ghcr.io/dask/dask:latest linux/amd64

ghcr.io/dask/dask:latest - Trivy安全扫描结果 扫描时间: 2026-01-23 10:41
全部漏洞信息
低危漏洞:12 中危漏洞:12 高危漏洞:5 严重漏洞:0

系统OS: ubuntu 24.04 扫描引擎: Trivy 扫描时间: 2026-01-23 10:41

ghcr.io/dask/dask:latest (ubuntu 24.04) (ubuntu)
低危漏洞:12 中危漏洞:11 高危漏洞:1 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
gpgv CVE-2025-68973 高危 2.4.4-2ubuntu17.3 2.4.4-2ubuntu17.4 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2025-12-28 17:16 修改: 2026-01-14 19:16

git-man CVE-2024-52005 中危 1:2.43.0-1ubuntu7.3 git: The sideband payload is passed unfiltered to the terminal in git

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52005

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2025-01-15 18:15 修改: 2025-12-18 16:00

git CVE-2024-52005 中危 1:2.43.0-1ubuntu7.3 git: The sideband payload is passed unfiltered to the terminal in git

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52005

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2025-01-15 18:15 修改: 2025-12-18 16:00

gpgv CVE-2025-68972 中危 2.4.4-2ubuntu17.3 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2025-12-27 23:15 修改: 2026-01-09 20:08

libexpat1 CVE-2025-66382 中危 2.6.1-2ubuntu0.3 libexpat: libexpat: Denial of service via crafted file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66382

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2025-11-28 07:15 修改: 2025-12-19 16:05

libpam-modules CVE-2025-8941 中危 1.5.3-5ubuntu5.5 linux-pam: Incomplete fix for CVE-2025-6020

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8941

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2025-08-13 15:15 修改: 2025-11-20 21:16

libpam-modules-bin CVE-2025-8941 中危 1.5.3-5ubuntu5.5 linux-pam: Incomplete fix for CVE-2025-6020

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8941

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2025-08-13 15:15 修改: 2025-11-20 21:16

libpam-runtime CVE-2025-8941 中危 1.5.3-5ubuntu5.5 linux-pam: Incomplete fix for CVE-2025-6020

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8941

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2025-08-13 15:15 修改: 2025-11-20 21:16

libpam0g CVE-2025-8941 中危 1.5.3-5ubuntu5.5 linux-pam: Incomplete fix for CVE-2025-6020

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8941

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2025-08-13 15:15 修改: 2025-11-20 21:16

libtasn1-6 CVE-2025-13151 中危 4.19.0-3ubuntu0.24.04.1 4.19.0-3ubuntu0.24.04.2 libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13151

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2026-01-07 22:15 修改: 2026-01-20 18:16

tar CVE-2025-45582 中危 1.35+dfsg-3build1 tar: Tar path traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-45582

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2025-07-11 17:15 修改: 2025-11-02 01:15

wget CVE-2021-31879 中危 1.21.4-1ubuntu4.1 wget: authorization header disclosure on redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-31879

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2021-04-29 05:15 修改: 2024-11-21 06:06

libcurl3t64-gnutls CVE-2025-9086 低危 8.5.0-2ubuntu10.6 curl: libcurl: Curl out of bounds read for cookie path

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9086

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2025-09-12 06:15 修改: 2026-01-20 14:58

coreutils CVE-2016-2781 低危 9.4-3ubuntu6.1 coreutils: Non-privileged session can escape to the parent session in chroot

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-2781

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2017-02-07 15:59 修改: 2025-06-09 16:15

libgcrypt20 CVE-2024-2236 低危 1.10.3-2build1 libgcrypt: vulnerable to Marvin Attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-2236

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2024-03-06 22:15 修改: 2025-04-02 17:15

gpgv CVE-2022-3219 低危 2.4.4-2ubuntu17.3 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2023-02-23 20:15 修改: 2025-03-12 21:15

libcurl3t64-gnutls CVE-2025-0167 低危 8.5.0-2ubuntu10.6 When asked to use a `.netrc` file for credentials **and** to follow HT ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0167

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2025-02-05 10:15 修改: 2025-07-30 19:41

libcurl3t64-gnutls CVE-2025-10148 低危 8.5.0-2ubuntu10.6 curl: predictable WebSocket mask

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-10148

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2025-09-12 06:15 修改: 2026-01-20 14:55

libcurl3t64-gnutls CVE-2025-14524 低危 8.5.0-2ubuntu10.6 When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14524

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:53

libcurl3t64-gnutls CVE-2025-14819 低危 8.5.0-2ubuntu10.6 When doing TLS related transfers with reused easy or multi handles and ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14819

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:51

login CVE-2024-56433 低危 1:4.13+dfsg1-4ubuntu3.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2024-12-26 09:15 修改: 2024-12-26 09:15

passwd CVE-2024-56433 低危 1:4.13+dfsg1-4ubuntu3.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:e8bce0aabd687e9ee90e0bada33884f40b277196f72aac9934357472863a80ae

发布日期: 2024-12-26 09:15 修改: 2024-12-26 09:15

libcurl3t64-gnutls CVE-2025-15079 低危 8.5.0-2ubuntu10.6 When doing SSH-based transfers using either SCP or SFTP, and setting t ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15079

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:50

libcurl3t64-gnutls CVE-2025-15224 低危 8.5.0-2ubuntu10.6 When doing SSH-based transfers using either SCP or SFTP, and asked to ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15224

镜像层: sha256:ff9efa9a985ad4f3a012774ded7e75abbf75a5dfb5b5fef675d9354b871064bc

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:47

Python (python-pkg)
低危漏洞:0 中危漏洞:1 高危漏洞:4 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
jaraco.context CVE-2026-23949 高危 5.3.0 6.1.0 jaraco.context: jaraco.context: Path traversal via malicious tar archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-23949

镜像层: sha256:66ec881a1957f1bc4d43f0e1564a1ad4f9a2f1b0ff1ba815304564ab621ba9c7

发布日期: 2026-01-20 01:15 修改: 2026-01-20 01:15

urllib3 CVE-2025-66418 高危 2.5.0 2.6.0 urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66418

镜像层: sha256:66ec881a1957f1bc4d43f0e1564a1ad4f9a2f1b0ff1ba815304564ab621ba9c7

发布日期: 2025-12-05 16:15 修改: 2025-12-10 16:08

urllib3 CVE-2025-66471 高危 2.5.0 2.6.0 urllib3: urllib3 Streaming API improperly handles highly compressed data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66471

镜像层: sha256:66ec881a1957f1bc4d43f0e1564a1ad4f9a2f1b0ff1ba815304564ab621ba9c7

发布日期: 2025-12-05 17:16 修改: 2025-12-10 16:10

urllib3 CVE-2026-21441 高危 2.5.0 2.6.3 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-21441

镜像层: sha256:66ec881a1957f1bc4d43f0e1564a1ad4f9a2f1b0ff1ba815304564ab621ba9c7

发布日期: 2026-01-07 22:15 修改: 2026-01-15 19:21

bokeh CVE-2026-21883 中危 3.8.1 3.8.2 Bokeh: Bokeh: Information disclosure and unauthorized actions via flawed WebSocket origin validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-21883

镜像层: sha256:66ec881a1957f1bc4d43f0e1564a1ad4f9a2f1b0ff1ba815304564ab621ba9c7

发布日期: 2026-01-08 02:15 修改: 2026-01-08 18:08