.31
teleport affected wolfi teleport
teleport affected chainguard teleport
timoni affected wolfi timoni
timoni affected chainguard timoni
tkn affected wolfi tkn
tkn affected chainguard tkn
tkn-fips affected chainguard tkn-fips
traefik-3.0 affected wolfi traefik-3.0
traefik-3.0 affected chainguard traefik-3.0
traefik-3.1 affected wolfi traefik-3.1
traefik-3.1 affected chainguard traefik-3.1
traefik-fips-2.11 affected chainguard traefik-fips-2.11
traefik-fips-3.0 affected chainguard traefik-fips-3.0
traefik-fips-3.1 affected chainguard traefik-fips-3.1
trivy affected wolfi trivy
trivy affected chainguard trivy
trivy-fips affected chainguard trivy-fips
up affected chainguard up
up affected wolfi up
vault-1.16 affected chainguard vault-1.16
vault-1.17 affected chainguard vault-1.17
vault-fips-1.15 affected chainguard vault-fips-1.15
vault-fips-1.17 affected chainguard vault-fips-1.17
vcluster affected chainguard vcluster
vcluster affected wolfi vcluster
vexctl affected wolfi vexctl
vexctl affected chainguard vexctl
wolfictl affected wolfi wolfictl
wolfictl affected chainguard wolfictl
zarf affected wolfi zarf
zarf affected chainguard zarf
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

GO-2024-3005

Open SourcePoC exploit2024-07-29

Moby authz zero length regression in github.com/moby/moby

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
apko affected wolfi apko
apko affected chainguard apko
argo-workflows affected chainguard argo-workflows
argo-workflows affected wolfi argo-workflows
argo-workflows-fips affected chainguard argo-workflows-fips
bom affected wolfi bom
bom affected chainguard bom
buf affected chainguard buf
buf affected wolfi buf
buildah affected wolfi buildah
buildah affected chainguard buildah
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
cadvisor affected wolfi cadvisor
cadvisor affected chainguard cadvisor
cadvisor-fips affected chainguard cadvisor-fips
cert-manager-cmctl affected chainguard cert-manager-cmctl
cert-manager-cmctl affected wolfi cert-manager-cmctl
cert-manager-cmctl-fips affected chainguard cert-manager-cmctl-fips
chainctl affected chainguard chainctl
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
chartmuseum-fips affected chainguard chartmuseum-fips
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
commercial-chainloop-backend affected chainguard commercial-chainloop-backend
cosign affected wolfi cosign
cosign affected chainguard cosign
cosign-fips affected chainguard cosign-fips
crane affected chainguard crane
crane affected wolfi crane
cri-tools affected wolfi cri-tools
cri-tools affected chainguard cri-tools
crossplane affected wolfi crossplane
crossplane affected chainguard crossplane
ctop affected chainguard ctop
ctop affected wolfi ctop
dagdotdev affected chainguard dagdotdev
dagdotdev affected wolfi dagdotdev
dagger affected wolfi dagger
dagger affected chainguard dagger
dive affected wolfi dive
dive affected chainguard dive
docker affected wolfi docker
docker affected chainguard docker
docker-compose affected wolfi docker-compose
docker-compose affected chainguard docker-compose
docker-credential-gcr affected wolfi docker-credential-gcr
docker-credential-gcr affected chainguard docker-credential-gcr
docker/docker affected github.com github.com/docker/docker
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
falcoctl affected wolfi falcoctl
falcoctl affected chainguard falcoctl
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
flux affected wolfi flux
flux affected chainguard flux
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
gh affected chainguard gh
gh affected wolfi gh
gitlab-rails-ce-18.1 affected chainguard gitlab-rails-ce-18.1
gitlab-rails-ce-fips-18.1 affected chainguard gitlab-rails-ce-fips-18.1
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
grafana-alloy affected wolfi grafana-alloy
grafana-alloy affected chainguard grafana-alloy
grafana-alloy-fips affected chainguard grafana-alloy-fips
grype affected wolfi grype
grype affected chainguard grype
guac affected wolfi guac
guac affected chainguard guac
harbor-2.11 affected chainguard harbor-2.11
harbor-fips-2.11 affected chainguard harbor-fips-2.11
harbor-scanner-trivy affected chainguard harbor-scanner-trivy
harbor-scanner-trivy affected wolfi harbor-scanner-trivy
harbor-scanner-trivy-fips affected chainguard harbor-scanner-trivy-fips
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected wolfi helm-3
helm-3 affected chainguard helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected wolfi helm-operator
helm-operator affected chainguard helm-operator
helm-operator-fips affected chainguard helm-operator-fips
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
istio-pilot-agent-1.22 affected chainguard istio-pilot-agent-1.22
istio-pilot-discovery-1.22 affected chainguard istio-pilot-discovery-1.22
k3d affected wolfi k3d
k3d affected chainguard k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k9s affected wolfi k9s
k9s affected chainguard k9s
kaniko affected wolfi kaniko
kaniko affected chainguard kaniko
kaniko-fips affected chainguard kaniko-fips
kargo affected wolfi kargo
kargo affected chainguard kargo
ko affected wolfi ko
ko affected chainguard ko
ko-fips affected chainguard ko-fips
kots affected wolfi kots
kots affected chainguard kots
kpt affected chainguard kpt
kpt affected wolfi kpt
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
kubevela-fips affected chainguard kubevela-fips
loki-2.9 affected chainguard loki-2.9
loki-fips-2.9 affected chainguard loki-fips-2.9
longhorn-engine-1.10 affected chainguard longhorn-engine-1.10
longhorn-engine-1.8 affected chainguard longhorn-engine-1.8
longhorn-engine-1.9 affected chainguard longhorn-engine-1.9
melange affected wolfi melange
melange affected chainguard melange
moby/moby affected github.com github.com/moby/moby
nerdctl affected wolfi nerdctl
nerdctl affected chainguard nerdctl
neuvector affected chainguard neuvector
neuvector-fips affected chainguard neuvector-fips
neuvector-scanner affected wolfi neuvector-scanner
neuvector-scanner affected chainguard neuvector-scanner
neuvector-scanner-fips affected chainguard neuvector-scanner-fips
neuvector-sigstore-interface affected wolfi neuvector-sigstore-interface
neuvector-sigstore-interface affected chainguard neuvector-sigstore-interface
neuvector-sigstore-interface-fips affected chainguard neuvector-sigstore-interface-fips
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
paranoia affected wolfi paranoia
paranoia affected chainguard paranoia
policy-controller affected chainguard policy-controller
policy-controller affected wolfi policy-controller
policy-controller-fips affected chainguard policy-controller-fips
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-2.53 affected chainguard prometheus-2.53
rancher-2.10 affected chainguard rancher-2.10
rancher-agent-2.10 affected chainguard rancher-agent-2.10
rancher-agent-2.11 affected chainguard rancher-agent-2.11
rancher-agent-2.9 affected chainguard rancher-agent-2.9
rancher-fleet affected chainguard rancher-fleet
rancher-fleet affected wolfi rancher-fleet
rke2-runtime-1.33 affected chainguard rke2-runtime-1.33
rke2-runtime-1.36 affected chainguard rke2-runtime-1.36
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
skopeo affected wolfi skopeo
skopeo affected chainguard skopeo
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
syft affected chainguard syft
syft affected wolfi syft
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
timoni affected chainguard timoni
timoni affected wolfi timoni
tkn affected wolfi tkn
tkn affected chainguard tkn
tkn-fips affected chainguard tkn-fips
traefik-fips-2.11 affected chainguard traefik-fips-2.11
trivy affected wolfi trivy
trivy affected chainguard trivy
trivy-fips affected chainguard trivy-fips
up affected wolfi up
up affected chainguard up
vault-1.16 affected chainguard vault-1.16
vault-1.17 affected chainguard vault-1.17
vcluster affected chainguard vcluster
vcluster affected wolfi vcluster
vexctl affected wolfi vexctl
vexctl affected chainguard vexctl
wolfictl affected wolfi wolfictl
wolfictl affected chainguard wolfictl
zarf affected wolfi zarf
zarf affected chainguard zarf
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

CLSA-2024-1721401573

Open SourcePoC exploit2024-07-19

Fix CVE(s): CVE-2020-27619

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:18.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:18.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:18.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:18.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:18.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:18.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:18.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:18.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:18.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:18.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:18.04 python2.7-minimal
Upstream advisory

CLSA-2024-1721401321

Open SourcePoC exploit2024-07-19

Fix CVE(s): CVE-2020-27619

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

openSUSE-SU-2024:0212-1

Open SourcePoC exploitCRITICAL2024-07-22

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.5 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected SUSE:Package Hub 15 SP6 chromium
chromium affected openSUSE:Leap 15.6 chromium
Upstream advisory

openSUSE-SU-2024:0212-2

Open SourcePoC exploitCRITICAL2024-07-22

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected SUSE:Package Hub 15 SP6 chromium
chromium affected openSUSE:Leap 15.5 chromium
chromium affected openSUSE:Leap 15.6 chromium
Upstream advisory

MGASA-2024-0273

Open SourcePoC exploitCRITICAL2024-07-20

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

openSUSE-SU-2024:14205-1

Open SourcePoC exploit2024-07-19

chromedriver-126.0.6478.182-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

openSUSE-SU-2024:14144-1

Open SourcePoC exploit2024-07-12

python310-kubernetes-28.1.0-4.3 on GA media

Affected products

ProductStatusVendorPackageEcosystem
python-kubernetes affected openSUSE:Tumbleweed python-kubernetes
Upstream advisory

RLSA-2024:4212

Open SourcePoC exploitHIGH2024-07-15

Moderate: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Rocky Linux:9 golang
Upstream advisory

ALSA-2024:4212

Open SourcePoC exploit2024-07-02

Moderate: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected AlmaLinux:9 golang
golang-bin affected AlmaLinux:9 golang-bin
golang-docs affected AlmaLinux:9 golang-docs
golang-misc affected AlmaLinux:9 golang-misc
golang-src affected AlmaLinux:9 golang-src
golang-tests affected AlmaLinux:9 golang-tests
go-toolset affected AlmaLinux:9 go-toolset
Upstream advisory

ALSA-2024:4237

Open SourcePoC exploit2024-07-02

Moderate: go-toolset security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected AlmaLinux:8 delve
go affected golang
golang affected AlmaLinux:8 golang
golang-bin affected AlmaLinux:8 golang-bin
golang-docs affected AlmaLinux:8 golang-docs
golang-misc affected AlmaLinux:8 golang-misc
golang-src affected AlmaLinux:8 golang-src
golang-tests affected AlmaLinux:8 golang-tests
go-toolset affected AlmaLinux:8 go-toolset
Upstream advisory

GHSA-cx63-2mw6-8hw5

Open SourcePoC exploitCRITICAL2024-07-15

setuptools vulnerable to Command Injection via package URL

Affected products

ProductStatusVendorPackageEcosystem
airflow affected chainguard airflow
airflow affected wolfi airflow
az affected chainguard az
az affected wolfi az
checkov affected wolfi checkov
checkov affected chainguard checkov
k8s-sidecar-1.22 affected chainguard k8s-sidecar-1.22
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
nemo affected chainguard nemo
nvidia-nsight-compute-13.1 affected chainguard nvidia-nsight-compute-13.1
nvidia-nsight-compute-13.2 affected chainguard nvidia-nsight-compute-13.2
py3.10-pytorch-cuda-11.8 affected chainguard py3.10-pytorch-cuda-11.8
py3.10-pytorch-cuda-12.3 affected chainguard py3.10-pytorch-cuda-12.3
py3.10-torchvision-cuda-11.8 affected chainguard py3.10-torchvision-cuda-11.8
py3.10-torchvision-cuda-12.3 affected chainguard py3.10-torchvision-cuda-12.3
py3.11-pytorch-cuda-12.3 affected chainguard py3.11-pytorch-cuda-12.3
py3.11-torchaudio-cuda-12.3 affected chainguard py3.11-torchaudio-cuda-12.3
py3.11-torchvision-cuda-11.8 affected chainguard py3.11-torchvision-cuda-11.8
py3.11-torchvision-cuda-12.3 affected chainguard py3.11-torchvision-cuda-12.3
py3.12-pytorch-cuda-11.8 affected chainguard py3.12-pytorch-cuda-11.8
py3.12-pytorch-cuda-12.3 affected chainguard py3.12-pytorch-cuda-12.3
py3.12-torchvision-cuda-11.8 affected chainguard py3.12-torchvision-cuda-11.8
py3.12-torchvision-cuda-12.3 affected chainguard py3.12-torchvision-cuda-12.3
py3.8-setuptools affected chainguard py3.8-setuptools
py3.9-setuptools affected chainguard py3.9-setuptools
py3-cassandra-medusa affected chainguard py3-cassandra-medusa
py3-cassandra-medusa affected wolfi py3-cassandra-medusa
py3-pipenv affected chainguard py3-pipenv
py3-pipenv affected wolfi py3-pipenv
py3-torchvision-cuda-11.8 affected chainguard py3-torchvision-cuda-11.8
reflex affected wolfi reflex
reflex affected chainguard reflex
request-1276 affected chainguard request-1276
setuptools affected PyPI setuptools
setuptools affected PyPI setuptools
setuptools affected PyPI
superset affected chainguard superset
superset affected wolfi superset
Upstream advisory

GHSA-cx63-2mw6-8hw5

GooglePoC exploitCRITICAL2024-07-15

setuptools vulnerable to Command Injection via package URL

Affected products

ProductStatusVendorPackageEcosystem
setuptools affected PyPI setuptools
Upstream advisory

GHSA-4xqq-m2hx-25v8

GooglePoC exploitHIGH2024-07-16

REXML denial of service vulnerability

Affected products

ProductStatusVendorPackageEcosystem
rexml affected RubyGems rexml
Upstream advisory

GHSA-4xqq-m2hx-25v8

Open SourcePoC exploitHIGH2024-07-16

REXML denial of service vulnerability

Affected products

ProductStatusVendorPackageEcosystem
jruby-9.4 affected chainguard jruby-9.4
jruby-9.4 affected wolfi jruby-9.4
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-fluentd-operator affected chainguard kube-fluentd-operator
logstash affected wolfi logstash
logstash affected chainguard logstash
logstash-jre-bcfips affected chainguard logstash-jre-bcfips
rexml affected RubyGems rexml
ruby-3.1 affected chainguard ruby-3.1
ruby-3.1 affected wolfi ruby-3.1
ruby3.1-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.1-fluentd-kubernetes-daemonset-1.16
ruby3.1-fluentd-kubernetes-daemonset-1.17 affected chainguard ruby3.1-fluentd-kubernetes-daemonset-1.17
ruby3.1-fluentd-kubernetes-daemonset-1.17 affected wolfi ruby3.1-fluentd-kubernetes-daemonset-1.17
ruby-3.2 affected wolfi ruby-3.2
ruby-3.2 affected chainguard ruby-3.2
ruby3.2-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.2-fluentd-kubernetes-daemonset-1.16
ruby3.2-fluentd-kubernetes-daemonset-1.17 affected chainguard ruby3.2-fluentd-kubernetes-daemonset-1.17
ruby3.2-fluentd-kubernetes-daemonset-1.17 affected wolfi ruby3.2-fluentd-kubernetes-daemonset-1.17
ruby3.2-rexml affected wolfi ruby3.2-rexml
ruby3.2-rexml affected chainguard ruby3.2-rexml
ruby-3.3 affected chainguard ruby-3.3
ruby-3.3 affected wolfi ruby-3.3
ruby3.3-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.3-fluentd-kubernetes-daemonset-1.16
ruby3.4-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.4-fluentd-kubernetes-daemonset-1.16
ruby3.4-fluentd-kubernetes-daemonset-1.17 affected wolfi ruby3.4-fluentd-kubernetes-daemonset-1.17
ruby3.4-fluentd-kubernetes-daemonset-1.17 affected chainguard ruby3.4-fluentd-kubernetes-daemonset-1.17
Upstream advisory

openSUSE-SU-2024:14198-1

Open SourcePoC exploit2024-07-17

istioctl-1.22.3-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
istioctl affected openSUSE:Tumbleweed istioctl
Upstream advisory

MGASA-2024-0261

Open SourcePoC exploitHIGH2024-07-11

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:9 golang
Upstream advisory

BIT-golang-2024-24791

Open SourcePoC exploitHIGH2024-07-04

Denial of service due to improper 100-continue handling in net/http

Affected products

ProductStatusVendorPackageEcosystem
golang affected Bitnami golang
Upstream advisory

GHSA-hw49-2p59-3mhj

Open SourcePoC exploitHIGH2024-07-03

GHSA-hw49-2p59-3mhj

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
actions-runner-controller affected wolfi actions-runner-controller
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller-fips affected chainguard actions-runner-controller-fips
addon-resizer affected chainguard addon-resizer
addon-resizer affected wolfi addon-resizer
addon-resizer-fips affected chainguard addon-resizer-fips
age affected wolfi age
age affected chainguard age
amass affected chainguard amass
amass affected wolfi amass
argo-cd-fips-2.9 affected chainguard argo-cd-fips-2.9
argo-workflows affected wolfi argo-workflows
argo-workflows affected chainguard argo-workflows
atlantis affected wolfi atlantis
atlantis affected chainguard atlantis
atlantis-fips affected chainguard atlantis-fips
authservice affected chainguard authservice
authservice affected wolfi authservice
authservice-fips affected chainguard authservice-fips
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-ebs-csi-driver-fips affected chainguard aws-ebs-csi-driver-fips
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
aws-network-policy-agent affected chainguard aws-network-policy-agent
aws-network-policy-agent affected wolfi aws-network-policy-agent
azcopy-fips affected chainguard azcopy-fips
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bazelisk affected wolfi bazelisk
bazelisk affected chainguard bazelisk
bincapz affected chainguard bincapz
bincapz affected wolfi bincapz
bom affected chainguard bom
bom affected wolfi bom
boring-registry affected wolfi boring-registry
boring-registry affected chainguard boring-registry
boring-registry-fips affected chainguard boring-registry-fips
buf affected wolfi buf
buf affected chainguard buf
buildah affected chainguard buildah
buildah affected wolfi buildah
caddy affected chainguard caddy
caddy affected wolfi caddy
caddy-fips affected chainguard caddy-fips
cadvisor affected wolfi cadvisor
cadvisor affected chainguard cadvisor
cadvisor-fips affected chainguard cadvisor-fips
calico affected wolfi calico
calico affected chainguard calico
capslock affected wolfi capslock
capslock affected chainguard capslock
cass-operator affected chainguard cass-operator
cass-operator affected wolfi cass-operator
cass-operator-fips-no-pvc-delete affected chainguard cass-operator-fips-no-pvc-delete
cert-exporter affected wolfi cert-exporter
cert-exporter affected chainguard cert-exporter
cert-exporter-fips affected chainguard cert-exporter-fips
certificate-transparency affected chainguard certificate-transparency
certificate-transparency affected wolfi certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.14 affected chainguard cert-manager-1.14
cert-manager-1.14 affected wolfi cert-manager-1.14
cert-manager-1.15 affected chainguard cert-manager-1.15
cert-manager-1.15 affected wolfi cert-manager-1.15
cert-manager-cmctl affected wolfi cert-manager-cmctl
cert-manager-cmctl affected chainguard cert-manager-cmctl
cert-manager-cmctl-fips affected chainguard cert-manager-cmctl-fips
cert-manager-fips-1.12 affected chainguard cert-manager-fips-1.12
cert-manager-fips-1.14 affected chainguard cert-manager-fips-1.14
cert-manager-fips-1.15 affected chainguard cert-manager-fips-1.15
cert-manager-webhook-pdns affected chainguard cert-manager-webhook-pdns
cert-manager-webhook-pdns affected wolfi cert-manager-webhook-pdns
cert-manager-webhook-pdns-fips affected chainguard cert-manager-webhook-pdns-fips
cfssl affected chainguard cfssl
cfssl affected wolfi cfssl
chainctl affected chainguard chainctl
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
chartmuseum-fips affected chainguard chartmuseum-fips
cilium-1.14 affected wolfi cilium-1.14
cilium-1.14 affected chainguard cilium-1.14
cilium-1.15 affected wolfi cilium-1.15
cilium-1.15 affected chainguard cilium-1.15
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
cilium-fips-1.15 affected chainguard cilium-fips-1.15
cloudflared affected wolfi cloudflared
cloudflared affected chainguard cloudflared
cloudnative-pg affected wolfi cloudnative-pg
cloudnative-pg affected chainguard cloudnative-pg
cloudnative-pg-fips affected chainguard cloudnative-pg-fips
cloud-sql-proxy affected chainguard cloud-sql-proxy
cloud-sql-proxy affected wolfi cloud-sql-proxy
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
cluster-api-controller affected chainguard cluster-api-controller
cluster-api-controller affected wolfi cluster-api-controller
cluster-autoscaler-1.28 affected chainguard cluster-autoscaler-1.28
cluster-autoscaler-1.28 affected wolfi cluster-autoscaler-1.28
cluster-autoscaler-1.29 affected wolfi cluster-autoscaler-1.29
cluster-autoscaler-1.29 affected chainguard cluster-autoscaler-1.29
cluster-autoscaler-1.30 affected chainguard cluster-autoscaler-1.30
cluster-autoscaler-1.30 affected wolfi cluster-autoscaler-1.30
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
cluster-autoscaler-fips-1.29 affected chainguard cluster-autoscaler-fips-1.29
cluster-autoscaler-fips-1.30 affected chainguard cluster-autoscaler-fips-1.30
clusterctl affected chainguard clusterctl
clusterctl affected wolfi clusterctl
cluster-proportional-autoscaler affected chainguard cluster-proportional-autoscaler
cluster-proportional-autoscaler affected wolfi cluster-proportional-autoscaler
cni-plugins affected chainguard cni-plugins
cni-plugins affected wolfi cni-plugins
cni-plugins-fips affected chainguard cni-plugins-fips
configmap-reload affected wolfi configmap-reload
configmap-reload affected chainguard configmap-reload
configmap-reload-fips affected chainguard configmap-reload-fips
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
confluent-common-docker affected chainguard confluent-common-docker
confluent-common-docker affected wolfi confluent-common-docker
conftest affected chainguard conftest
conftest affected wolfi conftest
conftest-fips affected chainguard conftest-fips
consul-1.15 affected wolfi consul-1.15
consul-1.15 affected chainguard consul-1.15
consul-1.16 affected chainguard consul-1.16
consul-1.16 affected wolfi consul-1.16
consul-1.17 affected chainguard consul-1.17
consul-1.17-fips affected chainguard consul-1.17-fips
containerd affected chainguard containerd
containerd affected wolfi containerd
contour-1.27 affected chainguard contour-1.27
contour-1.27 affected wolfi contour-1.27
contour-1.28 affected chainguard contour-1.28
contour-1.28 affected wolfi contour-1.28
contour-1.29 affected chainguard contour-1.29
contour-1.29 affected wolfi contour-1.29
controller-gen affected wolfi controller-gen
controller-gen affected chainguard controller-gen
coredns affected wolfi coredns
coredns affected chainguard coredns
coredns-fips affected chainguard coredns-fips
cortex affected chainguard cortex
cortex affected wolfi cortex
cortex-fips affected chainguard cortex-fips
cosign affected wolfi cosign
cosign affected chainguard cosign
cosign-fips affected chainguard cosign-fips
cosign-fips affected wolfi cosign-fips
crane affected wolfi crane
crane affected chainguard crane
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
croc affected chainguard croc
croc affected wolfi croc
crossplane affected chainguard crossplane
crossplane affected wolfi crossplane
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure affected wolfi crossplane-provider-azure
ctop affected wolfi ctop
ctop affected chainguard ctop
cue affected chainguard cue
cue affected wolfi cue
cue-fips affected chainguard cue-fips
dagdotdev affected chainguard dagdotdev
dagdotdev affected wolfi dagdotdev
dagger affected chainguard dagger
dagger affected wolfi dagger
dask-gateway affected wolfi dask-gateway
dask-gateway affected chainguard dask-gateway
datadog-agent affected wolfi datadog-agent
datadog-agent affected chainguard datadog-agent
dataplaneapi affected chainguard dataplaneapi
dataplaneapi affected wolfi dataplaneapi
dataplaneapi-fips affected chainguard dataplaneapi-fips
dbmate affected wolfi dbmate
dbmate affected chainguard dbmate
delve affected chainguard delve
delve affected wolfi delve
dex affected wolfi dex
dex affected chainguard dex
dex-fips affected chainguard dex-fips
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
direnv affected wolfi direnv
direnv affected chainguard direnv
dive affected wolfi dive
dive affected chainguard dive
docker-compose affected wolfi docker-compose
docker-compose affected chainguard docker-compose
docker-credential-acr-env affected wolfi docker-credential-acr-env
docker-credential-acr-env affected chainguard docker-credential-acr-env
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-gcr affected chainguard docker-credential-gcr
docker-credential-gcr affected wolfi docker-credential-gcr
dockerize affected chainguard dockerize
dockerize affected wolfi dockerize
dockerize-fips affected chainguard dockerize-fips
doppler-kubernetes-operator affected wolfi doppler-kubernetes-operator
doppler-kubernetes-operator affected chainguard doppler-kubernetes-operator
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
envoy-ratelimit affected chainguard envoy-ratelimit
envoy-ratelimit affected wolfi envoy-ratelimit
envoy-ratelimit-fips affected chainguard envoy-ratelimit-fips
esbuild affected wolfi esbuild
esbuild affected chainguard esbuild
esbuild-fips affected chainguard esbuild-fips
etcd-3.4 affected chainguard etcd-3.4
etcd-3.5 affected chainguard etcd-3.5
etcd-3.5 affected wolfi etcd-3.5
etcd-fips-3.4 affected chainguard etcd-fips-3.4
etcd-fips-3.5 affected chainguard etcd-fips-3.5
external-dns affected wolfi external-dns
external-dns affected chainguard external-dns
external-dns-fips affected chainguard external-dns-fips
external-secrets-fips affected chainguard external-secrets-fips
external-secrets-operator affected wolfi external-secrets-operator
external-secrets-operator affected chainguard external-secrets-operator
extism affected chainguard extism
extism affected wolfi extism
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
falcosidekick affected chainguard falcosidekick
falcosidekick affected wolfi falcosidekick
falcosidekick-fips affected chainguard falcosidekick-fips
ferretdb affected chainguard ferretdb
ferretdb affected wolfi ferretdb
filebeat affected chainguard filebeat
filebeat affected wolfi filebeat
filebeat-7.17 affected chainguard filebeat-7.17
filebeat-7.17-fips affected chainguard filebeat-7.17-fips
flannel affected wolfi flannel
flannel affected chainguard flannel
flannel-cni-plugin affected wolfi flannel-cni-plugin
flannel-cni-plugin affected chainguard flannel-cni-plugin
fluent-bit-plugin-loki affected chainguard fluent-bit-plugin-loki
fluent-bit-plugin-loki affected wolfi fluent-bit-plugin-loki
fluent-operator affected wolfi fluent-operator
fluent-operator affected chainguard fluent-operator
fluent-operator-fips affected chainguard fluent-operator-fips
flux affected wolfi flux
flux affected chainguard flux
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
flyte affected chainguard flyte
flyte affected wolfi flyte
fulcio affected wolfi fulcio
fulcio affected chainguard fulcio
fulcio-fips affected chainguard fulcio-fips
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fzf affected wolfi fzf
fzf affected chainguard fzf
gatekeeper-3.15 affected chainguard gatekeeper-3.15
gatekeeper-3.15 affected wolfi gatekeeper-3.15
gatekeeper-3.16 affected wolfi gatekeeper-3.16
gatekeeper-3.16 affected chainguard gatekeeper-3.16
gatekeeper-fips-3.15 affected chainguard gatekeeper-fips-3.15
gatekeeper-fips-3.16 affected chainguard gatekeeper-fips-3.16
gcsfuse affected wolfi gcsfuse
gcsfuse affected chainguard gcsfuse
gh affected chainguard gh
gh affected wolfi gh
ghaudit affected chainguard ghaudit
ghaudit affected wolfi ghaudit
gitaly affected chainguard gitaly
gitaly affected wolfi gitaly
gitlab-kas affected wolfi gitlab-kas
gitlab-kas affected chainguard gitlab-kas
gitlab-rails-ee-17.0 affected chainguard gitlab-rails-ee-17.0
gitlab-rails-ee-17.3 affected chainguard gitlab-rails-ee-17.3
gitlab-rails-ee-fips-17.0 affected chainguard gitlab-rails-ee-fips-17.0
gitlab-rails-ee-fips-17.1 affected chainguard gitlab-rails-ee-fips-17.1
gitlab-runner affected wolfi gitlab-runner
gitlab-runner affected chainguard gitlab-runner
gitlab-runner-fips affected chainguard gitlab-runner-fips
gitleaks affected chainguard gitleaks
gitleaks affected wolfi gitleaks
git-lfs affected chainguard git-lfs
git-lfs affected wolfi git-lfs
git-lfs-fips affected chainguard git-lfs-fips
gitness affected wolfi gitness
gitness affected chainguard gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
glab affected wolfi glab
glab affected chainguard glab
go-1.20 affected chainguard go-1.20
go-1.20 affected wolfi go-1.20
go-1.21 affected chainguard go-1.21
go-1.21 affected wolfi go-1.21
go-1.22 affected chainguard go-1.22
go-1.22 affected wolfi go-1.22
go-bindata affected chainguard go-bindata
go-bindata affected wolfi go-bindata
gobump affected wolfi gobump
gobump affected chainguard gobump
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
go-fips-1.21 affected chainguard go-fips-1.21
go-fips-1.21 affected wolfi go-fips-1.21
go-fips-1.22 affected chainguard go-fips-1.22
go-ipfs-fips affected chainguard go-ipfs-fips
golangci-lint affected wolfi golangci-lint
golangci-lint affected chainguard golangci-lint
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
go-md2man affected chainguard go-md2man
go-md2man affected wolfi go-md2man
gomplate affected wolfi gomplate
gomplate affected chainguard gomplate
gomplate-fips affected chainguard gomplate-fips
go-openssl-1.22 affected chainguard go-openssl-1.22
gops affected chainguard gops
gops affected wolfi gops
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
gostatsd affected chainguard gostatsd
gostatsd affected wolfi gostatsd
gosu affected wolfi gosu
gosu affected chainguard gosu
gosu-1.11 affected chainguard gosu-1.11
gosu-fips affected chainguard gosu-fips
gotenberg affected chainguard gotenberg
govulncheck affected chainguard govulncheck
govulncheck affected wolfi govulncheck
gpu-feature-discovery affected chainguard gpu-feature-discovery
gpu-operator affected chainguard gpu-operator
grafana-10.4 affected wolfi grafana-10.4
grafana-10.4 affected chainguard grafana-10.4
grafana-11.0 affected wolfi grafana-11.0
grafana-11.0 affected chainguard grafana-11.0
grafana-11.1 affected chainguard grafana-11.1
grafana-11.1 affected wolfi grafana-11.1
grafana-9 affected chainguard grafana-9
grafana-9-fips affected chainguard grafana-9-fips
grafana-agent-operator affected wolfi grafana-agent-operator
grafana-agent-operator affected chainguard grafana-agent-operator
grafana-fips-10.4 affected chainguard grafana-fips-10.4
grafana-fips-11.0 affected chainguard grafana-fips-11.0
grafana-fips-11.1 affected chainguard grafana-fips-11.1
grafana-mimir affected chainguard grafana-mimir
grafana-mimir affected wolfi grafana-mimir
grafana-operator-fips affected chainguard grafana-operator-fips
grafana-rollout-operator-0.14 affected chainguard grafana-rollout-operator-0.14
grafana-rollout-operator-0.14 affected wolfi grafana-rollout-operator-0.14
grpc-health-probe-fips affected chainguard grpc-health-probe-fips
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
grype affected wolfi grype
grype affected chainguard grype
guac affected wolfi guac
guac affected chainguard guac
haproxy-ingress affected wolfi haproxy-ingress
haproxy-ingress affected chainguard haproxy-ingress
harbor-2.10 affected chainguard harbor-2.10
harbor-2.10 affected wolfi harbor-2.10
harbor-2.11 affected wolfi harbor-2.11
harbor-2.11 affected chainguard harbor-2.11
harbor-2.9 affected chainguard harbor-2.9
harbor-cli affected wolfi harbor-cli
harbor-cli affected chainguard harbor-cli
harbor-fips-2.10 affected chainguard harbor-fips-2.10
harbor-fips-2.11 affected chainguard harbor-fips-2.11
harbor-fips-2.9 affected chainguard harbor-fips-2.9
harbor-registry affected wolfi harbor-registry
harbor-registry affected chainguard harbor-registry
harbor-registry-fips affected chainguard harbor-registry-fips
harbor-scanner-trivy affected wolfi harbor-scanner-trivy
harbor-scanner-trivy affected chainguard harbor-scanner-trivy
harbor-scanner-trivy-fips affected chainguard harbor-scanner-trivy-fips
hello-world-golang affected chainguard hello-world-golang
hello-world-golang affected wolfi hello-world-golang
helm affected chainguard helm
helm affected wolfi helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
helm-docs affected wolfi helm-docs
helm-docs affected chainguard helm-docs
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected chainguard helm-operator
helm-operator affected wolfi helm-operator
helm-operator-fips affected chainguard helm-operator-fips
helm-operator-fips-1.33 affected chainguard helm-operator-fips-1.33
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
hey affected wolfi hey
hey affected chainguard hey
hivemind affected chainguard hivemind
hivemind affected wolfi hivemind
http-echo affected chainguard http-echo
http-echo affected wolfi http-echo
hubble affected wolfi hubble
hubble affected chainguard hubble
hubble-fips affected chainguard hubble-fips
hubble-ui affected wolfi hubble-ui
hubble-ui affected chainguard hubble-ui
hubble-ui-backend-fips affected chainguard hubble-ui-backend-fips
hugo affected wolfi hugo
hugo affected chainguard hugo
hugo-extended affected chainguard hugo-extended
hugo-extended affected wolfi hugo-extended
influx affected wolfi influx
influx affected chainguard influx
influxd affected wolfi influxd
influxd affected chainguard influxd
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller-1.9 affected chainguard ingress-nginx-controller-1.9
ingress-nginx-controller-fips affected chainguard ingress-nginx-controller-fips
ingress-nginx-controller-fips-1.9 affected chainguard ingress-nginx-controller-fips-1.9
ipfs affected chainguard ipfs
ipfs affected wolfi ipfs
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
istio-cni-1.21 affected chainguard istio-cni-1.21
istio-cni-1.21 affected wolfi istio-cni-1.21
istio-cni-1.22 affected wolfi istio-cni-1.22
istio-cni-1.22 affected chainguard istio-cni-1.22
istio-operator-1.21 affected wolfi istio-operator-1.21
istio-operator-1.21 affected chainguard istio-operator-1.21
istio-operator-1.22 affected chainguard istio-operator-1.22
istio-operator-1.22 affected wolfi istio-operator-1.22
istio-pilot-agent-1.20 affected chainguard istio-pilot-agent-1.20
istio-pilot-agent-1.20 affected wolfi istio-pilot-agent-1.20
istio-pilot-agent-1.21 affected wolfi istio-pilot-agent-1.21
istio-pilot-agent-1.21 affected chainguard istio-pilot-agent-1.21
istio-pilot-agent-1.22 affected wolfi istio-pilot-agent-1.22
istio-pilot-agent-1.22 affected chainguard istio-pilot-agent-1.22
istio-pilot-discovery-1.21 affected wolfi istio-pilot-discovery-1.21
istio-pilot-discovery-1.21 affected chainguard istio-pilot-discovery-1.21
istio-pilot-discovery-1.22 affected wolfi istio-pilot-discovery-1.22
istio-pilot-discovery-1.22 affected chainguard istio-pilot-discovery-1.22
jitsucom-bulker affected wolfi jitsucom-bulker
jitsucom-bulker affected chainguard jitsucom-bulker
jsonnet-bundler affected chainguard jsonnet-bundler
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected wolfi k3s
k3s affected chainguard k3s
k8s-device-plugin affected chainguard k8s-device-plugin
k8s-device-plugin affected wolfi k8s-device-plugin
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k8sgpt-operator affected wolfi k8sgpt-operator
k8sgpt-operator affected chainguard k8sgpt-operator
k8ssandra-operator affected wolfi k8ssandra-operator
k8ssandra-operator affected chainguard k8ssandra-operator
k8ssandra-operator-fips affected chainguard k8ssandra-operator-fips
k9s affected wolfi k9s
k9s affected chainguard k9s
kaf affected chainguard kaf
kaf affected wolfi kaf
kafka_exporter affected wolfi kafka_exporter
kafka_exporter affected chainguard kafka_exporter
kafka-proxy affected chainguard kafka-proxy
kafka-proxy affected wolfi kafka-proxy
kaniko affected wolfi kaniko
kaniko affected chainguard kaniko
kargo affected wolfi kargo
kargo affected chainguard kargo
karpenter affected chainguard karpenter
karpenter affected wolfi karpenter
karpenter-0.23 affected chainguard karpenter-0.23
karpenter-0.35 affected chainguard karpenter-0.35
karpenter-fips-0.35 affected chainguard karpenter-fips-0.35
karpenter-fips-0.36 affected chainguard karpenter-fips-0.36
keda-2.13 affected chainguard keda-2.13
keda-2.13 affected wolfi keda-2.13
keda-2.14 affected chainguard keda-2.14
keda-2.14 affected wolfi keda-2.14
kiam affected chainguard kiam
kind affected chainguard kind
kind affected wolfi kind
kine affected chainguard kine
kine affected wolfi kine
ko affected chainguard ko
ko affected wolfi ko
ko-fips affected wolfi ko-fips
ko-fips affected chainguard ko-fips
kor affected wolfi kor
kor affected chainguard kor
kots affected wolfi kots
kots affected chainguard kots
kpt affected wolfi kpt
kpt affected chainguard kpt
kubeadm-bootstrap-controller affected wolfi kubeadm-bootstrap-controller
kubeadm-bootstrap-controller affected chainguard kubeadm-bootstrap-controller
kubeadm-controlplane-controller affected chainguard kubeadm-controlplane-controller
kubeadm-controlplane-controller affected wolfi kubeadm-controlplane-controller
kube-bench affected wolfi kube-bench
kube-bench affected chainguard kube-bench
kubebuilder affected wolfi kubebuilder
kubebuilder affected chainguard kubebuilder
kubecolor affected wolfi kubecolor
kubecolor affected chainguard kubecolor
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kube-logging-operator affected wolfi kube-logging-operator
kube-logging-operator affected chainguard kube-logging-operator
kube-oidc-proxy affected chainguard kube-oidc-proxy
kuberay-operator affected chainguard kuberay-operator
kuberay-operator affected wolfi kuberay-operator
kube-rbac-proxy affected wolfi kube-rbac-proxy
kube-rbac-proxy affected chainguard kube-rbac-proxy
kube-rbac-proxy-fips affected chainguard kube-rbac-proxy-fips
kubernetes-1.30 affected wolfi kubernetes-1.30
kubernetes-1.30 affected chainguard kubernetes-1.30
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-external-attacher-4.3 affected chainguard kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.3 affected wolfi kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.4 affected chainguard kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-attacher-4.4 affected wolfi kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-attacher-fips-4.3 affected chainguard kubernetes-csi-external-attacher-fips-4.3
kubernetes-csi-external-attacher-fips-4.4 affected chainguard kubernetes-csi-external-attacher-fips-4.4
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer-1.10 affected wolfi kubernetes-csi-external-resizer-1.10
kubernetes-csi-external-resizer-1.10 affected chainguard kubernetes-csi-external-resizer-1.10
kubernetes-csi-external-resizer-1.8 affected chainguard kubernetes-csi-external-resizer-1.8
kubernetes-csi-external-resizer-1.9 affected chainguard kubernetes-csi-external-resizer-1.9
kubernetes-csi-external-resizer-fips-1.10 affected chainguard kubernetes-csi-external-resizer-fips-1.10
kubernetes-csi-external-resizer-fips-1.8 affected chainguard kubernetes-csi-external-resizer-fips-1.8
kubernetes-csi-external-resizer-fips-1.9 affected chainguard kubernetes-csi-external-resizer-fips-1.9
kubernetes-csi-external-snapshotter-6.0 affected chainguard kubernetes-csi-external-snapshotter-6.0
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-csi-node-driver-registrar-2.10 affected wolfi kubernetes-csi-node-driver-registrar-2.10
kubernetes-csi-node-driver-registrar-2.10 affected chainguard kubernetes-csi-node-driver-registrar-2.10
kubernetes-csi-node-driver-registrar-2.11 affected chainguard kubernetes-csi-node-driver-registrar-2.11
kubernetes-csi-node-driver-registrar-2.11 affected wolfi kubernetes-csi-node-driver-registrar-2.11
kubernetes-csi-node-driver-registrar-2.6 affected chainguard kubernetes-csi-node-driver-registrar-2.6
kubernetes-csi-node-driver-registrar-2.7 affected chainguard kubernetes-csi-node-driver-registrar-2.7
kubernetes-csi-node-driver-registrar-2.8 affected chainguard kubernetes-csi-node-driver-registrar-2.8
kubernetes-csi-node-driver-registrar-2.9 affected wolfi kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-2.9 affected chainguard kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-fips-2.10 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.10
kubernetes-csi-node-driver-registrar-fips-2.11 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.11
kubernetes-csi-node-driver-registrar-fips-2.6 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.6
kubernetes-csi-node-driver-registrar-fips-2.7 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.7
kubernetes-csi-node-driver-registrar-fips-2.8 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.8
kubernetes-csi-node-driver-registrar-fips-2.9 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.9
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard-fips affected chainguard kubernetes-dashboard-fips
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper-fips affected chainguard kubernetes-dashboard-metrics-scraper-fips
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache-fips affected chainguard kubernetes-dns-node-cache-fips
kubernetes-event-exporter affected chainguard kubernetes-event-exporter
kubernetes-event-exporter affected wolfi kubernetes-event-exporter
kubernetes-ingress-defaultbackend affected chainguard kubernetes-ingress-defaultbackend
kubernetes-ingress-defaultbackend affected wolfi kubernetes-ingress-defaultbackend
kube-state-metrics affected wolfi kube-state-metrics
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics-2.2.0 affected chainguard kube-state-metrics-2.2.0
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
kube-vip affected wolfi kube-vip
kube-vip affected chainguard kube-vip
kube-vip-fips affected chainguard kube-vip-fips
kubewatch affected chainguard kubewatch
kubewatch affected wolfi kubewatch
kustomize affected chainguard kustomize
kustomize affected wolfi kustomize
kustomize-fips affected chainguard kustomize-fips
kwok affected wolfi kwok
kwok affected chainguard kwok
kyverno affected wolfi kyverno
kyverno affected chainguard kyverno
kyverno-fips-1.12 affected chainguard kyverno-fips-1.12
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
kyverno-policy-reporter-2.11 affected chainguard kyverno-policy-reporter-2.11
kyverno-policy-reporter-kyverno-plugin affected chainguard kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-kyverno-plugin affected wolfi kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-kyverno-plugin-1.5 affected chainguard kyverno-policy-reporter-kyverno-plugin-1.5
kyverno-policy-reporter-ui affected wolfi kyverno-policy-reporter-ui
kyverno-policy-reporter-ui affected chainguard kyverno-policy-reporter-ui
kyverno-policy-reporter-ui-1.7 affected chainguard kyverno-policy-reporter-ui-1.7
lazygit affected wolfi lazygit
lazygit affected chainguard lazygit
libnvidia-container affected wolfi libnvidia-container
libnvidia-container affected chainguard libnvidia-container
litefs affected wolfi litefs
litefs affected chainguard litefs
litestream affected wolfi litestream
litestream affected chainguard litestream
local-path-provisioner affected chainguard local-path-provisioner
local-path-provisioner affected wolfi local-path-provisioner
local-static-provisioner affected chainguard local-static-provisioner
local-static-provisioner affected wolfi local-static-provisioner
logstash affected chainguard logstash
logstash affected wolfi logstash
logstash-exporter affected wolfi logstash-exporter
logstash-exporter affected chainguard logstash-exporter
logstash-exporter-fips affected chainguard logstash-exporter-fips
logstash-jre-bcfips affected chainguard logstash-jre-bcfips
mage affected chainguard mage
mage affected wolfi mage
mattermost-9 affected chainguard mattermost-9
mattermost-9 affected wolfi mattermost-9
mc affected wolfi mc
mc affected chainguard mc
mc-fips affected chainguard mc-fips
memcached-exporter affected chainguard memcached-exporter
memcached-exporter affected wolfi memcached-exporter
metacontroller affected chainguard metacontroller
metacontroller affected wolfi metacontroller
metallb affected chainguard metallb
metallb affected wolfi metallb
metrics-server affected chainguard metrics-server
metrics-server affected wolfi metrics-server
metrics-server-fips affected chainguard metrics-server-fips
minify affected wolfi minify
minify affected chainguard minify
minify-fips affected chainguard minify-fips
minio affected chainguard minio
minio affected wolfi minio
mkcert affected wolfi mkcert
mkcert affected chainguard mkcert
mockery affected wolfi mockery
mockery affected chainguard mockery
mods affected chainguard mods
mods affected wolfi mods
mongo-tools affected wolfi mongo-tools
mongo-tools affected chainguard mongo-tools
multus-cni affected wolfi multus-cni
multus-cni affected chainguard multus-cni
multus-cni-fips affected chainguard multus-cni-fips
nats affected chainguard nats
nats affected wolfi nats
nats-server affected chainguard nats-server
nats-server affected wolfi nats-server
nerdctl affected chainguard nerdctl
nerdctl affected wolfi nerdctl
neuvector affected chainguard neuvector
neuvector affected wolfi neuvector
neuvector-scanner affected chainguard neuvector-scanner
neuvector-scanner affected wolfi neuvector-scanner
neuvector-scanner-fips affected chainguard neuvector-scanner-fips
neuvector-sigstore-interface affected wolfi neuvector-sigstore-interface
neuvector-sigstore-interface affected chainguard neuvector-sigstore-interface
neuvector-sigstore-interface-fips affected chainguard neuvector-sigstore-interface-fips
newrelic-fluent-bit-output affected wolfi newrelic-fluent-bit-output
newrelic-fluent-bit-output affected chainguard newrelic-fluent-bit-output
newrelic-infra-operator affected chainguard newrelic-infra-operator
newrelic-infra-operator affected wolfi newrelic-infra-operator
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent-1.43 affected chainguard newrelic-infrastructure-agent-1.43
newrelic-nri-kube-events affected chainguard newrelic-nri-kube-events
newrelic-nri-kube-events affected wolfi newrelic-nri-kube-events
newrelic-nri-kube-events-1.9 affected chainguard newrelic-nri-kube-events-1.9
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
newrelic-prometheus-configurator affected chainguard newrelic-prometheus-configurator
newrelic-prometheus-configurator affected wolfi newrelic-prometheus-configurator
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
node-feature-discovery-0.15 affected wolfi node-feature-discovery-0.15
node-feature-discovery-0.15 affected chainguard node-feature-discovery-0.15
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nri-apache affected wolfi nri-apache
nri-apache affected chainguard nri-apache
nri-cassandra affected wolfi nri-cassandra
nri-cassandra affected chainguard nri-cassandra
nri-consul affected wolfi nri-consul
nri-consul affected chainguard nri-consul
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nri-elasticsearch affected wolfi nri-elasticsearch
nri-elasticsearch affected chainguard nri-elasticsearch
nri-f5 affected chainguard nri-f5
nri-f5 affected wolfi nri-f5
nri-haproxy affected chainguard nri-haproxy
nri-haproxy affected wolfi nri-haproxy
nri-jmx affected wolfi nri-jmx
nri-jmx affected chainguard nri-jmx
nri-kafka affected chainguard nri-kafka
nri-kafka affected wolfi nri-kafka
nri-kubernetes affected chainguard nri-kubernetes
nri-kubernetes affected wolfi nri-kubernetes
nri-kubernetes-2.13 affected chainguard nri-kubernetes-2.13
nri-memcached affected chainguard nri-memcached
nri-memcached affected wolfi nri-memcached
nri-mongodb affected wolfi nri-mongodb
nri-mongodb affected chainguard nri-mongodb
nri-mssql affected wolfi nri-mssql
nri-mssql affected chainguard nri-mssql
nri-mysql affected wolfi nri-mysql
nri-mysql affected chainguard nri-mysql
nri-nagios affected chainguard nri-nagios
nri-nagios affected wolfi nri-nagios
nri-nginx affected chainguard nri-nginx
nri-nginx affected wolfi nri-nginx
nri-postgresql affected chainguard nri-postgresql
nri-postgresql affected wolfi nri-postgresql
nri-prometheus affected chainguard nri-prometheus
nri-prometheus affected wolfi nri-prometheus
nri-redis affected chainguard nri-redis
nri-redis affected wolfi nri-redis
nsc affected wolfi nsc
nsc affected chainguard nsc
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
nvidia-container-toolkit affected chainguard nvidia-container-toolkit
nvidia-container-toolkit affected wolfi nvidia-container-toolkit
nvidia-nsight-compute-12.8 affected chainguard nvidia-nsight-compute-12.8
oauth2-proxy affected wolfi oauth2-proxy
oauth2-proxy affected chainguard oauth2-proxy
octo-sts affected chainguard octo-sts
octo-sts affected wolfi octo-sts
ollama affected wolfi ollama
ollama affected chainguard ollama
opa affected wolfi opa
opa affected chainguard opa
opa-fips affected chainguard opa-fips
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
opentofu affected chainguard opentofu
opentofu affected wolfi opentofu
oras affected chainguard oras
oras affected wolfi oras
osv-scanner affected chainguard osv-scanner
osv-scanner affected wolfi osv-scanner
overmind affected wolfi overmind
overmind affected chainguard overmind
paranoia affected wolfi paranoia
paranoia affected chainguard paranoia
petname affected wolfi petname
petname affected chainguard petname
php-fpm_exporter affected chainguard php-fpm_exporter
php-fpm_exporter affected wolfi php-fpm_exporter
pluto affected chainguard pluto
pluto affected wolfi pluto
policy-controller affected wolfi policy-controller
policy-controller affected chainguard policy-controller
policy-controller-fips affected chainguard policy-controller-fips
pombump affected chainguard pombump
pombump affected wolfi pombump
postgres-operator affected wolfi postgres-operator
postgres-operator affected chainguard postgres-operator
prometheus-2.45 affected wolfi prometheus-2.45
prometheus-2.45 affected chainguard prometheus-2.45
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-2.53 affected wolfi prometheus-2.53
prometheus-2.53 affected chainguard prometheus-2.53
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-alertmanager-fips affected chainguard prometheus-alertmanager-fips
prometheus-beat-exporter affected wolfi prometheus-beat-exporter
prometheus-beat-exporter affected chainguard prometheus-beat-exporter
prometheus-beat-exporter-fips affected chainguard prometheus-beat-exporter-fips
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-blackbox-exporter affected wolfi prometheus-blackbox-exporter
prometheus-blackbox-exporter-fips affected chainguard prometheus-blackbox-exporter-fips
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter affected wolfi prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter-fips affected chainguard prometheus-elasticsearch-exporter-fips
prometheus-fips affected chainguard prometheus-fips
prometheus-fips-2.45 affected chainguard prometheus-fips-2.45
prometheus-fips-2.53 affected chainguard prometheus-fips-2.53
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter affected wolfi prometheus-mongodb-exporter
prometheus-mongodb-exporter-0.37 affected chainguard prometheus-mongodb-exporter-0.37
prometheus-mongodb-exporter-fips affected chainguard prometheus-mongodb-exporter-fips
prometheus-mongodb-exporter-fips-0.37 affected chainguard prometheus-mongodb-exporter-fips-0.37
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-mysqld-exporter affected wolfi prometheus-mysqld-exporter
prometheus-nats-exporter affected wolfi prometheus-nats-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-node-exporter affected wolfi prometheus-node-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter-1.4 affected chainguard prometheus-node-exporter-1.4
prometheus-node-exporter-1.5 affected chainguard prometheus-node-exporter-1.5
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-postgres-exporter affected wolfi prometheus-postgres-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-postgres-exporter-0.13 affected chainguard prometheus-postgres-exporter-0.13
prometheus-postgres-exporter-fips affected chainguard prometheus-postgres-exporter-fips
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway-1.4 affected chainguard prometheus-pushgateway-1.4
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
prometheus-pushgateway-fips-1.4 affected chainguard prometheus-pushgateway-fips-1.4
prometheus-redis-exporter affected chainguard prometheus-redis-exporter
prometheus-redis-exporter affected wolfi prometheus-redis-exporter
prometheus-redis-exporter-fips affected chainguard prometheus-redis-exporter-fips
prometheus-redis-exporter-fips-1.44 affected chainguard prometheus-redis-exporter-fips-1.44
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter affected wolfi prometheus-statsd-exporter
prometheus-statsd-exporter-0.22 affected chainguard prometheus-statsd-exporter-0.22
prometheus-statsd-exporter-fips affected chainguard prometheus-statsd-exporter-fips
prometheus-statsd-exporter-fips-0.22 affected chainguard prometheus-statsd-exporter-fips-0.22
protoc-gen-go affected chainguard protoc-gen-go
protoc-gen-go affected wolfi protoc-gen-go
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-yaml affected wolfi pulumi-language-yaml
pulumi-language-yaml affected chainguard pulumi-language-yaml
q affected wolfi q
q affected chainguard q
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-default-user-credential-updater affected chainguard rabbitmq-default-user-credential-updater
rabbitmq-default-user-credential-updater affected wolfi rabbitmq-default-user-credential-updater
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
rclone affected chainguard rclone
rclone affected wolfi rclone
redka affected chainguard redka
redka affected wolfi redka
regclient affected wolfi regclient
regclient affected chainguard regclient
rekor affected chainguard rekor
rekor affected wolfi rekor
rekor-fips affected chainguard rekor-fips
render-template affected wolfi render-template
render-template affected chainguard render-template
request-1279 affected chainguard request-1279
request-1279-1-14 affected chainguard request-1279-1-14
restic affected wolfi restic
restic affected chainguard restic
restic-fips affected chainguard restic-fips
rootlesskit affected chainguard rootlesskit
rootlesskit affected wolfi rootlesskit
runc affected wolfi runc
runc affected chainguard runc
s5cmd affected chainguard s5cmd
s5cmd affected wolfi s5cmd
sbom-convert affected chainguard sbom-convert
sbom-convert affected wolfi sbom-convert
sbom-scorecard affected chainguard sbom-scorecard
sbom-scorecard affected wolfi sbom-scorecard
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
shfmt affected chainguard shfmt
shfmt affected wolfi shfmt
sigstore-scaffolding-fips affected chainguard sigstore-scaffolding-fips
skaffold affected wolfi skaffold
skaffold affected chainguard skaffold
skopeo affected wolfi skopeo
skopeo affected chainguard skopeo
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
snyk-cli affected chainguard snyk-cli
snyk-cli affected wolfi snyk-cli
sonobuoy affected chainguard sonobuoy
sonobuoy affected wolfi sonobuoy
speedtest-go affected chainguard speedtest-go
speedtest-go affected wolfi speedtest-go
spegel affected wolfi spegel
spegel affected chainguard spegel
spicedb affected chainguard spicedb
spicedb affected wolfi spicedb
spqr affected wolfi spqr
spqr affected chainguard spqr
src affected chainguard src
src affected wolfi src
src-fingerprint affected wolfi src-fingerprint
src-fingerprint affected chainguard src-fingerprint
src-fingerprint-fips affected chainguard src-fingerprint-fips
stakater-reloader affected wolfi stakater-reloader
stakater-reloader affected chainguard stakater-reloader
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
step affected wolfi step
step affected chainguard step
step-ca affected chainguard step-ca
step-ca affected wolfi step-ca
step-ca-fips affected chainguard step-ca-fips
step-fips affected chainguard step-fips
step-issuer affected chainguard step-issuer
step-issuer affected wolfi step-issuer
step-issuer-fips affected chainguard step-issuer-fips
stern affected wolfi stern
stern affected chainguard stern
supercronic affected wolfi supercronic
supercronic affected chainguard supercronic
swagger affected wolfi swagger
swagger affected chainguard swagger
syft affected chainguard syft
syft affected wolfi syft
tailscale affected chainguard tailscale
tailscale affected wolfi tailscale
task affected wolfi task
task affected chainguard task
tctl affected chainguard tctl
tctl affected wolfi tctl
tekton-chains affected chainguard tekton-chains
tekton-chains affected wolfi tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
telegraf-1.30 affected chainguard telegraf-1.30
telegraf-1.30 affected wolfi telegraf-1.30
telegraf-1.31 affected chainguard telegraf-1.31
telegraf-1.31 affected wolfi telegraf-1.31
teleport affected wolfi teleport
teleport affected chainguard teleport
tempo affected chainguard tempo
tempo affected wolfi tempo
tempo-2.3 affected chainguard tempo-2.3
tempo-fips affected chainguard tempo-fips
temporal affected chainguard temporal
temporal affected wolfi temporal
temporal-ui-server affected wolfi temporal-ui-server
temporal-ui-server affected chainguard temporal-ui-server
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-docs affected chainguard terraform-docs
terraform-docs affected wolfi terraform-docs
terraform-fips-1.5 affected chainguard terraform-fips-1.5
terraform-provider-aws affected chainguard terraform-provider-aws
terraform-provider-aws affected wolfi terraform-provider-aws
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terraform-provider-google affected chainguard terraform-provider-google
terraform-provider-google affected wolfi terraform-provider-google
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
tflint affected chainguard tflint
tflint affected wolfi tflint
thanos affected wolfi thanos
thanos affected chainguard thanos
thanos-fips affected chainguard thanos-fips
thanos-operator affected wolfi thanos-operator
thanos-operator affected chainguard thanos-operator
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
tigera-operator-1.30 affected chainguard tigera-operator-1.30
tigera-operator-1.30 affected wolfi tigera-operator-1.30
tigera-operator-1.31 affected chainguard tigera-operator-1.31
tigera-operator-1.31 affected wolfi tigera-operator-1.31
tigera-operator-1.32 affected wolfi tigera-operator-1.32
tigera-operator-1.32 affected chainguard tigera-operator-1.32
tigera-operator-1.33 affected chainguard tigera-operator-1.33
tigera-operator-1.33 affected wolfi tigera-operator-1.33
tigera-operator-1.34 affected wolfi tigera-operator-1.34
tigera-operator-1.34 affected chainguard tigera-operator-1.34
tigera-operator-fips affected chainguard tigera-operator-fips
tigera-operator-fips-1.29 affected chainguard tigera-operator-fips-1.29
tigera-operator-fips-1.30 affected chainguard tigera-operator-fips-1.30
tigera-operator-fips-1.31 affected chainguard tigera-operator-fips-1.31
tigera-operator-fips-1.32 affected chainguard tigera-operator-fips-1.32
tigera-operator-fips-1.33 affected chainguard tigera-operator-fips-1.33
tigera-operator-fips-1.34 affected chainguard tigera-operator-fips-1.34
timestamp-authority affected chainguard timestamp-authority
timestamp-authority affected wolfi timestamp-authority
timestamp-authority-fips affected chainguard timestamp-authority-fips
timoni affected wolfi timoni
timoni affected chainguard timoni
tkn affected chainguard tkn
tkn affected wolfi tkn
tkn-fips affected chainguard tkn-fips
traefik-3.0 affected chainguard traefik-3.0
traefik-3.0 affected wolfi traefik-3.0
traefik-3.0-fips affected chainguard traefik-3.0-fips
trillian affected chainguard trillian
trillian affected wolfi trillian
trillian-fips affected chainguard trillian-fips
trivy-fips affected chainguard trivy-fips
trust-manager affected wolfi trust-manager
trust-manager affected chainguard trust-manager
trust-manager-fips affected chainguard trust-manager-fips
up affected chainguard up
up affected wolfi up
vault-1.15 affected chainguard vault-1.15
vault-csi-provider affected wolfi vault-csi-provider
vault-csi-provider affected chainguard vault-csi-provider
vault-fips-1.15 affected chainguard vault-fips-1.15
vault-fips-1.16 affected chainguard vault-fips-1.16
vault-fips-1.17 affected chainguard vault-fips-1.17
vault-k8s affected chainguard vault-k8s
vault-k8s affected wolfi vault-k8s
vcluster affected chainguard vcluster
vcluster affected wolfi vcluster
velero affected chainguard velero
velero affected wolfi velero
velero-plugin-for-aws affected chainguard velero-plugin-for-aws
velero-plugin-for-aws affected wolfi velero-plugin-for-aws
velero-plugin-for-aws-fips affected chainguard velero-plugin-for-aws-fips
velero-plugin-for-csi affected wolfi velero-plugin-for-csi
velero-plugin-for-csi affected chainguard velero-plugin-for-csi
velero-plugin-for-csi-fips affected chainguard velero-plugin-for-csi-fips
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vertical-pod-autoscaler-fips affected chainguard vertical-pod-autoscaler-fips
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
volume-modifier-for-k8s affected chainguard volume-modifier-for-k8s
volume-modifier-for-k8s affected wolfi volume-modifier-for-k8s
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
vt-cli affected chainguard vt-cli
vt-cli affected wolfi vt-cli
wait-for-port affected chainguard wait-for-port
wait-for-port affected wolfi wait-for-port
wave affected chainguard wave
wave affected wolfi wave
wave-fips affected chainguard wave-fips
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
wazero affected wolfi wazero
wazero affected chainguard wazero
weaviate affected chainguard weaviate
weaviate affected wolfi weaviate
wgcf affected chainguard wgcf
wgcf affected wolfi wgcf
whereabouts affected wolfi whereabouts
whereabouts affected chainguard whereabouts
whereabouts-fips affected chainguard whereabouts-fips
wire-go affected wolfi wire-go
wire-go affected chainguard wire-go
wireguard-go affected chainguard wireguard-go
wireguard-go affected wolfi wireguard-go
wolfictl affected wolfi wolfictl
wolfictl affected chainguard wolfictl
wuzz affected wolfi wuzz
wuzz affected chainguard wuzz
xcaddy affected chainguard xcaddy
xcaddy affected wolfi xcaddy
yam affected chainguard yam
yam affected wolfi yam
yq affected chainguard yq
yq affected wolfi yq
yq-fips affected chainguard yq-fips
ytt affected chainguard ytt
ytt affected wolfi ytt
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

AZL-43068

Open SourcePoC exploitHIGH2024-07-02

CVE-2024-24791 affecting package golang for versions less than 1.22.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-78960

Open SourcePoC exploitHIGH2024-07-02

CVE-2024-24791 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2024-24791

Open SourcePoC exploitHIGH2024-07-02

DEBIAN-CVE-2024-24791

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GO-2024-2963

Open SourcePoC exploitHIGH2024-07-02

Denial of service due to improper 100-continue handling in net/http

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller affected wolfi actions-runner-controller
actions-runner-controller-fips affected chainguard actions-runner-controller-fips
addon-resizer affected chainguard addon-resizer
addon-resizer affected wolfi addon-resizer
addon-resizer-fips affected chainguard addon-resizer-fips
age affected chainguard age
age affected wolfi age
amass affected wolfi amass
amass affected chainguard amass
argo-workflows affected wolfi argo-workflows
argo-workflows affected chainguard argo-workflows
atlantis affected chainguard atlantis
atlantis affected wolfi atlantis
atlantis-fips affected chainguard atlantis-fips
authservice affected chainguard authservice
authservice affected wolfi authservice
authservice-fips affected chainguard authservice-fips
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
aws-network-policy-agent affected chainguard aws-network-policy-agent
aws-network-policy-agent affected wolfi aws-network-policy-agent
azcopy-fips affected chainguard azcopy-fips
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults affected chainguard bank-vaults
bank-vaults affected wolfi bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bazelisk affected wolfi bazelisk
bazelisk affected chainguard bazelisk
bom affected wolfi bom
bom affected chainguard bom
boring-registry affected wolfi boring-registry
boring-registry affected chainguard boring-registry
boring-registry-fips affected chainguard boring-registry-fips
buf affected chainguard buf
buf affected wolfi buf
buildah affected wolfi buildah
buildah affected chainguard buildah
caddy affected chainguard caddy
caddy affected wolfi caddy
caddy-fips affected chainguard caddy-fips
cadvisor affected wolfi cadvisor
cadvisor affected chainguard cadvisor
cadvisor-fips affected chainguard cadvisor-fips
capslock affected chainguard capslock
capslock affected wolfi capslock
cass-operator affected wolfi cass-operator
cass-operator affected chainguard cass-operator
cass-operator-fips-no-pvc-delete affected chainguard cass-operator-fips-no-pvc-delete
cert-exporter affected wolfi cert-exporter
cert-exporter affected chainguard cert-exporter
cert-exporter-fips affected chainguard cert-exporter-fips
certificate-transparency affected chainguard certificate-transparency
certificate-transparency affected wolfi certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cert-manager-cmctl affected chainguard cert-manager-cmctl
cert-manager-cmctl affected wolfi cert-manager-cmctl
cert-manager-cmctl-fips affected chainguard cert-manager-cmctl-fips
cert-manager-webhook-pdns affected wolfi cert-manager-webhook-pdns
cert-manager-webhook-pdns affected chainguard cert-manager-webhook-pdns
cert-manager-webhook-pdns-fips affected chainguard cert-manager-webhook-pdns-fips
cfssl affected chainguard cfssl
cfssl affected wolfi cfssl
chainctl affected chainguard chainctl
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
chartmuseum-fips affected chainguard chartmuseum-fips
cilium-1.15 affected chainguard cilium-1.15
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
cilium-fips-1.15 affected chainguard cilium-fips-1.15
cloudflared affected wolfi cloudflared
cloudflared affected chainguard cloudflared
cloudnative-pg affected chainguard cloudnative-pg
cloudnative-pg affected wolfi cloudnative-pg
cloudnative-pg-fips affected chainguard cloudnative-pg-fips
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
cluster-proportional-autoscaler affected wolfi cluster-proportional-autoscaler
cluster-proportional-autoscaler affected chainguard cluster-proportional-autoscaler
cni-plugins affected chainguard cni-plugins
cni-plugins affected wolfi cni-plugins
cni-plugins-fips affected chainguard cni-plugins-fips
configmap-reload affected wolfi configmap-reload
configmap-reload affected chainguard configmap-reload
configmap-reload-fips affected chainguard configmap-reload-fips
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
confluent-common-docker affected wolfi confluent-common-docker
confluent-common-docker affected chainguard confluent-common-docker
conftest affected wolfi conftest
conftest affected chainguard conftest
conftest-fips affected chainguard conftest-fips
controller-gen affected wolfi controller-gen
controller-gen affected chainguard controller-gen
cortex affected wolfi cortex
cortex affected chainguard cortex
cortex-fips affected chainguard cortex-fips
cosign affected chainguard cosign
cosign affected wolfi cosign
cosign-fips affected chainguard cosign-fips
crane affected wolfi crane
crane affected chainguard crane
cri-tools affected wolfi cri-tools
cri-tools affected chainguard cri-tools
croc affected wolfi croc
croc affected chainguard croc
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure affected wolfi crossplane-provider-azure
ctop affected chainguard ctop
ctop affected wolfi ctop
cue affected chainguard cue
cue affected wolfi cue
cue-fips affected chainguard cue-fips
dagdotdev affected wolfi dagdotdev
dagdotdev affected chainguard dagdotdev
dagger affected chainguard dagger
dagger affected wolfi dagger
dask-gateway affected wolfi dask-gateway
dask-gateway affected chainguard dask-gateway
dataplaneapi affected chainguard dataplaneapi
dataplaneapi affected wolfi dataplaneapi
dataplaneapi-fips affected chainguard dataplaneapi-fips
dbmate affected chainguard dbmate
dbmate affected wolfi dbmate
delve affected wolfi delve
delve affected chainguard delve
dex affected wolfi dex
dex affected chainguard dex
dex-fips affected chainguard dex-fips
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
direnv affected wolfi direnv
direnv affected chainguard direnv
dive affected wolfi dive
dive affected chainguard dive
docker-compose affected chainguard docker-compose
docker-compose affected wolfi docker-compose
docker-credential-acr-env affected wolfi docker-credential-acr-env
docker-credential-acr-env affected chainguard docker-credential-acr-env
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-gcr affected chainguard docker-credential-gcr
docker-credential-gcr affected wolfi docker-credential-gcr
dockerize affected wolfi dockerize
dockerize affected chainguard dockerize
dockerize-fips affected chainguard dockerize-fips
doppler-kubernetes-operator affected chainguard doppler-kubernetes-operator
doppler-kubernetes-operator affected wolfi doppler-kubernetes-operator
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
eksctl affected wolfi eksctl
eksctl affected chainguard eksctl
envoy-ratelimit affected wolfi envoy-ratelimit
envoy-ratelimit affected chainguard envoy-ratelimit
envoy-ratelimit-fips affected chainguard envoy-ratelimit-fips
esbuild affected wolfi esbuild
esbuild affected chainguard esbuild
esbuild-fips affected chainguard esbuild-fips
etcd-3.4 affected chainguard etcd-3.4
etcd-3.5 affected chainguard etcd-3.5
etcd-fips-3.4 affected chainguard etcd-fips-3.4
etcd-fips-3.5 affected chainguard etcd-fips-3.5
external-secrets-fips affected chainguard external-secrets-fips
extism affected wolfi extism
extism affected chainguard extism
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
falcosidekick affected wolfi falcosidekick
falcosidekick affected chainguard falcosidekick
falcosidekick-fips affected chainguard falcosidekick-fips
ferretdb affected wolfi ferretdb
ferretdb affected chainguard ferretdb
flannel affected wolfi flannel
flannel affected chainguard flannel
flannel-cni-plugin affected chainguard flannel-cni-plugin
flannel-cni-plugin affected wolfi flannel-cni-plugin
fluent-bit-plugin-loki affected wolfi fluent-bit-plugin-loki
fluent-bit-plugin-loki affected chainguard fluent-bit-plugin-loki
fluent-operator affected chainguard fluent-operator
fluent-operator affected wolfi fluent-operator
fluent-operator-fips affected chainguard fluent-operator-fips
flux affected chainguard flux
flux affected wolfi flux
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
flyte affected wolfi flyte
flyte affected chainguard flyte
fulcio affected chainguard fulcio
fulcio affected wolfi fulcio
fulcio-fips affected chainguard fulcio-fips
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
fzf affected chainguard fzf
fzf affected wolfi fzf
gcsfuse affected wolfi gcsfuse
gcsfuse affected chainguard gcsfuse
gh affected chainguard gh
gh affected wolfi gh
ghaudit affected wolfi ghaudit
ghaudit affected chainguard ghaudit
gitleaks affected wolfi gitleaks
gitleaks affected chainguard gitleaks
git-lfs affected chainguard git-lfs
git-lfs affected wolfi git-lfs
git-lfs-fips affected chainguard git-lfs-fips
gitness affected chainguard gitness
gitness affected wolfi gitness
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
glab affected chainguard glab
glab affected wolfi glab
go-1.20 affected chainguard go-1.20
go-1.20 affected wolfi go-1.20
go-1.21 affected wolfi go-1.21
go-1.21 affected chainguard go-1.21
go-1.22 affected chainguard go-1.22
go-1.22 affected wolfi go-1.22
go-bindata affected chainguard go-bindata
go-bindata affected wolfi go-bindata
gobump affected chainguard gobump
gobump affected wolfi gobump
gobuster affected wolfi gobuster
gobuster affected chainguard gobuster
golangci-lint affected wolfi golangci-lint
golangci-lint affected chainguard golangci-lint
go-licenses affected wolfi go-licenses
go-licenses affected chainguard go-licenses
go-md2man affected chainguard go-md2man
go-md2man affected wolfi go-md2man
gomplate affected wolfi gomplate
gomplate affected chainguard gomplate
gomplate-fips affected chainguard gomplate-fips
gops affected wolfi gops
gops affected chainguard gops
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
gostatsd affected chainguard gostatsd
gostatsd affected wolfi gostatsd
gosu affected wolfi gosu
gosu affected chainguard gosu
gosu-1.11 affected chainguard gosu-1.11
gosu-fips affected chainguard gosu-fips
gotenberg affected chainguard gotenberg
govulncheck affected wolfi govulncheck
govulncheck affected chainguard govulncheck
grafana-agent-operator affected chainguard grafana-agent-operator
grafana-agent-operator affected wolfi grafana-agent-operator
grafana-mimir affected wolfi grafana-mimir
grafana-mimir affected chainguard grafana-mimir
grafana-operator-fips affected chainguard grafana-operator-fips
grpc-health-probe-fips affected chainguard grpc-health-probe-fips
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
grype affected wolfi grype
grype affected chainguard grype
guac affected chainguard guac
guac affected wolfi guac
haproxy-ingress affected wolfi haproxy-ingress
haproxy-ingress affected chainguard haproxy-ingress
harbor-2.11 affected chainguard harbor-2.11
harbor-cli affected wolfi harbor-cli
harbor-cli affected chainguard harbor-cli
harbor-fips-2.11 affected chainguard harbor-fips-2.11
harbor-registry affected wolfi harbor-registry
harbor-registry affected chainguard harbor-registry
harbor-registry-fips affected chainguard harbor-registry-fips
harbor-scanner-trivy affected chainguard harbor-scanner-trivy
harbor-scanner-trivy affected wolfi harbor-scanner-trivy
harbor-scanner-trivy-fips affected chainguard harbor-scanner-trivy-fips
hello-world-golang affected wolfi hello-world-golang
hello-world-golang affected chainguard hello-world-golang
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
helm-docs affected wolfi helm-docs
helm-docs affected chainguard helm-docs
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected chainguard helm-operator
helm-operator affected wolfi helm-operator
helm-operator-fips affected chainguard helm-operator-fips
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
hey affected wolfi hey
hey affected chainguard hey
hivemind affected chainguard hivemind
hivemind affected wolfi hivemind
http-echo affected wolfi http-echo
http-echo affected chainguard http-echo
hubble affected wolfi hubble
hubble affected chainguard hubble
hubble-fips affected chainguard hubble-fips
hubble-ui affected chainguard hubble-ui
hubble-ui affected wolfi hubble-ui
hubble-ui-backend-fips affected chainguard hubble-ui-backend-fips
hugo affected wolfi hugo
hugo affected chainguard hugo
hugo-extended affected wolfi hugo-extended
hugo-extended affected chainguard hugo-extended
influx affected chainguard influx
influx affected wolfi influx
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
istio-pilot-agent-1.22 affected chainguard istio-pilot-agent-1.22
istio-pilot-discovery-1.22 affected chainguard istio-pilot-discovery-1.22
jitsucom-bulker affected chainguard jitsucom-bulker
jitsucom-bulker affected wolfi jitsucom-bulker
jsonnet-bundler affected chainguard jsonnet-bundler
k3d affected wolfi k3d
k3d affected chainguard k3d
k3s affected wolfi k3s
k3s affected chainguard k3s
k8s-device-plugin affected wolfi k8s-device-plugin
k8s-device-plugin affected chainguard k8s-device-plugin
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
k8sgpt-operator affected chainguard k8sgpt-operator
k8sgpt-operator affected wolfi k8sgpt-operator
k8ssandra-operator affected chainguard k8ssandra-operator
k8ssandra-operator affected wolfi k8ssandra-operator
k8ssandra-operator-fips affected chainguard k8ssandra-operator-fips
k9s affected chainguard k9s
k9s affected wolfi k9s
kaf affected wolfi kaf
kaf affected chainguard kaf
kafka_exporter affected wolfi kafka_exporter
kafka_exporter affected chainguard kafka_exporter
kafka-proxy affected wolfi kafka-proxy
kafka-proxy affected chainguard kafka-proxy
kaniko affected wolfi kaniko
kaniko affected chainguard kaniko
kargo affected wolfi kargo
kargo affected chainguard kargo
karpenter-0.35 affected chainguard karpenter-0.35
karpenter-fips-0.35 affected chainguard karpenter-fips-0.35
karpenter-fips-0.36 affected chainguard karpenter-fips-0.36
kiam affected chainguard kiam
kind affected chainguard kind
kind affected wolfi kind
kine affected chainguard kine
kine affected wolfi kine
ko affected chainguard ko
ko affected wolfi ko
ko-fips affected chainguard ko-fips
kor affected chainguard kor
kor affected wolfi kor
kots affected wolfi kots
kots affected chainguard kots
kpt affected chainguard kpt
kpt affected wolfi kpt
kube-bench affected wolfi kube-bench
kube-bench affected chainguard kube-bench
kubebuilder affected wolfi kubebuilder
kubebuilder affected chainguard kubebuilder
kubecolor affected wolfi kubecolor
kubecolor affected chainguard kubecolor
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kube-logging-operator affected chainguard kube-logging-operator
kube-logging-operator affected wolfi kube-logging-operator
kube-oidc-proxy affected chainguard kube-oidc-proxy
kuberay-operator affected chainguard kuberay-operator
kuberay-operator affected wolfi kuberay-operator
kube-rbac-proxy affected chainguard kube-rbac-proxy
kube-rbac-proxy affected wolfi kube-rbac-proxy
kube-rbac-proxy-fips affected chainguard kube-rbac-proxy-fips
kubernetes-1.30 affected chainguard kubernetes-1.30
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard-fips affected chainguard kubernetes-dashboard-fips
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper-fips affected chainguard kubernetes-dashboard-metrics-scraper-fips
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache-fips affected chainguard kubernetes-dns-node-cache-fips
kubernetes-event-exporter affected chainguard kubernetes-event-exporter
kubernetes-event-exporter affected wolfi kubernetes-event-exporter
kubernetes-ingress-defaultbackend affected wolfi kubernetes-ingress-defaultbackend
kubernetes-ingress-defaultbackend affected chainguard kubernetes-ingress-defaultbackend
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
kube-vip affected wolfi kube-vip
kube-vip affected chainguard kube-vip
kube-vip-fips affected chainguard kube-vip-fips
kubewatch affected chainguard kubewatch
kubewatch affected wolfi kubewatch
kustomize affected chainguard kustomize
kustomize affected wolfi kustomize
kustomize-fips affected chainguard kustomize-fips
kwok affected wolfi kwok
kwok affected chainguard kwok
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
kyverno-policy-reporter-kyverno-plugin affected wolfi kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-kyverno-plugin affected chainguard kyverno-policy-reporter-kyverno-plugin
kyverno-policy-reporter-ui affected wolfi kyverno-policy-reporter-ui
kyverno-policy-reporter-ui affected chainguard kyverno-policy-reporter-ui
lazygit affected chainguard lazygit
lazygit affected wolfi lazygit
libnvidia-container affected chainguard libnvidia-container
libnvidia-container affected wolfi libnvidia-container
litefs affected chainguard litefs
litefs affected wolfi litefs
litestream affected chainguard litestream
litestream affected wolfi litestream
local-path-provisioner affected wolfi local-path-provisioner
local-path-provisioner affected chainguard local-path-provisioner
local-static-provisioner affected chainguard local-static-provisioner
local-static-provisioner affected wolfi local-static-provisioner
logstash-exporter affected wolfi logstash-exporter
logstash-exporter affected chainguard logstash-exporter
logstash-exporter-fips affected chainguard logstash-exporter-fips
mage affected wolfi mage
mage affected chainguard mage
mc affected chainguard mc
mc affected wolfi mc
mc-fips affected chainguard mc-fips
memcached-exporter affected wolfi memcached-exporter
memcached-exporter affected chainguard memcached-exporter
metacontroller affected chainguard metacontroller
metacontroller affected wolfi metacontroller
metallb affected chainguard metallb
metallb affected wolfi metallb
metrics-server affected chainguard metrics-server
metrics-server affected wolfi metrics-server
metrics-server-fips affected chainguard metrics-server-fips
minify affected chainguard minify
minify affected wolfi minify
minify-fips affected chainguard minify-fips
minio affected chainguard minio
minio affected wolfi minio
mkcert affected chainguard mkcert
mkcert affected wolfi mkcert
mockery affected chainguard mockery
mockery affected wolfi mockery
mods affected chainguard mods
mods affected wolfi mods
mongo-tools affected wolfi mongo-tools
mongo-tools affected chainguard mongo-tools
multus-cni affected wolfi multus-cni
multus-cni affected chainguard multus-cni
multus-cni-fips affected chainguard multus-cni-fips
nats affected chainguard nats
nats affected wolfi nats
nats-server affected wolfi nats-server
nats-server affected chainguard nats-server
nerdctl affected chainguard nerdctl
nerdctl affected wolfi nerdctl
neuvector affected chainguard neuvector
neuvector-scanner affected wolfi neuvector-scanner
neuvector-scanner affected chainguard neuvector-scanner
neuvector-scanner-fips affected chainguard neuvector-scanner-fips
neuvector-sigstore-interface affected wolfi neuvector-sigstore-interface
neuvector-sigstore-interface affected chainguard neuvector-sigstore-interface
neuvector-sigstore-interface-fips affected chainguard neuvector-sigstore-interface-fips
newrelic-fluent-bit-output affected chainguard newrelic-fluent-bit-output
newrelic-fluent-bit-output affected wolfi newrelic-fluent-bit-output
newrelic-infra-operator affected chainguard newrelic-infra-operator
newrelic-infra-operator affected wolfi newrelic-infra-operator
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-nri-kube-events affected chainguard newrelic-nri-kube-events
newrelic-nri-kube-events affected wolfi newrelic-nri-kube-events
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
newrelic-prometheus-configurator affected wolfi newrelic-prometheus-configurator
newrelic-prometheus-configurator affected chainguard newrelic-prometheus-configurator
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nri-apache affected wolfi nri-apache
nri-apache affected chainguard nri-apache
nri-cassandra affected chainguard nri-cassandra
nri-cassandra affected wolfi nri-cassandra
nri-consul affected chainguard nri-consul
nri-consul affected wolfi nri-consul
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-elasticsearch affected wolfi nri-elasticsearch
nri-elasticsearch affected chainguard nri-elasticsearch
nri-f5 affected wolfi nri-f5
nri-f5 affected chainguard nri-f5
nri-haproxy affected wolfi nri-haproxy
nri-haproxy affected chainguard nri-haproxy
nri-jmx affected chainguard nri-jmx
nri-jmx affected wolfi nri-jmx
nri-kafka affected wolfi nri-kafka
nri-kafka affected chainguard nri-kafka
nri-kubernetes affected chainguard nri-kubernetes
nri-kubernetes affected wolfi nri-kubernetes
nri-memcached affected chainguard nri-memcached
nri-memcached affected wolfi nri-memcached
nri-mongodb affected chainguard nri-mongodb
nri-mongodb affected wolfi nri-mongodb
nri-mssql affected chainguard nri-mssql
nri-mssql affected wolfi nri-mssql
nri-mysql affected chainguard nri-mysql
nri-mysql affected wolfi nri-mysql
nri-nagios affected chainguard nri-nagios
nri-nagios affected wolfi nri-nagios
nri-nginx affected chainguard nri-nginx
nri-nginx affected wolfi nri-nginx
nri-postgresql affected chainguard nri-postgresql
nri-postgresql affected wolfi nri-postgresql
nri-prometheus affected wolfi nri-prometheus
nri-prometheus affected chainguard nri-prometheus
nri-redis affected wolfi nri-redis
nri-redis affected chainguard nri-redis
nsc affected chainguard nsc
nsc affected wolfi nsc
nuclei affected wolfi nuclei
nuclei affected chainguard nuclei
nvidia-container-toolkit affected wolfi nvidia-container-toolkit
nvidia-container-toolkit affected chainguard nvidia-container-toolkit
nvidia-nsight-compute-12.8 affected chainguard nvidia-nsight-compute-12.8
oauth2-proxy affected chainguard oauth2-proxy
oauth2-proxy affected wolfi oauth2-proxy
octo-sts affected wolfi octo-sts
octo-sts affected chainguard octo-sts
ollama affected chainguard ollama
ollama affected wolfi ollama
opa affected chainguard opa
opa affected wolfi opa
opa-fips affected chainguard opa-fips
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
oras affected chainguard oras
oras affected wolfi oras
osv-scanner affected chainguard osv-scanner
osv-scanner affected wolfi osv-scanner
overmind affected wolfi overmind
overmind affected chainguard overmind
paranoia affected chainguard paranoia
paranoia affected wolfi paranoia
petname affected wolfi petname
petname affected chainguard petname
php-fpm_exporter affected chainguard php-fpm_exporter
php-fpm_exporter affected wolfi php-fpm_exporter
pluto affected wolfi pluto
pluto affected chainguard pluto
policy-controller affected chainguard policy-controller
policy-controller affected wolfi policy-controller
policy-controller-fips affected chainguard policy-controller-fips
pombump affected wolfi pombump
pombump affected chainguard pombump
postgres-operator affected chainguard postgres-operator
postgres-operator affected wolfi postgres-operator
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-2.53 affected chainguard prometheus-2.53
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-alertmanager-fips affected chainguard prometheus-alertmanager-fips
prometheus-beat-exporter affected chainguard prometheus-beat-exporter
prometheus-beat-exporter-fips affected chainguard prometheus-beat-exporter-fips
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-blackbox-exporter-fips affected chainguard prometheus-blackbox-exporter-fips
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter-fips affected chainguard prometheus-elasticsearch-exporter-fips
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter-0.37 affected chainguard prometheus-mongodb-exporter-0.37
prometheus-mongodb-exporter-fips affected chainguard prometheus-mongodb-exporter-fips
prometheus-mongodb-exporter-fips-0.37 affected chainguard prometheus-mongodb-exporter-fips-0.37
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter-1.4 affected chainguard prometheus-node-exporter-1.4
prometheus-node-exporter-1.5 affected chainguard prometheus-node-exporter-1.5
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-postgres-exporter-fips affected chainguard prometheus-postgres-exporter-fips
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway-1.4 affected chainguard prometheus-pushgateway-1.4
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
prometheus-pushgateway-fips-1.4 affected chainguard prometheus-pushgateway-fips-1.4
prometheus-redis-exporter affected chainguard prometheus-redis-exporter
prometheus-redis-exporter-fips affected chainguard prometheus-redis-exporter-fips
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter-fips affected chainguard prometheus-statsd-exporter-fips
prometheus-statsd-exporter-fips-0.22 affected chainguard prometheus-statsd-exporter-fips-0.22
protoc-gen-go affected wolfi protoc-gen-go
protoc-gen-go affected chainguard protoc-gen-go
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
pulumi affected chainguard pulumi
pulumi affected wolfi pulumi
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-yaml affected wolfi pulumi-language-yaml
pulumi-language-yaml affected chainguard pulumi-language-yaml
q affected wolfi q
q affected chainguard q
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-default-user-credential-updater affected chainguard rabbitmq-default-user-credential-updater
rabbitmq-default-user-credential-updater affected wolfi rabbitmq-default-user-credential-updater
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rclone affected chainguard rclone
rclone affected wolfi rclone
redka affected wolfi redka
redka affected chainguard redka
regclient affected wolfi regclient
regclient affected chainguard regclient
rekor affected wolfi rekor
rekor affected chainguard rekor
rekor-fips affected chainguard rekor-fips
render-template affected wolfi render-template
render-template affected chainguard render-template
request-1279 affected chainguard request-1279
request-1279-1-14 affected chainguard request-1279-1-14
restic affected chainguard restic
restic affected wolfi restic
restic-fips affected chainguard restic-fips
rootlesskit affected wolfi rootlesskit
rootlesskit affected chainguard rootlesskit
runc affected wolfi runc
runc affected chainguard runc
s5cmd affected chainguard s5cmd
s5cmd affected wolfi s5cmd
sbom-convert affected wolfi sbom-convert
sbom-convert affected chainguard sbom-convert
sbom-scorecard affected wolfi sbom-scorecard
sbom-scorecard affected chainguard sbom-scorecard
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
shfmt affected wolfi shfmt
shfmt affected chainguard shfmt
sigstore-scaffolding-fips affected chainguard sigstore-scaffolding-fips
skaffold affected wolfi skaffold
skaffold affected chainguard skaffold
skopeo affected wolfi skopeo
skopeo affected chainguard skopeo
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
snyk-cli affected chainguard snyk-cli
snyk-cli affected wolfi snyk-cli
sonobuoy affected wolfi sonobuoy
sonobuoy affected chainguard sonobuoy
speedtest-go affected chainguard speedtest-go
speedtest-go affected wolfi speedtest-go
spegel affected chainguard spegel
spegel affected wolfi spegel
spicedb affected wolfi spicedb
spicedb affected chainguard spicedb
spqr affected chainguard spqr
spqr affected wolfi spqr
src affected wolfi src
src affected chainguard src
src-fingerprint affected wolfi src-fingerprint
src-fingerprint affected chainguard src-fingerprint
src-fingerprint-fips affected chainguard src-fingerprint-fips
stakater-reloader affected chainguard stakater-reloader
stakater-reloader affected wolfi stakater-reloader
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
stdlib affected Go stdlib
step affected wolfi step
step affected chainguard step
step-ca affected chainguard step-ca
step-ca affected wolfi step-ca
step-ca-fips affected chainguard step-ca-fips
step-fips affected chainguard step-fips
step-issuer affected wolfi step-issuer
step-issuer affected chainguard step-issuer
step-issuer-fips affected chainguard step-issuer-fips
stern affected chainguard stern
stern affected wolfi stern
supercronic affected chainguard supercronic
supercronic affected wolfi supercronic
swagger affected wolfi swagger
swagger affected chainguard swagger
syft affected chainguard syft
syft affected wolfi syft
tailscale affected wolfi tailscale
tailscale affected chainguard tailscale
task affected chainguard task
task affected wolfi task
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
tempo affected chainguard tempo
tempo affected wolfi tempo
temporal affected wolfi temporal
temporal affected chainguard temporal
temporal-ui-server affected wolfi temporal-ui-server
temporal-ui-server affected chainguard temporal-ui-server
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-docs affected wolfi terraform-docs
terraform-docs affected chainguard terraform-docs
terraform-provider-aws affected chainguard terraform-provider-aws
terraform-provider-aws affected wolfi terraform-provider-aws
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terraform-provider-google affected wolfi terraform-provider-google
terraform-provider-google affected chainguard terraform-provider-google
terragrunt affected wolfi terragrunt
terragrunt affected chainguard terragrunt
tflint affected wolfi tflint
tflint affected chainguard tflint
thanos affected wolfi thanos
thanos affected chainguard thanos
thanos-fips affected chainguard thanos-fips
thanos-operator affected wolfi thanos-operator
thanos-operator affected chainguard thanos-operator
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
tigera-operator-1.34 affected chainguard tigera-operator-1.34
tigera-operator-fips-1.29 affected chainguard tigera-operator-fips-1.29
tigera-operator-fips-1.34 affected chainguard tigera-operator-fips-1.34
timestamp-authority affected chainguard timestamp-authority
timestamp-authority affected wolfi timestamp-authority
timestamp-authority-fips affected chainguard timestamp-authority-fips
timoni affected wolfi timoni
timoni affected chainguard timoni
tkn affected chainguard tkn
tkn affected wolfi tkn
tkn-fips affected chainguard tkn-fips
trillian affected chainguard trillian
trillian affected wolfi trillian
trillian-fips affected chainguard trillian-fips
trivy-fips affected chainguard trivy-fips
trust-manager affected chainguard trust-manager
trust-manager affected wolfi trust-manager
trust-manager-fips affected chainguard trust-manager-fips
up affected wolfi up
up affected chainguard up
vault-csi-provider affected chainguard vault-csi-provider
vault-k8s affected wolfi vault-k8s
vault-k8s affected chainguard vault-k8s
vcluster affected wolfi vcluster
vcluster affected chainguard vcluster
velero affected chainguard velero
velero affected wolfi velero
velero-plugin-for-aws affected chainguard velero-plugin-for-aws
velero-plugin-for-aws affected wolfi velero-plugin-for-aws
velero-plugin-for-aws-fips affected chainguard velero-plugin-for-aws-fips
velero-plugin-for-csi affected chainguard velero-plugin-for-csi
velero-plugin-for-csi affected wolfi velero-plugin-for-csi
velero-plugin-for-csi-fips affected chainguard velero-plugin-for-csi-fips
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vertical-pod-autoscaler-fips affected chainguard vertical-pod-autoscaler-fips
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
volume-modifier-for-k8s affected wolfi volume-modifier-for-k8s
volume-modifier-for-k8s affected chainguard volume-modifier-for-k8s
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
vt-cli affected wolfi vt-cli
vt-cli affected chainguard vt-cli
wait-for-port affected wolfi wait-for-port
wait-for-port affected chainguard wait-for-port
wave affected wolfi wave
wave affected chainguard wave
wave-fips affected chainguard wave-fips
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
wazero affected chainguard wazero
wazero affected wolfi wazero
weaviate affected chainguard weaviate
weaviate affected wolfi weaviate
wgcf affected chainguard wgcf
wgcf affected wolfi wgcf
whereabouts affected chainguard whereabouts
whereabouts affected wolfi whereabouts
whereabouts-fips affected chainguard whereabouts-fips
wire-go affected wolfi wire-go
wire-go affected chainguard wire-go
wireguard-go affected chainguard wireguard-go
wireguard-go affected wolfi wireguard-go
wolfictl affected chainguard wolfictl
wolfictl affected wolfi wolfictl
wuzz affected chainguard wuzz
wuzz affected wolfi wuzz
xcaddy affected wolfi xcaddy
xcaddy affected chainguard xcaddy
yam affected wolfi yam
yam affected chainguard yam
yq affected wolfi yq
yq affected chainguard yq
yq-fips affected chainguard yq-fips
ytt affected wolfi ytt
ytt affected chainguard ytt
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

AZL-43207

Open SourcePoC exploitHIGH2024-07-07

CVE-2024-3651 affecting package tensorflow for versions less than 2.16.1-7

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

RHSA-2024:4159

Open SourcePoC exploitHIGH2024-07-03

Red Hat Security Advisory: OpenShift Container Platform 4.16.1 packages and security update

Affected products

ProductStatusVendorPackageEcosystem
bpftool affected Red Hat:openshift:4.16::el9 bpftool
bpftool-debuginfo affected Red Hat:openshift:4.16::el9 bpftool-debuginfo
cri-o affected Red Hat:openshift:4.16::el8 cri-o
cri-o affected Red Hat:openshift:4.16::el9 cri-o
cri-o-debuginfo affected Red Hat:openshift:4.16::el8 cri-o-debuginfo
cri-o-debuginfo affected Red Hat:openshift:4.16::el9 cri-o-debuginfo
cri-o-debugsource affected Red Hat:openshift:4.16::el9 cri-o-debugsource
cri-o-debugsource affected Red Hat:openshift:4.16::el8 cri-o-debugsource
kernel affected Red Hat:openshift:4.16::el9 kernel
kernel-64k affected Red Hat:openshift:4.16::el9 kernel-64k
kernel-64k-core affected Red Hat:openshift:4.16::el9 kernel-64k-core
kernel-64k-debug affected Red Hat:openshift:4.16::el9 kernel-64k-debug
kernel-64k-debug-core affected Red Hat:openshift:4.16::el9 kernel-64k-debug-core
kernel-64k-debug-debuginfo affected Red Hat:openshift:4.16::el9 kernel-64k-debug-debuginfo
kernel-64k-debug-devel affected Red Hat:openshift:4.16::el9 kernel-64k-debug-devel
kernel-64k-debug-devel-matched affected Red Hat:openshift:4.16::el9 kernel-64k-debug-devel-matched
kernel-64k-debuginfo affected Red Hat:openshift:4.16::el9 kernel-64k-debuginfo
kernel-64k-debug-modules affected Red Hat:openshift:4.16::el9 kernel-64k-debug-modules
kernel-64k-debug-modules-core affected Red Hat:openshift:4.16::el9 kernel-64k-debug-modules-core
kernel-64k-debug-modules-extra affected Red Hat:openshift:4.16::el9 kernel-64k-debug-modules-extra
kernel-64k-debug-modules-internal affected Red Hat:openshift:4.16::el9 kernel-64k-debug-modules-internal
kernel-64k-debug-modules-partner affected Red Hat:openshift:4.16::el9 kernel-64k-debug-modules-partner
kernel-64k-devel affected Red Hat:openshift:4.16::el9 kernel-64k-devel
kernel-64k-devel-matched affected Red Hat:openshift:4.16::el9 kernel-64k-devel-matched
kernel-64k-modules affected Red Hat:openshift:4.16::el9 kernel-64k-modules
kernel-64k-modules-core affected Red Hat:openshift:4.16::el9 kernel-64k-modules-core
kernel-64k-modules-extra affected Red Hat:openshift:4.16::el9 kernel-64k-modules-extra
kernel-64k-modules-internal affected Red Hat:openshift:4.16::el9 kernel-64k-modules-internal
kernel-64k-modules-partner affected Red Hat:openshift:4.16::el9 kernel-64k-modules-partner
kernel-abi-stablelists affected Red Hat:openshift:4.16::el9 kernel-abi-stablelists
kernel-core affected Red Hat:openshift:4.16::el9 kernel-core
kernel-debug affected Red Hat:openshift:4.16::el9 kernel-debug
kernel-debug-core affected Red Hat:openshift:4.16::el9 kernel-debug-core
kernel-debug-debuginfo affected Red Hat:openshift:4.16::el9 kernel-debug-debuginfo
kernel-debug-devel affected Red Hat:openshift:4.16::el9 kernel-debug-devel
kernel-debug-devel-matched affected Red Hat:openshift:4.16::el9 kernel-debug-devel-matched
kernel-debuginfo affected Red Hat:openshift:4.16::el9 kernel-debuginfo
kernel-debuginfo-common-aarch64 affected Red Hat:openshift:4.16::el9 kernel-debuginfo-common-aarch64
kernel-debuginfo-common-ppc64le affected Red Hat:openshift:4.16::el9 kernel-debuginfo-common-ppc64le
kernel-debuginfo-common-s390x affected Red Hat:openshift:4.16::el9 kernel-debuginfo-common-s390x
kernel-debuginfo-common-x86_64 affected Red Hat:openshift:4.16::el9 kernel-debuginfo-common-x86_64
kernel-debug-modules affected Red Hat:openshift:4.16::el9 kernel-debug-modules
kernel-debug-modules-core affected Red Hat:openshift:4.16::el9 kernel-debug-modules-core
kernel-debug-modules-extra affected Red Hat:openshift:4.16::el9 kernel-debug-modules-extra
kernel-debug-modules-internal affected Red Hat:openshift:4.16::el9 kernel-debug-modules-internal
kernel-debug-modules-partner affected Red Hat:openshift:4.16::el9 kernel-debug-modules-partner
kernel-debug-uki-virt affected Red Hat:openshift:4.16::el9 kernel-debug-uki-virt
kernel-devel affected Red Hat:openshift:4.16::el9 kernel-devel
kernel-devel-matched affected Red Hat:openshift:4.16::el9 kernel-devel-matched
kernel-doc affected Red Hat:openshift:4.16::el9 kernel-doc
kernel-ipaclones-internal affected Red Hat:openshift:4.16::el9 kernel-ipaclones-internal
kernel-modules affected Red Hat:openshift:4.16::el9 kernel-modules
kernel-modules-core affected Red Hat:openshift:4.16::el9 kernel-modules-core
kernel-modules-extra affected Red Hat:openshift:4.16::el9 kernel-modules-extra
kernel-modules-internal affected Red Hat:openshift:4.16::el9 kernel-modules-internal
kernel-modules-partner affected Red Hat:openshift:4.16::el9 kernel-modules-partner
kernel-rt affected Red Hat:openshift:4.16::el9 kernel-rt
kernel-rt-core affected Red Hat:openshift:4.16::el9 kernel-rt-core
kernel-rt-debug affected Red Hat:openshift:4.16::el9 kernel-rt-debug
kernel-rt-debug-core affected Red Hat:openshift:4.16::el9 kernel-rt-debug-core
kernel-rt-debug-debuginfo affected Red Hat:openshift:4.16::el9 kernel-rt-debug-debuginfo
kernel-rt-debug-devel affected Red Hat:openshift:4.16::el9 kernel-rt-debug-devel
kernel-rt-debug-devel-matched affected Red Hat:openshift:4.16::el9 kernel-rt-debug-devel-matched
kernel-rt-debuginfo affected Red Hat:openshift:4.16::el9 kernel-rt-debuginfo
kernel-rt-debug-kvm affected Red Hat:openshift:4.16::el9 kernel-rt-debug-kvm
kernel-rt-debug-modules affected Red Hat:openshift:4.16::el9 kernel-rt-debug-modules
kernel-rt-debug-modules-core affected Red Hat:openshift:4.16::el9 kernel-rt-debug-modules-core
kernel-rt-debug-modules-extra affected Red Hat:openshift:4.16::el9 kernel-rt-debug-modules-extra
kernel-rt-debug-modules-internal affected Red Hat:openshift:4.16::el9 kernel-rt-debug-modules-internal
kernel-rt-debug-modules-partner affected Red Hat:openshift:4.16::el9 kernel-rt-debug-modules-partner
kernel-rt-devel affected Red Hat:openshift:4.16::el9 kernel-rt-devel
kernel-rt-devel-matched affected Red Hat:openshift:4.16::el9 kernel-rt-devel-matched
kernel-rt-kvm affected Red Hat:openshift:4.16::el9 kernel-rt-kvm
kernel-rt-modules affected Red Hat:openshift:4.16::el9 kernel-rt-modules
kernel-rt-modules-core affected Red Hat:openshift:4.16::el9 kernel-rt-modules-core
kernel-rt-modules-extra affected Red Hat:openshift:4.16::el9 kernel-rt-modules-extra
kernel-rt-modules-internal affected Red Hat:openshift:4.16::el9 kernel-rt-modules-internal
kernel-rt-modules-partner affected Red Hat:openshift:4.16::el9 kernel-rt-modules-partner
kernel-selftests-internal affected Red Hat:openshift:4.16::el9 kernel-selftests-internal
kernel-tools affected Red Hat:openshift:4.16::el9 kernel-tools
kernel-tools-debuginfo affected Red Hat:openshift:4.16::el9 kernel-tools-debuginfo
kernel-tools-libs affected Red Hat:openshift:4.16::el9 kernel-tools-libs
kernel-tools-libs-devel affected Red Hat:openshift:4.16::el9 kernel-tools-libs-devel
kernel-uki-virt affected Red Hat:openshift:4.16::el9 kernel-uki-virt
kernel-zfcpdump affected Red Hat:openshift:4.16::el9 kernel-zfcpdump
kernel-zfcpdump-core affected Red Hat:openshift:4.16::el9 kernel-zfcpdump-core
kernel-zfcpdump-debuginfo affected Red Hat:openshift:4.16::el9 kernel-zfcpdump-debuginfo
kernel-zfcpdump-devel affected Red Hat:openshift:4.16::el9 kernel-zfcpdump-devel
kernel-zfcpdump-devel-matched affected Red Hat:openshift:4.16::el9 kernel-zfcpdump-devel-matched
kernel-zfcpdump-modules affected Red Hat:openshift:4.16::el9 kernel-zfcpdump-modules
kernel-zfcpdump-modules-core affected Red Hat:openshift:4.16::el9 kernel-zfcpdump-modules-core
kernel-zfcpdump-modules-extra affected Red Hat:openshift:4.16::el9 kernel-zfcpdump-modules-extra
kernel-zfcpdump-modules-internal affected Red Hat:openshift:4.16::el9 kernel-zfcpdump-modules-internal
kernel-zfcpdump-modules-partner affected Red Hat:openshift:4.16::el9 kernel-zfcpdump-modules-partner
libperf-debuginfo affected Red Hat:openshift:4.16::el9 libperf-debuginfo
openshift affected Red Hat:openshift:4.16::el8 openshift
openshift affected Red Hat:openshift:4.16::el9 openshift
openshift-hyperkube affected Red Hat:openshift:4.16::el8 openshift-hyperkube
openshift-hyperkube affected Red Hat:openshift:4.16::el9 openshift-hyperkube
openshift-kube-apiserver affected Red Hat:openshift:4.16::el9 openshift-kube-apiserver
openshift-kube-apiserver affected Red Hat:openshift:4.16::el8 openshift-kube-apiserver
openshift-kube-controller-manager affected Red Hat:openshift:4.16::el8 openshift-kube-controller-manager
openshift-kube-controller-manager affected Red Hat:openshift:4.16::el9 openshift-kube-controller-manager
openshift-kubelet affected Red Hat:openshift:4.16::el8 openshift-kubelet
openshift-kubelet affected Red Hat:openshift:4.16::el9 openshift-kubelet
openshift-kube-scheduler affected Red Hat:openshift:4.16::el9 openshift-kube-scheduler
openshift-kube-scheduler affected Red Hat:openshift:4.16::el8 openshift-kube-scheduler
perf affected Red Hat:openshift:4.16::el9 perf
perf-debuginfo affected Red Hat:openshift:4.16::el9 perf-debuginfo
python3-perf affected Red Hat:openshift:4.16::el9 python3-perf
python3-perf-debuginfo affected Red Hat:openshift:4.16::el9 python3-perf-debuginfo
rtla affected Red Hat:openshift:4.16::el9 rtla
Upstream advisory

RHEA-2024:4866

GooglePoC exploitHIGH2024-07-25

Red Hat Enhancement Advisory: Red Hat Service Interconnect 1.4.7 Release rpms

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
skupper-cli affected Red Hat:service_interconnect:1.4::el8 skupper-cli
skupper-cli affected Red Hat:service_interconnect:1.4::el9 skupper-cli
Upstream advisory

GHSA-248v-346w-9cwc

GooglePoC exploit2024-07-05

Certifi removes GLOBALTRUST root certificate

Affected products

ProductStatusVendorPackageEcosystem
certifi affected PyPI certifi
Upstream advisory

GHSA-248v-346w-9cwc

Open SourcePoC exploitLOW2024-07-05

Certifi removes GLOBALTRUST root certificate

Affected products

ProductStatusVendorPackageEcosystem
airflow affected chainguard airflow
airflow affected wolfi airflow
az affected chainguard az
az affected wolfi az
barman affected chainguard barman
certifi affected PyPI certifi
certifi affected PyPI certifi
checkov affected wolfi checkov
checkov affected chainguard checkov
confluent-docker-utils affected chainguard confluent-docker-utils
confluent-docker-utils affected wolfi confluent-docker-utils
dask-gateway affected wolfi dask-gateway
dask-gateway affected chainguard dask-gateway
datadog-agent affected wolfi datadog-agent
datadog-agent affected chainguard datadog-agent
datadog-agent-fips affected chainguard datadog-agent-fips
jwt-tool affected wolfi jwt-tool
jwt-tool affected chainguard jwt-tool
k8s-sidecar affected chainguard k8s-sidecar
k8s-sidecar affected wolfi k8s-sidecar
k8s-sidecar-1.22 affected chainguard k8s-sidecar-1.22
kubeflow-jupyter-web-app affected wolfi kubeflow-jupyter-web-app
kubeflow-jupyter-web-app affected chainguard kubeflow-jupyter-web-app
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines-visualization-server affected wolfi kubeflow-pipelines-visualization-server
kubeflow-pipelines-visualization-server affected chainguard kubeflow-pipelines-visualization-server
kubeflow-volumes-web-app affected chainguard kubeflow-volumes-web-app
kubeflow-volumes-web-app affected wolfi kubeflow-volumes-web-app
mlflow affected chainguard mlflow
mlflow affected wolfi mlflow
nvidia-nsight-compute-13.1 affected chainguard nvidia-nsight-compute-13.1
nvidia-nsight-compute-13.2 affected chainguard nvidia-nsight-compute-13.2
patroni affected wolfi patroni
patroni affected chainguard patroni
py3.10-pytorch-cuda-11.8 affected chainguard py3.10-pytorch-cuda-11.8
py3.10-pytorch-cuda-12.3 affected chainguard py3.10-pytorch-cuda-12.3
py3.10-torchvision-cuda-11.8 affected chainguard py3.10-torchvision-cuda-11.8
py3.10-torchvision-cuda-12.3 affected chainguard py3.10-torchvision-cuda-12.3
py3.11-pytorch-cuda-12.3 affected chainguard py3.11-pytorch-cuda-12.3
py3.11-torchaudio-cuda-12.3 affected chainguard py3.11-torchaudio-cuda-12.3
py3.11-torchvision-cuda-11.8 affected chainguard py3.11-torchvision-cuda-11.8
py3.11-torchvision-cuda-12.3 affected chainguard py3.11-torchvision-cuda-12.3
py3.12-pytorch-cuda-11.8 affected chainguard py3.12-pytorch-cuda-11.8
py3.12-pytorch-cuda-12.3 affected chainguard py3.12-pytorch-cuda-12.3
py3.12-torchvision-cuda-11.8 affected chainguard py3.12-torchvision-cuda-11.8
py3.12-torchvision-cuda-12.3 affected chainguard py3.12-torchvision-cuda-12.3
py3-cassandra-medusa affected chainguard py3-cassandra-medusa
py3-cassandra-medusa affected wolfi py3-cassandra-medusa
py3-certifi affected wolfi py3-certifi
py3-certifi affected chainguard py3-certifi
py3-pipenv affected wolfi py3-pipenv
py3-pipenv affected chainguard py3-pipenv
py3-torchvision-cuda-11.8 affected chainguard py3-torchvision-cuda-11.8
reflex affected chainguard reflex
reflex affected wolfi reflex
request-1276 affected chainguard request-1276
superset affected wolfi superset
superset affected chainguard superset
Upstream advisory

openSUSE-SU-2024:14218-1

Open SourcePoC exploit2024-07-26

golang-github-lusitaniae-apache_exporter-1.0.8-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lusitaniae-apache_exporter affected openSUSE:Tumbleweed golang-github-lusitaniae-apache_exporter
Upstream advisory

BIT-golang-2023-24531

Open SourcePoC exploitCRITICAL2024-07-04

Output of "go env" does not sanitize values in cmd/go

Affected products

ProductStatusVendorPackageEcosystem
golang affected Bitnami golang
Upstream advisory

AZL-43104

Open SourcePoC exploit2024-07-02

CVE-2023-24531 affecting package msft-golang for versions less than 1.21.0-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-43110

Open SourcePoC exploit2024-07-02

CVE-2023-24531 affecting package golang for versions less than 1.21.0-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-52719

Open SourcePoC exploit2024-07-02

CVE-2023-24531 affecting package golang for versions less than 1.21.0-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-79036

Open SourcePoC exploit2024-07-02

CVE-2023-24531 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-24531

Open SourcePoC exploitCRITICAL2024-07-02

DEBIAN-CVE-2023-24531

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GO-2024-2918

Open SourcePoC exploitCRITICAL2024-07-01

Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity

Affected products

ProductStatusVendorPackageEcosystem
airflow affected chainguard airflow
airflow affected wolfi airflow
argo-cd-2.13 affected chainguard argo-cd-2.13
argo-events affected chainguard argo-events
argo-events affected wolfi argo-events
argo-events-fips affected chainguard argo-events-fips
argo-workflows affected chainguard argo-workflows
argo-workflows affected wolfi argo-workflows
argo-workflows-fips affected chainguard argo-workflows-fips
Azure/azure-sdk-for-go/sdk/azidentity affected github.com github.com/Azure/azure-sdk-for-go/sdk/azidentity
bank-vaults affected chainguard bank-vaults
bank-vaults affected wolfi bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
boring-registry affected wolfi boring-registry
boring-registry affected chainguard boring-registry
boring-registry-fips affected chainguard boring-registry-fips
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
chezmoi affected wolfi chezmoi
chezmoi affected chainguard chezmoi
cluster-autoscaler-1.31 affected chainguard cluster-autoscaler-1.31
cluster-autoscaler-1.32 affected chainguard cluster-autoscaler-1.32
cluster-autoscaler-fips-1.31 affected chainguard cluster-autoscaler-fips-1.31
cluster-autoscaler-fips-1.32 affected chainguard cluster-autoscaler-fips-1.32
cortex affected wolfi cortex
cortex affected chainguard cortex
cortex-fips affected chainguard cortex-fips
cosign affected wolfi cosign
cosign affected chainguard cosign
cosign-fips affected chainguard cosign-fips
druid affected wolfi druid
druid affected chainguard druid
external-secrets-fips affected chainguard external-secrets-fips
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
fluent-bit-plugin-loki affected wolfi fluent-bit-plugin-loki
fluent-bit-plugin-loki affected chainguard fluent-bit-plugin-loki
flux affected wolfi flux
flux affected chainguard flux
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
flyte affected chainguard flyte
flyte affected wolfi flyte
fulcio affected wolfi fulcio
fulcio affected chainguard fulcio
fulcio-fips affected chainguard fulcio-fips
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
grafana-agent-operator affected chainguard grafana-agent-operator
grafana-agent-operator affected wolfi grafana-agent-operator
grafana-mimir affected chainguard grafana-mimir
grafana-mimir affected wolfi grafana-mimir
guac affected wolfi guac
guac affected chainguard guac
harbor-registry affected chainguard harbor-registry
harbor-registry affected wolfi harbor-registry
harbor-registry-fips affected chainguard harbor-registry-fips
hugo affected wolfi hugo
hugo affected chainguard hugo
hugo-extended affected wolfi hugo-extended
hugo-extended affected chainguard hugo-extended
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
ksops affected chainguard ksops
ksops affected wolfi ksops
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
loki-2.9 affected chainguard loki-2.9
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
policy-controller affected chainguard policy-controller
policy-controller affected wolfi policy-controller
policy-controller-fips affected chainguard policy-controller-fips
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-operator affected wolfi prometheus-operator
prometheus-operator affected chainguard prometheus-operator
prometheus-operator-fips affected chainguard prometheus-operator-fips
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
py3-azure-identity affected chainguard py3-azure-identity
py3-azure-identity affected wolfi py3-azure-identity
py3-cassandra-medusa affected wolfi py3-cassandra-medusa
py3-cassandra-medusa affected chainguard py3-cassandra-medusa
rclone affected chainguard rclone
rclone affected wolfi rclone
rekor affected wolfi rekor
rekor affected chainguard rekor
rekor-fips affected chainguard rekor-fips
request-1276 affected chainguard request-1276
restic affected chainguard restic
restic affected wolfi restic
restic-fips affected chainguard restic-fips
rook affected wolfi rook
rook affected chainguard rook
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
sigstore-scaffolding-fips affected chainguard sigstore-scaffolding-fips
sops affected chainguard sops
sops affected wolfi sops
spire-server affected chainguard spire-server
spire-server affected wolfi spire-server
spire-server-fips affected chainguard spire-server-fips
sqlpad affected chainguard sqlpad
sqlpad affected wolfi sqlpad
step affected chainguard step
step affected wolfi step
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
step-ca-fips affected chainguard step-ca-fips
step-fips affected chainguard step-fips
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
tempo affected wolfi tempo
tempo affected chainguard tempo
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
thanos affected chainguard thanos
thanos affected wolfi thanos
thanos-fips affected chainguard thanos-fips
timestamp-authority affected wolfi timestamp-authority
timestamp-authority affected chainguard timestamp-authority
timestamp-authority-fips affected chainguard timestamp-authority-fips
tkn affected chainguard tkn
tkn affected wolfi tkn
tkn-fips affected chainguard tkn-fips
trino affected chainguard trino
trino affected wolfi trino
trivy affected chainguard trivy
trivy affected wolfi trivy
trivy-fips affected chainguard trivy-fips
up affected wolfi up
up affected chainguard up
vault-1.16 affected chainguard vault-1.16
velero affected chainguard velero
velero affected wolfi velero
velero-fips affected chainguard velero-fips
wal-g affected chainguard wal-g
wal-g affected wolfi wal-g
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

GHSA-9m98-937v-r97x

Open SourcePoC exploitHIGH2024-07-17

GHSA-9m98-937v-r97x

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-6778

Open SourcePoC exploitHIGH2024-07-16

DEBIAN-CVE-2024-6778

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-6778

GooglePoC exploitHIGH2024-07-16

Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

CVEs:CVE-2024-6778

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6778

GooglePoC exploit2024-07-16

Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

CVEs:CVE-2024-6778

Upstream advisory

OESA-2024-1791

Open SourcePoC exploit2024-07-05

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:24.03-LTS golang
Upstream advisory

CVE-2023-7011

GooglePoC exploitMEDIUM2024-07-16

Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-7011

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-7011

Open SourcePoC exploitMEDIUM2024-07-16

DEBIAN-CVE-2023-7011

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-34722

Open SourcePoC exploitHIGH2024-07-01

In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User in...

CVEs:CVE-2024-34722

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

AZL-43189

Open SourcePoC exploitCRITICAL2024-07-09

CVE-2024-5569 affecting package tensorflow for versions less than 2.16.1-9

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

ASB-A-336268889

GooglePoC exploitHIGH2024-07-01

ASB-A-336268889

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-332315050

GooglePoC exploit2024-07-01

ASB-A-332315050

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom/opensource/graphics-kernel affected platform platform/vendor/qcom/opensource/graphics-kernel
Upstream advisory

ASB-A-332315102

GooglePoC exploit2024-07-01

ASB-A-332315102

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom/opensource/graphics-kernel affected platform platform/vendor/qcom/opensource/graphics-kernel
Upstream advisory

GHSA-v4v9-v4wf-9c86

Open SourceCoalition ESS < 30%HIGH2024-07-17

GHSA-v4v9-v4wf-9c86

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-6779

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2024-6779

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-6779

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6779

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

ALSA-2024:4379

Open SourceCoalition ESS < 30%NONE2024-07-08

Important: gvisor-tap-vsock security update

Affected products

ProductStatusVendorPackageEcosystem
gvisor-tap-vsock affected AlmaLinux:9 gvisor-tap-vsock
Upstream advisory

DEBIAN-CVE-2024-37298

Open SourceCoalition ESS < 30%HIGH2024-07-01

DEBIAN-CVE-2024-37298

Affected products

ProductStatusVendorPackageEcosystem
golang-github-gorilla-schema affected Debian:12 golang-github-gorilla-schema
golang-github-gorilla-schema affected Debian:13 golang-github-gorilla-schema
golang-github-gorilla-schema affected Debian:14 golang-github-gorilla-schema
Upstream advisory

DSA-5735-1

Open SourceCoalition ESS < 30%2024-07-31

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

CVE-2024-6990

GoogleCoalition ESS < 30%2024-07-30

Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2024-6990

Upstream advisory

CVE-2024-6990

GoogleCoalition ESS < 30%HIGH2024-07-30

Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2024-6990

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-7255

GoogleCoalition ESS < 30%HIGH2024-07-30

Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-7255

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

ASB-A-338887097

GoogleCoalition ESS < 30%2024-07-01

ASB-A-338887097

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-338887100

GoogleCoalition ESS < 30%2024-07-01

ASB-A-338887100

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-6989

GoogleCoalition ESS < 30%CRITICAL2024-07-23

Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6989

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6989

GoogleCoalition ESS < 30%2024-07-23

Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6989

Upstream advisory

CVE-2024-6991

GoogleCoalition ESS < 30%2024-07-23

Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6991

Upstream advisory

CVE-2024-6991

GoogleCoalition ESS < 30%CRITICAL2024-07-23

Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6991

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-30636

Open SourceCoalition ESS < 30%HIGH2024-07-02

DEBIAN-CVE-2022-30636

Affected products

ProductStatusVendorPackageEcosystem
golang-go.crypto affected Debian:12 golang-go.crypto
golang-go.crypto affected Debian:11 golang-go.crypto
golang-go.crypto affected Debian:13 golang-go.crypto
golang-go.crypto affected Debian:14 golang-go.crypto
Upstream advisory

GO-2024-2961

Open SourceCoalition ESS < 30%HIGH2024-07-02

Limited directory traversal vulnerability on Windows in golang.org/x/crypto

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CVE-2024-6988

GoogleCoalition ESS < 30%CRITICAL2024-07-23

Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6988

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6988

GoogleCoalition ESS < 30%2024-07-23

Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6988

Upstream advisory

CVE-2024-6994

GoogleCoalition ESS < 30%CRITICAL2024-07-23

Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-6994

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6997

GoogleCoalition ESS < 30%2024-07-23

Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-6997

Upstream advisory

CVE-2024-6997

GoogleCoalition ESS < 30%CRITICAL2024-07-23

Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-6997

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6998

GoogleCoalition ESS < 30%CRITICAL2024-07-23

Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-6998

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6998

GoogleCoalition ESS < 30%2024-07-23

Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-6998

Upstream advisory

CVE-2024-34593

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34593

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-7000

GoogleCoalition ESS < 30%2024-07-23

Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-7000

Upstream advisory

CVE-2024-7000

GoogleCoalition ESS < 30%CRITICAL2024-07-23

Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-7000

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-7256

GoogleCoalition ESS < 30%2024-07-30

Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-7256

Upstream advisory

CVE-2024-7256

GoogleCoalition ESS < 30%CRITICAL2024-07-30

Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-7256

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6995

GoogleCoalition ESS < 30%HIGH2024-07-23

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chro...

CVEs:CVE-2024-6995

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6995

GoogleCoalition ESS < 30%2024-07-23

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-6995

Upstream advisory

GHSA-cc8c-62x7-qwjr

Open SourceCoalition ESS < 30%HIGH2024-07-17

GHSA-cc8c-62x7-qwjr

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-6772

Open SourceCoalition ESS < 30%HIGH2024-07-16

DEBIAN-CVE-2024-6772

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-6772

GoogleCoalition ESS < 30%2024-07-16

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6772

Upstream advisory

CVE-2024-6772

GoogleCoalition ESS < 30%HIGH2024-07-16

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6772

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-34587

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnera...

CVEs:CVE-2024-34587

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-7003

GoogleCoalition ESS < 30%MEDIUM2024-07-23

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-7003

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-7003

GoogleCoalition ESS < 30%2024-07-23

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-7003

Upstream advisory

CVE-2024-6999

GoogleCoalition ESS < 30%MEDIUM2024-07-23

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-6999

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-7001

GoogleCoalition ESS < 30%MEDIUM2024-07-23

Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-7001

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-7001

GoogleCoalition ESS < 30%2024-07-23

Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-7001

Upstream advisory

CVE-2024-7005

GoogleCoalition ESS < 30%HIGH2024-07-23

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium ...

CVEs:CVE-2024-7005

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-7gj8-545r-5295

Open SourceCoalition ESS < 30%HIGH2024-07-17

GHSA-7gj8-545r-5295

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

GHSA-cgm7-mqr6-f7vg

Open SourceCoalition ESS < 30%CRITICAL2024-07-17

GHSA-cgm7-mqr6-f7vg

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-6773

Open SourceCoalition ESS < 30%HIGH2024-07-16

DEBIAN-CVE-2024-6773

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2024-6774

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2024-6774

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-6773

GoogleCoalition ESS < 30%HIGH2024-07-16

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6773

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6774

GoogleCoalition ESS < 30%2024-07-16

Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6774

Upstream advisory

CVE-2024-6774

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6774

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-7hjm-9cg2-rcg6

Open SourceCoalition ESS < 30%CRITICAL2024-07-17

GHSA-7hjm-9cg2-rcg6

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

GHSA-mxwm-jm3p-mh5m

Open SourceCoalition ESS < 30%CRITICAL2024-07-17

GHSA-mxwm-jm3p-mh5m

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-6775

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2024-6775

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2024-6776

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2024-6776

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-6775

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Use after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6775

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6776

GoogleCoalition ESS < 30%2024-07-16

Use after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6776

Upstream advisory

CVE-2024-6776

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Use after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-6776

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-7004

GoogleCoalition ESS < 30%2024-07-23

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)

CVEs:CVE-2024-7004

Upstream advisory

CVE-2024-7004

GoogleCoalition ESS < 30%MEDIUM2024-07-23

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium ...

CVEs:CVE-2024-7004

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-6996

GoogleCoalition ESS < 30%LOW2024-07-23

Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-6996

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-7010

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2023-7010

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-7010

GoogleCoalition ESS < 30%2024-07-16

Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-7010

Upstream advisory

CVE-2023-7010

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-7010

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-34588

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Improper input validation혻in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34588

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34589

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34589

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34590

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34590

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34591

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34591

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34592

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34592

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-4860

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4860

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-4860

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2023-4860

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2024:14092-1

Open SourceCoalition ESS < 30%2024-07-03

golang-github-prometheus-prometheus-2.53.0-2.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-prometheus affected openSUSE:Tumbleweed golang-github-prometheus-prometheus
Upstream advisory

CVE-2024-5219

GoogleCoalition ESS < 30%HIGH2024-07-02

The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible...

CVEs:CVE-2024-5219

Affected products

ProductStatusVendorPackageEcosystem
easy_google_maps affected supsystic
Upstream advisory

GHSA-w2v8-c457-cjvf

Open SourceCoalition ESS < 30%CRITICAL2024-07-17

GHSA-w2v8-c457-cjvf

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-6777

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2024-6777

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-6777

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

CVEs:CVE-2024-6777

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2019-25154

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2019-25154

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-25154

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2019-25154

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-36765

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Insufficient policy enforcement in Navigation in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2020-36765

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-36765

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2020-36765

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-7012

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Me...

CVEs:CVE-2023-7012

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-7012

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2023-7012

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GO-2024-2977

GoogleCoalition ESS < 30%2024-07-09

IP addresses were encoded in the wrong byte order in github.com/google/nftables

Affected products

ProductStatusVendorPackageEcosystem
google/nftables affected github.com github.com/google/nftables
Upstream advisory

GHSA-qjvf-8748-9w7h

GoogleCoalition ESS < 30%MEDIUM2024-07-04

github.com/google/nftable IP addresses were encoded in the wrong byte order

Affected products

ProductStatusVendorPackageEcosystem
google/nftables affected github.com github.com/google/nftables
Upstream advisory

GHSA-qjvf-8748-9w7h

GoogleCoalition ESS < 30%MEDIUM2024-07-04

github.com/google/nftable IP addresses were encoded in the wrong byte order

Affected products

ProductStatusVendorPackageEcosystem
google/nftables affected github.com github.com/google/nftables
Upstream advisory

CVE-2024-6284

GoogleCoalition ESS < 30%MEDIUM2024-07-03

github.com/google/nftable IP addresses were encoded in the wrong byte order

CVEs:CVE-2024-6284

Affected products

ProductStatusVendorPackageEcosystem
google/nftables affected github.com github.com/google/nftables
Upstream advisory

CVE-2024-6284

GoogleCoalition ESS < 30%HIGH2024-07-03

In https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses). This issue affects:  https://pkg.go....

CVEs:CVE-2024-6284

Affected products

ProductStatusVendorPackageEcosystem
nftables affected google
Upstream advisory

CVE-2024-6284

GoogleCoalition ESS < 30%2024-07-03

In https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses). This issue affects:  https://pkg.go.dev/github.com/google/nftables@v0.1.0 The bug was fixed in the next released version:  https://pkg.go.dev/github.com/google/nftables@v0.2.0

CVEs:CVE-2024-6284

Upstream advisory

DEBIAN-CVE-2024-6284

Open SourceCoalition ESS < 30%HIGH2024-07-03

DEBIAN-CVE-2024-6284

Affected products

ProductStatusVendorPackageEcosystem
golang-github-google-nftables affected Debian:12 golang-github-google-nftables
golang-github-google-nftables affected Debian:13 golang-github-google-nftables
golang-github-google-nftables affected Debian:14 golang-github-google-nftables
Upstream advisory

CVE-2024-20080

Open SourceCoalition ESS < 30%CRITICAL2024-07-01

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patc...

CVEs:CVE-2024-20080

Affected products

ProductStatusVendorPackageEcosystem
android affected google
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2024-20080

GoogleCoalition ESS < 30%2024-07-01

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.

CVEs:CVE-2024-20080

Upstream advisory

PUB-A-318387243

GoogleCoalition ESS < 30%2024-07-01

PUB-A-318387243

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20078

Open SourceCoalition ESS < 30%CRITICAL2024-07-01

In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issue ID: MSV-1452.

CVEs:CVE-2024-20078

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-7013

GoogleCoalition ESS < 30%MEDIUM2024-07-16

Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-7013

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-7013

Open SourceCoalition ESS < 30%MEDIUM2024-07-16

DEBIAN-CVE-2023-7013

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-20894

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-20894

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-3175

GoogleCoalition ESS < 30%CRITICAL2024-07-16

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)

CVEs:CVE-2024-3175

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-3175

Open SourceCoalition ESS < 30%CRITICAL2024-07-16

DEBIAN-CVE-2024-3175

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-20890

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.

CVEs:CVE-2024-20890

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20889

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.

CVEs:CVE-2024-20889

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-302570828

GoogleCoalition ESS < 30%2024-07-01

ASB-A-302570828

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-318386769

GoogleCoalition ESS < 30%2024-07-01

PUB-A-318386769

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-318386861

GoogleCoalition ESS < 30%2024-07-01

PUB-A-318386861

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-318386997

GoogleCoalition ESS < 30%2024-07-01

PUB-A-318386997

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20888

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-20888

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20079

Open SourceCoalition ESS < 30%CRITICAL2024-07-01

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040...

CVEs:CVE-2024-20079

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-34595

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2024-34595

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20893

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.

CVEs:CVE-2024-20893

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20901

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.

CVEs:CVE-2024-20901

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34594

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.

CVEs:CVE-2024-34594

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20891

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2024-20891

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20896

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVEs:CVE-2024-20896

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20895

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.

CVEs:CVE-2024-20895

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34585

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2024-34585

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20900

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.

CVEs:CVE-2024-20900

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20897

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVEs:CVE-2024-20897

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20898

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVEs:CVE-2024-20898

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20899

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVEs:CVE-2024-20899

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34583

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.

CVEs:CVE-2024-34583

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34586

Open SourceCoalition ESS < 30%MEDIUM2024-07-01

Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.

CVEs:CVE-2024-34586

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20892

Open SourceCoalition ESS < 30%HIGH2024-07-01

Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-20892

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-31332

Open SourceCoalition ESS < 30%HIGH2024-07-01

In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...

CVEs:CVE-2024-31332

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-332315224

GoogleCoalition ESS < 30%2024-07-01

ASB-A-332315224

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2024-39428

Open SourceCoalition ESS < 30%CRITICAL2024-07-01

In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2024-39428

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-39427

Open SourceCoalition ESS < 30%CRITICAL2024-07-01

In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2024-39427

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-39430

Open SourceCoalition ESS < 30%CRITICAL2024-07-01

In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2024-39430

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-39429

Open SourceCoalition ESS < 30%CRITICAL2024-07-01

In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2024-39429

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-q445-7m23-qrmw

GoogleAll remainingMEDIUM2024-07-22

openssl's `MemBio::get_buf` has undefined behavior with empty buffers

Affected products

ProductStatusVendorPackageEcosystem
openssl affected crates.io openssl
Upstream advisory

GHSA-q445-7m23-qrmw

Open SourceAll remainingMEDIUM2024-07-22

openssl's `MemBio::get_buf` has undefined behavior with empty buffers

Affected products

ProductStatusVendorPackageEcosystem
berg affected chainguard berg
berg affected wolfi berg
lychee affected wolfi lychee
lychee affected chainguard lychee
openssl affected crates.io openssl
openssl affected crates.io
pixi affected chainguard pixi
pixi affected wolfi pixi
rustup affected chainguard rustup
rustup affected wolfi rustup
sccache affected wolfi sccache
sccache affected chainguard sccache
sdp-k8s-injector affected wolfi sdp-k8s-injector
sdp-k8s-injector affected chainguard sdp-k8s-injector
zed affected chainguard zed
zed affected wolfi zed
Upstream advisory

GO-2024-2978

Open SourceAll remainingNONE2024-07-09

Private tokens could appear in logs if context containing gRPC metadata is logged in google.golang.org/grpc

Affected products

ProductStatusVendorPackageEcosystem
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
certificate-transparency affected chainguard certificate-transparency
certificate-transparency affected wolfi certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cert-manager-cmctl affected wolfi cert-manager-cmctl
cert-manager-cmctl affected chainguard cert-manager-cmctl
cert-manager-cmctl-fips affected chainguard cert-manager-cmctl-fips
cilium-1.15 affected chainguard cilium-1.15
cilium-1.16 affected chainguard cilium-1.16
cilium-cli affected wolfi cilium-cli
cilium-cli affected chainguard cilium-cli
cilium-fips-1.15 affected chainguard cilium-fips-1.15
cloudnative-pg affected chainguard cloudnative-pg
cloudnative-pg affected wolfi cloudnative-pg
cloudnative-pg-fips affected chainguard cloudnative-pg-fips
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
conftest affected chainguard conftest
conftest affected wolfi conftest
conftest-fips affected chainguard conftest-fips
dagger affected chainguard dagger
dagger affected wolfi dagger
dbmate affected wolfi dbmate
dbmate affected chainguard dbmate
dex affected wolfi dex
dex affected chainguard dex
dex-fips affected chainguard dex-fips
external-secrets-fips affected chainguard external-secrets-fips
falcosidekick affected wolfi falcosidekick
falcosidekick affected chainguard falcosidekick
falcosidekick-fips affected chainguard falcosidekick-fips
ferretdb affected wolfi ferretdb
ferretdb affected chainguard ferretdb
fulcio affected wolfi fulcio
fulcio affected chainguard fulcio
fulcio-fips affected chainguard fulcio-fips
gomplate affected chainguard gomplate
gomplate affected wolfi gomplate
gomplate-fips affected chainguard gomplate-fips
grafana-agent-operator affected chainguard grafana-agent-operator
grafana-agent-operator affected wolfi grafana-agent-operator
grafana-mimir affected chainguard grafana-mimir
grafana-mimir affected wolfi grafana-mimir
grpc affected google.golang.org google.golang.org/grpc
grpc-health-probe affected wolfi grpc-health-probe
grpc-health-probe affected chainguard grpc-health-probe
grpc-health-probe-fips affected chainguard grpc-health-probe-fips
guac affected chainguard guac
guac affected wolfi guac
hubble-ui affected chainguard hubble-ui
hubble-ui affected wolfi hubble-ui
hubble-ui-backend-fips affected chainguard hubble-ui-backend-fips
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k3s-1.31 affected chainguard k3s-1.31
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k8sgpt-operator affected chainguard k8sgpt-operator
k8sgpt-operator affected wolfi k8sgpt-operator
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
kargo affected wolfi kargo
kargo affected chainguard kargo
kots affected wolfi kots
kots affected chainguard kots
ksops affected chainguard ksops
ksops affected wolfi ksops
kube-rbac-proxy affected wolfi kube-rbac-proxy
kube-rbac-proxy affected chainguard kube-rbac-proxy
kube-rbac-proxy-fips affected chainguard kube-rbac-proxy-fips
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kwok affected chainguard kwok
kwok affected wolfi kwok
melange affected wolfi melange
melange affected chainguard melange
minio affected chainguard minio
minio affected wolfi minio
minio-fips affected chainguard minio-fips
opa affected chainguard opa
opa affected wolfi opa
opa-fips affected chainguard opa-fips
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
osv-scanner affected wolfi osv-scanner
osv-scanner affected chainguard osv-scanner
prometheus-2.53 affected chainguard prometheus-2.53
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
restic affected wolfi restic
restic affected chainguard restic
restic-fips affected chainguard restic-fips
rqlite affected wolfi rqlite
rqlite affected chainguard rqlite
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
sigstore-scaffolding-fips affected chainguard sigstore-scaffolding-fips
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
sops affected wolfi sops
sops affected chainguard sops
spegel affected wolfi spegel
spegel affected chainguard spegel
spicedb affected wolfi spicedb
spicedb affected chainguard spicedb
spire-server affected chainguard spire-server
spire-server affected wolfi spire-server
spire-server-fips affected chainguard spire-server-fips
step affected wolfi step
step affected chainguard step
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
step-ca-fips affected chainguard step-ca-fips
step-fips affected chainguard step-fips
tempo affected chainguard tempo
tempo affected wolfi tempo
temporal affected chainguard temporal
temporal affected wolfi temporal
temporal-fips affected chainguard temporal-fips
terraform-docs affected chainguard terraform-docs
terraform-docs affected wolfi terraform-docs
terraform-provider-google affected chainguard terraform-provider-google
terraform-provider-google affected wolfi terraform-provider-google
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
tflint affected chainguard tflint
tflint affected wolfi tflint
trivy affected wolfi trivy
trivy affected chainguard trivy
trivy-fips affected chainguard trivy-fips
vault-1.17 affected chainguard vault-1.17
vcluster affected wolfi vcluster
vcluster affected chainguard vcluster
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

GHSA-xr7q-jx4m-x55m

Open SourceAll remainingNONE2024-07-05

Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go

Affected products

ProductStatusVendorPackageEcosystem
grpc affected google.golang.org google.golang.org/grpc
Upstream advisory

GHSA-xr7q-jx4m-x55m

Open SourceAll remainingNONE2024-07-05

Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go

Affected products

ProductStatusVendorPackageEcosystem
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-ebs-csi-driver-fips affected chainguard aws-ebs-csi-driver-fips
certificate-transparency affected wolfi certificate-transparency
certificate-transparency affected chainguard certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cert-manager-1.15 affected chainguard cert-manager-1.15
cert-manager-1.15 affected wolfi cert-manager-1.15
cert-manager-cmctl affected chainguard cert-manager-cmctl
cert-manager-cmctl affected wolfi cert-manager-cmctl
cert-manager-cmctl-fips affected chainguard cert-manager-cmctl-fips
cert-manager-fips-1.15 affected chainguard cert-manager-fips-1.15
cilium-1.15 affected chainguard cilium-1.15
cilium-1.15 affected wolfi cilium-1.15
cilium-1.16 affected chainguard cilium-1.16
cilium-1.16 affected wolfi cilium-1.16
cilium-cli affected wolfi cilium-cli
cilium-cli affected chainguard cilium-cli
cilium-fips-1.14 affected chainguard cilium-fips-1.14
cilium-fips-1.15 affected chainguard cilium-fips-1.15
cloudnative-pg affected chainguard cloudnative-pg
cloudnative-pg affected wolfi cloudnative-pg
cloudnative-pg-fips affected chainguard cloudnative-pg-fips
cloud-sql-proxy affected wolfi cloud-sql-proxy
cloud-sql-proxy affected chainguard cloud-sql-proxy
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
conftest affected wolfi conftest
conftest affected chainguard conftest
conftest-fips affected chainguard conftest-fips
dagger affected chainguard dagger
dagger affected wolfi dagger
datadog-agent affected chainguard datadog-agent
datadog-agent affected wolfi datadog-agent
datadog-agent-fips affected chainguard datadog-agent-fips
dbmate affected wolfi dbmate
dbmate affected chainguard dbmate
dex affected wolfi dex
dex affected chainguard dex
dex-fips affected chainguard dex-fips
external-secrets-fips affected chainguard external-secrets-fips
external-secrets-operator affected chainguard external-secrets-operator
external-secrets-operator affected wolfi external-secrets-operator
falcosidekick affected wolfi falcosidekick
falcosidekick affected chainguard falcosidekick
falcosidekick-fips affected chainguard falcosidekick-fips
ferretdb affected wolfi ferretdb
ferretdb affected chainguard ferretdb
filebeat affected chainguard filebeat
filebeat affected wolfi filebeat
filebeat-fips affected chainguard filebeat-fips
fulcio affected chainguard fulcio
fulcio affected wolfi fulcio
fulcio-fips affected chainguard fulcio-fips
gitaly affected chainguard gitaly
gitaly affected wolfi gitaly
gitaly-17.2 affected chainguard gitaly-17.2
gitaly-17.2 affected wolfi gitaly-17.2
gitaly-17.3 affected chainguard gitaly-17.3
gitaly-ee-17.1 affected chainguard gitaly-ee-17.1
gitaly-ee-fips-17.1 affected chainguard gitaly-ee-fips-17.1
gitlab-ee-17.1 affected chainguard gitlab-ee-17.1
gitlab-ee-fips-17.1 affected chainguard gitlab-ee-fips-17.1
gitlab-kas-17.1 affected wolfi gitlab-kas-17.1
gitlab-kas-17.1 affected chainguard gitlab-kas-17.1
gitlab-runner-17.0 affected chainguard gitlab-runner-17.0
gitlab-runner-17.1 affected wolfi gitlab-runner-17.1
gitlab-runner-17.1 affected chainguard gitlab-runner-17.1
gitlab-runner-fips-17.3 affected chainguard gitlab-runner-fips-17.3
go-ipfs-fips affected chainguard go-ipfs-fips
gomplate affected chainguard gomplate
gomplate affected wolfi gomplate
gomplate-fips affected chainguard gomplate-fips
grafana-11.0 affected chainguard grafana-11.0
grafana-11.0 affected wolfi grafana-11.0
grafana-11.1 affected chainguard grafana-11.1
grafana-11.1 affected wolfi grafana-11.1
grafana-11.2 affected chainguard grafana-11.2
grafana-11.2 affected wolfi grafana-11.2
grafana-9 affected chainguard grafana-9
grafana-9-fips affected chainguard grafana-9-fips
grafana-agent-operator affected chainguard grafana-agent-operator
grafana-agent-operator affected wolfi grafana-agent-operator
grafana-fips-11.0 affected chainguard grafana-fips-11.0
grafana-fips-11.1 affected chainguard grafana-fips-11.1
grafana-mimir affected wolfi grafana-mimir
grafana-mimir affected chainguard grafana-mimir
grpc affected google.golang.org
grpc affected google.golang.org google.golang.org/grpc
grpc affected google.golang.org google.golang.org/grpc
grpc/grpc-go affected github.com github.com/grpc/grpc-go
grpc/grpc-go affected github.com
grpc-health-probe affected wolfi grpc-health-probe
grpc-health-probe affected chainguard grpc-health-probe
grpc-health-probe-fips affected chainguard grpc-health-probe-fips
guac affected chainguard guac
guac affected wolfi guac
hubble-ui affected chainguard hubble-ui
hubble-ui affected wolfi hubble-ui
hubble-ui-backend affected chainguard hubble-ui-backend
hubble-ui-backend-fips affected chainguard hubble-ui-backend-fips
influxd affected chainguard influxd
influxd affected wolfi influxd
ipfs affected wolfi ipfs
ipfs affected chainguard ipfs
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected wolfi k3s
k3s affected chainguard k3s
k3s-1.31 affected chainguard k3s-1.31
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
k8sgpt-operator affected chainguard k8sgpt-operator
k8sgpt-operator affected wolfi k8sgpt-operator
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
kargo affected wolfi kargo
kargo affected chainguard kargo
kots affected chainguard kots
kots affected wolfi kots
kots-compat affected chainguard kots-compat
ksops affected wolfi ksops
ksops affected chainguard ksops
kube-rbac-proxy affected wolfi kube-rbac-proxy
kube-rbac-proxy affected chainguard kube-rbac-proxy
kube-rbac-proxy-fips affected chainguard kube-rbac-proxy-fips
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-snapshotter affected wolfi kubernetes-csi-external-snapshotter
kubernetes-csi-external-snapshotter affected chainguard kubernetes-csi-external-snapshotter
kubernetes-csi-external-snapshotter-6.0 affected chainguard kubernetes-csi-external-snapshotter-6.0
kwok affected wolfi kwok
kwok affected chainguard kwok
melange affected chainguard melange
melange affected wolfi melange
minio affected chainguard minio
minio affected wolfi minio
minio-fips affected chainguard minio-fips
opa affected wolfi opa
opa affected chainguard opa
opa-fips affected chainguard opa-fips
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
osv-scanner affected chainguard osv-scanner
osv-scanner affected wolfi osv-scanner
prometheus-2.53 affected wolfi prometheus-2.53
prometheus-2.53 affected chainguard prometheus-2.53
prometheus-fips affected chainguard prometheus-fips
prometheus-fips-2.53 affected chainguard prometheus-fips-2.53
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
restic affected chainguard restic
restic affected wolfi restic
restic-fips affected chainguard restic-fips
rqlite affected chainguard rqlite
rqlite affected wolfi rqlite
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
sigstore-scaffolding-fips affected chainguard sigstore-scaffolding-fips
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
sops affected chainguard sops
sops affected wolfi sops
spegel affected chainguard spegel
spegel affected wolfi spegel
spicedb affected wolfi spicedb
spicedb affected chainguard spicedb
spire-server affected chainguard spire-server
spire-server affected wolfi spire-server
spire-server-fips affected chainguard spire-server-fips
step affected chainguard step
step affected wolfi step
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
step-ca-fips affected chainguard step-ca-fips
step-fips affected chainguard step-fips
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
tekton-pipelines-fips affected chainguard tekton-pipelines-fips
telegraf-1.31 affected chainguard telegraf-1.31
telegraf-1.31 affected wolfi telegraf-1.31
teleport affected chainguard teleport
teleport affected wolfi teleport
tempo affected chainguard tempo
tempo affected wolfi tempo
tempo-fips affected chainguard tempo-fips
temporal affected chainguard temporal
temporal affected wolfi temporal
temporal-fips affected chainguard temporal-fips
terraform-docs affected chainguard terraform-docs
terraform-docs affected wolfi terraform-docs
terraform-provider-google affected wolfi terraform-provider-google
terraform-provider-google affected chainguard terraform-provider-google
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
tflint affected chainguard tflint
tflint affected wolfi tflint
traefik-3.0 affected wolfi traefik-3.0
traefik-3.0 affected chainguard traefik-3.0
traefik-3.0-fips affected chainguard traefik-3.0-fips
trivy affected chainguard trivy
trivy affected wolfi trivy
trivy-fips affected chainguard trivy-fips
vault-1.17 affected chainguard vault-1.17
vault-fips-1.17 affected chainguard vault-fips-1.17
vcluster affected chainguard vcluster
vcluster affected wolfi vcluster
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.