docker.io/pingcap/dm:v8.5.0 linux/amd64

docker.io/pingcap/dm:v8.5.0 - Trivy安全扫描结果 扫描时间: 2024-12-24 01:02
全部漏洞信息
低危漏洞:3 中危漏洞:5 高危漏洞:3 严重漏洞:6

系统OS: rocky 9.4 扫描引擎: Trivy 扫描时间: 2024-12-24 01:02

docker.io/pingcap/dm:v8.5.0 (rocky 9.4) (rocky)
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
dm-master (gobinary)
低危漏洞:1 中危漏洞:1 高危漏洞:1 严重漏洞:2
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
github.com/pingcap/tidb CVE-2022-3023 严重 v1.1.0-beta.0.20241120103608-82376c7732c1 TiDB vulnerable to Use of Externally-Controlled Format String

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3023

镜像层: sha256:bef83a5e494c6e9390af21f2971200b437023ec5df3817919dcf8c7d5f0cf4e2

发布日期: 2022-11-04 12:15 修改: 2022-11-05 02:02

golang.org/x/crypto CVE-2024-45337 严重 v0.29.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45337

镜像层: sha256:bef83a5e494c6e9390af21f2971200b437023ec5df3817919dcf8c7d5f0cf4e2

发布日期: 2024-12-12 02:02 修改: 2024-12-12 21:15

golang.org/x/net CVE-2024-45338 高危 v0.31.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:bef83a5e494c6e9390af21f2971200b437023ec5df3817919dcf8c7d5f0cf4e2

发布日期: 2024-12-18 21:15 修改: 2024-12-18 21:15

github.com/pingcap/tidb CVE-2024-37820 中危 v1.1.0-beta.0.20241120103608-82376c7732c1 8.2.0 tidb: Null pointer dereference in expression.inferCollation

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-37820

镜像层: sha256:bef83a5e494c6e9390af21f2971200b437023ec5df3817919dcf8c7d5f0cf4e2

发布日期: 2024-06-25 19:15 修改: 2024-11-21 19:15

google.golang.org/grpc GHSA-xr7q-jx4m-x55m 低危 v1.64.0 1.64.1 Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go

漏洞详情: https://github.com/advisories/GHSA-xr7q-jx4m-x55m

镜像层: sha256:bef83a5e494c6e9390af21f2971200b437023ec5df3817919dcf8c7d5f0cf4e2

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

dm-worker (gobinary)
低危漏洞:1 中危漏洞:3 高危漏洞:1 严重漏洞:2
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
github.com/pingcap/tidb CVE-2022-3023 严重 v1.1.0-beta.0.20241120103608-82376c7732c1 TiDB vulnerable to Use of Externally-Controlled Format String

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3023

镜像层: sha256:c5bfc0874a9a7e86a113426cb2abbb73ad9d8746743f441b1aaaf6eaeabed2a9

发布日期: 2022-11-04 12:15 修改: 2022-11-05 02:02

golang.org/x/crypto CVE-2024-45337 严重 v0.29.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45337

镜像层: sha256:c5bfc0874a9a7e86a113426cb2abbb73ad9d8746743f441b1aaaf6eaeabed2a9

发布日期: 2024-12-12 02:02 修改: 2024-12-12 21:15

golang.org/x/net CVE-2024-45338 高危 v0.31.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:c5bfc0874a9a7e86a113426cb2abbb73ad9d8746743f441b1aaaf6eaeabed2a9

发布日期: 2024-12-18 21:15 修改: 2024-12-18 21:15

github.com/pingcap/tidb CVE-2024-37820 中危 v1.1.0-beta.0.20241120103608-82376c7732c1 8.2.0 tidb: Null pointer dereference in expression.inferCollation

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-37820

镜像层: sha256:c5bfc0874a9a7e86a113426cb2abbb73ad9d8746743f441b1aaaf6eaeabed2a9

发布日期: 2024-06-25 19:15 修改: 2024-11-21 19:15

github.com/dvsekhvalnov/jose2go GHSA-mhpq-9638-x6pw 中危 v1.5.0 1.5.1-0.20231206184617-48ba0b76bc88 Denial of service when decrypting attack controlled input in github.com/dvsekhvalnov/jose2go

漏洞详情: https://github.com/advisories/GHSA-mhpq-9638-x6pw

镜像层: sha256:c5bfc0874a9a7e86a113426cb2abbb73ad9d8746743f441b1aaaf6eaeabed2a9

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

github.com/dvsekhvalnov/jose2go CVE-2023-50658 中危 v1.5.0 1.6.0 The jose2go component before 1.6.0 for Go allows attackers to cause a ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50658

镜像层: sha256:c5bfc0874a9a7e86a113426cb2abbb73ad9d8746743f441b1aaaf6eaeabed2a9

发布日期: 2024-02-29 01:42 修改: 2024-02-29 13:49

google.golang.org/grpc GHSA-xr7q-jx4m-x55m 低危 v1.64.0 1.64.1 Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go

漏洞详情: https://github.com/advisories/GHSA-xr7q-jx4m-x55m

镜像层: sha256:c5bfc0874a9a7e86a113426cb2abbb73ad9d8746743f441b1aaaf6eaeabed2a9

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

dmctl (gobinary)
低危漏洞:1 中危漏洞:1 高危漏洞:1 严重漏洞:2
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
github.com/pingcap/tidb CVE-2022-3023 严重 v1.1.0-beta.0.20241120103608-82376c7732c1 TiDB vulnerable to Use of Externally-Controlled Format String

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3023

镜像层: sha256:b753b48838606115366b910a484723a5567f33e7881446d375599fce48c085e3

发布日期: 2022-11-04 12:15 修改: 2022-11-05 02:02

golang.org/x/crypto CVE-2024-45337 严重 v0.29.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45337

镜像层: sha256:b753b48838606115366b910a484723a5567f33e7881446d375599fce48c085e3

发布日期: 2024-12-12 02:02 修改: 2024-12-12 21:15

golang.org/x/net CVE-2024-45338 高危 v0.31.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:b753b48838606115366b910a484723a5567f33e7881446d375599fce48c085e3

发布日期: 2024-12-18 21:15 修改: 2024-12-18 21:15

github.com/pingcap/tidb CVE-2024-37820 中危 v1.1.0-beta.0.20241120103608-82376c7732c1 8.2.0 tidb: Null pointer dereference in expression.inferCollation

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-37820

镜像层: sha256:b753b48838606115366b910a484723a5567f33e7881446d375599fce48c085e3

发布日期: 2024-06-25 19:15 修改: 2024-11-21 19:15

google.golang.org/grpc GHSA-xr7q-jx4m-x55m 低危 v1.64.0 1.64.1 Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go

漏洞详情: https://github.com/advisories/GHSA-xr7q-jx4m-x55m

镜像层: sha256:b753b48838606115366b910a484723a5567f33e7881446d375599fce48c085e3

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00