ghcr.io/gethomepage/homepage:v0.9.12 linux/amd64

ghcr.io/gethomepage/homepage:v0.9.12 - Trivy安全扫描结果 扫描时间: 2024-11-23 16:32
全部漏洞信息
低危漏洞:3 中危漏洞:4 高危漏洞:2 严重漏洞:1

系统OS: alpine 3.20.3 扫描引擎: Trivy 扫描时间: 2024-11-23 16:32

ghcr.io/gethomepage/homepage:v0.9.12 (alpine 3.20.3) (alpine)
低危漏洞:2 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
libcrypto3 CVE-2024-9143 低危 3.3.2-r0 3.3.2-r1 openssl: Low-level invalid GF(2^m) parameters lead to OOB memory access

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-9143

镜像层: sha256:63ca1fbb43ae5034640e5e6cb3e083e05c290072c5366fcaa9d62435a4cced85

发布日期: 2024-10-16 17:15 修改: 2024-11-08 16:35

libssl3 CVE-2024-9143 低危 3.3.2-r0 3.3.2-r1 openssl: Low-level invalid GF(2^m) parameters lead to OOB memory access

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-9143

镜像层: sha256:63ca1fbb43ae5034640e5e6cb3e083e05c290072c5366fcaa9d62435a4cced85

发布日期: 2024-10-16 17:15 修改: 2024-11-08 16:35

Node.js (node-pkg)
低危漏洞:1 中危漏洞:4 高危漏洞:2 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
jsonpath-plus CVE-2024-21534 严重 0.19.0 10.0.7 jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-21534

镜像层: sha256:3e28e87dfe68859c7dbb9b26307e239032fc4de1d54693d6d4d06fddcdd4dfcd

发布日期: 2024-10-11 13:15 修改: 2024-11-18 11:15

cross-spawn CVE-2024-21538 高危 7.0.3 7.0.5, 6.0.6 Regular Expression Denial of Service (ReDoS) in cross-spawn

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-21538

镜像层: sha256:f58c462fa0792c608b290544ee5db1ed82c670c5a0d9800359d10b817208ceae

发布日期: 2024-11-08 05:15 修改: 2024-11-19 14:15

cross-spawn CVE-2024-21538 高危 7.0.3 7.0.5, 6.0.6 Regular Expression Denial of Service (ReDoS) in cross-spawn

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-21538

镜像层: sha256:3e28e87dfe68859c7dbb9b26307e239032fc4de1d54693d6d4d06fddcdd4dfcd

发布日期: 2024-11-08 05:15 修改: 2024-11-19 14:15

next CVE-2024-47831 中危 12.3.4 14.2.7 next.js: Next.js image optimization has Denial of Service condition

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47831

镜像层: sha256:3e28e87dfe68859c7dbb9b26307e239032fc4de1d54693d6d4d06fddcdd4dfcd

发布日期: 2024-10-14 18:15 修改: 2024-11-08 15:39

postcss CVE-2023-44270 中危 8.4.14 8.4.31 An issue was discovered in PostCSS before 8.4.31. The vulnerability af ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-44270

镜像层: sha256:3e28e87dfe68859c7dbb9b26307e239032fc4de1d54693d6d4d06fddcdd4dfcd

发布日期: 2023-09-29 22:15 修改: 2023-10-10 17:19

request CVE-2023-28155 中危 2.88.2 The Request package through 2.88.1 for Node.js allows a bypass of SSRF ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-28155

镜像层: sha256:3e28e87dfe68859c7dbb9b26307e239032fc4de1d54693d6d4d06fddcdd4dfcd

发布日期: 2023-03-16 15:15 修改: 2024-08-02 13:15

tough-cookie CVE-2023-26136 中危 2.5.0 4.1.3 tough-cookie: prototype pollution in cookie memstore

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-26136

镜像层: sha256:3e28e87dfe68859c7dbb9b26307e239032fc4de1d54693d6d4d06fddcdd4dfcd

发布日期: 2023-07-01 05:15 修改: 2024-06-21 19:15

next CVE-2023-46298 低危 12.3.4 13.4.20-canary.13 Next.js missing cache-control header may lead to CDN caching empty reply

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-46298

镜像层: sha256:3e28e87dfe68859c7dbb9b26307e239032fc4de1d54693d6d4d06fddcdd4dfcd

发布日期: 2023-10-22 03:15 修改: 2023-10-28 03:30