ghcr.io/loft-sh/loft:4.1.0 linux/amd64

ghcr.io/loft-sh/loft:4.1.0 - Trivy安全扫描结果 扫描时间: 2025-01-22 10:27
全部漏洞信息
低危漏洞:3 中危漏洞:122 高危漏洞:45 严重漏洞:23

系统OS: alpine 3.18.9 扫描引擎: Trivy 扫描时间: 2025-01-22 10:27

ghcr.io/loft-sh/loft:4.1.0 (alpine 3.18.9) (alpine)
低危漏洞:1 中危漏洞:7 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
curl CVE-2024-11053 中危 8.9.1-r1 8.11.1-r0 curl: curl netrc password leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-11053

镜像层: sha256:cd8bfd304e3bf9690cb23bc5b71eb8c0fce09f87c05dffc5c92465ffe55ce34e

发布日期: 2024-12-11 08:15 修改: 2024-12-15 17:15

curl CVE-2024-8096 中危 8.9.1-r1 8.10.0-r0 curl: OCSP stapling bypass with GnuTLS

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-8096

镜像层: sha256:cd8bfd304e3bf9690cb23bc5b71eb8c0fce09f87c05dffc5c92465ffe55ce34e

发布日期: 2024-09-11 10:15 修改: 2024-09-11 16:26

curl CVE-2024-9681 中危 8.9.1-r1 8.11.0-r0 curl: HSTS subdomain overwrites parent cache entry

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-9681

镜像层: sha256:cd8bfd304e3bf9690cb23bc5b71eb8c0fce09f87c05dffc5c92465ffe55ce34e

发布日期: 2024-11-06 08:15 修改: 2024-12-13 14:15

git CVE-2024-52006 中危 2.40.3-r0 2.40.4-r0 git: Newline confusion in credential helpers can lead to credential exfiltration in git

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52006

镜像层: sha256:cd8bfd304e3bf9690cb23bc5b71eb8c0fce09f87c05dffc5c92465ffe55ce34e

发布日期: 2025-01-14 19:15 修改: 2025-01-14 19:15

libcurl CVE-2024-11053 中危 8.9.1-r1 8.11.1-r0 curl: curl netrc password leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-11053

镜像层: sha256:cd8bfd304e3bf9690cb23bc5b71eb8c0fce09f87c05dffc5c92465ffe55ce34e

发布日期: 2024-12-11 08:15 修改: 2024-12-15 17:15

libcurl CVE-2024-8096 中危 8.9.1-r1 8.10.0-r0 curl: OCSP stapling bypass with GnuTLS

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-8096

镜像层: sha256:cd8bfd304e3bf9690cb23bc5b71eb8c0fce09f87c05dffc5c92465ffe55ce34e

发布日期: 2024-09-11 10:15 修改: 2024-09-11 16:26

libcurl CVE-2024-9681 中危 8.9.1-r1 8.11.0-r0 curl: HSTS subdomain overwrites parent cache entry

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-9681

镜像层: sha256:cd8bfd304e3bf9690cb23bc5b71eb8c0fce09f87c05dffc5c92465ffe55ce34e

发布日期: 2024-11-06 08:15 修改: 2024-12-13 14:15

git CVE-2024-50349 低危 2.40.3-r0 2.40.4-r0 git: Git does not sanitize URLs when asking for credentials interactively

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-50349

镜像层: sha256:cd8bfd304e3bf9690cb23bc5b71eb8c0fce09f87c05dffc5c92465ffe55ce34e

发布日期: 2025-01-14 19:15 修改: 2025-01-14 19:15

usr/local/bin/containerd (gobinary)
低危漏洞:0 中危漏洞:11 高危漏洞:3 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
stdlib CVE-2024-24790 严重 1.20.10 1.21.11, 1.22.4 golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24790

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-06-05 16:15 修改: 2024-09-03 18:35

stdlib CVE-2023-45283 高危 1.20.10 1.20.11, 1.21.4, 1.20.12, 1.21.5 The filepath package does not recognize paths with a \??\ prefix as sp ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45283

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2023-11-09 17:15 修改: 2023-12-14 10:15

stdlib CVE-2023-45288 高危 1.20.10 1.21.9, 1.22.2 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-04-04 21:15 修改: 2024-08-26 21:35

stdlib CVE-2024-34156 高危 1.20.10 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

stdlib CVE-2023-39326 中危 1.20.10 1.20.12, 1.21.5 golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-39326

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2023-12-06 17:15 修改: 2024-01-20 04:15

stdlib CVE-2023-45284 中危 1.20.10 1.20.11, 1.21.4 On Windows, The IsLocal function does not correctly detect reserved de ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45284

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2023-11-09 17:15 修改: 2024-09-03 19:35

stdlib CVE-2023-45289 中危 1.20.10 1.21.8, 1.22.1 golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45289

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-03-05 23:15 修改: 2024-11-04 19:35

stdlib CVE-2023-45290 中危 1.20.10 1.21.8, 1.22.1 golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45290

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-03-05 23:15 修改: 2024-11-07 11:35

stdlib CVE-2024-24783 中危 1.20.10 1.21.8, 1.22.1 golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24783

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-03-05 23:15 修改: 2024-11-05 17:35

stdlib CVE-2024-24784 中危 1.20.10 1.21.8, 1.22.1 golang: net/mail: comments in display names are incorrectly handled

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24784

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-03-05 23:15 修改: 2024-08-05 21:35

stdlib CVE-2024-24785 中危 1.20.10 1.21.8, 1.22.1 golang: html/template: errors returned from MarshalJSON methods may break template escaping

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24785

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-03-05 23:15 修改: 2024-05-01 17:15

stdlib CVE-2024-24789 中危 1.20.10 1.21.11, 1.22.4 golang: archive/zip: Incorrect handling of certain ZIP files

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24789

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-06-05 16:15 修改: 2024-07-03 01:48

stdlib CVE-2024-24791 中危 1.20.10 1.21.12, 1.22.5 net/http: Denial of service due to improper 100-continue handling in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24791

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-07-02 22:15 修改: 2024-07-08 14:17

stdlib CVE-2024-34155 中危 1.20.10 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.20.10 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:26118db45be2486fba77aff54f8d180d7de2563a578f5d8ff118db0b20c5700e

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

usr/local/bin/containerd-shim-runc-v2 (gobinary)
低危漏洞:0 中危漏洞:11 高危漏洞:3 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
stdlib CVE-2024-24790 严重 1.20.10 1.21.11, 1.22.4 golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24790

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-06-05 16:15 修改: 2024-09-03 18:35

stdlib CVE-2023-45283 高危 1.20.10 1.20.11, 1.21.4, 1.20.12, 1.21.5 The filepath package does not recognize paths with a \??\ prefix as sp ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45283

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2023-11-09 17:15 修改: 2023-12-14 10:15

stdlib CVE-2023-45288 高危 1.20.10 1.21.9, 1.22.2 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-04-04 21:15 修改: 2024-08-26 21:35

stdlib CVE-2024-34156 高危 1.20.10 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

stdlib CVE-2023-39326 中危 1.20.10 1.20.12, 1.21.5 golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-39326

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2023-12-06 17:15 修改: 2024-01-20 04:15

stdlib CVE-2023-45284 中危 1.20.10 1.20.11, 1.21.4 On Windows, The IsLocal function does not correctly detect reserved de ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45284

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2023-11-09 17:15 修改: 2024-09-03 19:35

stdlib CVE-2023-45289 中危 1.20.10 1.21.8, 1.22.1 golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45289

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-03-05 23:15 修改: 2024-11-04 19:35

stdlib CVE-2023-45290 中危 1.20.10 1.21.8, 1.22.1 golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45290

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-03-05 23:15 修改: 2024-11-07 11:35

stdlib CVE-2024-24783 中危 1.20.10 1.21.8, 1.22.1 golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24783

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-03-05 23:15 修改: 2024-11-05 17:35

stdlib CVE-2024-24784 中危 1.20.10 1.21.8, 1.22.1 golang: net/mail: comments in display names are incorrectly handled

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24784

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-03-05 23:15 修改: 2024-08-05 21:35

stdlib CVE-2024-24785 中危 1.20.10 1.21.8, 1.22.1 golang: html/template: errors returned from MarshalJSON methods may break template escaping

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24785

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-03-05 23:15 修改: 2024-05-01 17:15

stdlib CVE-2024-24789 中危 1.20.10 1.21.11, 1.22.4 golang: archive/zip: Incorrect handling of certain ZIP files

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24789

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-06-05 16:15 修改: 2024-07-03 01:48

stdlib CVE-2024-24791 中危 1.20.10 1.21.12, 1.22.5 net/http: Denial of service due to improper 100-continue handling in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24791

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-07-02 22:15 修改: 2024-07-08 14:17

stdlib CVE-2024-34155 中危 1.20.10 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.20.10 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:38ecba7330195b7745647d7707f8d70fbb61a8f900f62a21d98985175f18ce16

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

usr/local/bin/ctr (gobinary)
低危漏洞:0 中危漏洞:11 高危漏洞:3 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
stdlib CVE-2024-24790 严重 1.20.10 1.21.11, 1.22.4 golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24790

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-06-05 16:15 修改: 2024-09-03 18:35

stdlib CVE-2023-45283 高危 1.20.10 1.20.11, 1.21.4, 1.20.12, 1.21.5 The filepath package does not recognize paths with a \??\ prefix as sp ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45283

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2023-11-09 17:15 修改: 2023-12-14 10:15

stdlib CVE-2023-45288 高危 1.20.10 1.21.9, 1.22.2 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-04-04 21:15 修改: 2024-08-26 21:35

stdlib CVE-2024-34156 高危 1.20.10 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

stdlib CVE-2023-39326 中危 1.20.10 1.20.12, 1.21.5 golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-39326

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2023-12-06 17:15 修改: 2024-01-20 04:15

stdlib CVE-2023-45284 中危 1.20.10 1.20.11, 1.21.4 On Windows, The IsLocal function does not correctly detect reserved de ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45284

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2023-11-09 17:15 修改: 2024-09-03 19:35

stdlib CVE-2023-45289 中危 1.20.10 1.21.8, 1.22.1 golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45289

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-03-05 23:15 修改: 2024-11-04 19:35

stdlib CVE-2023-45290 中危 1.20.10 1.21.8, 1.22.1 golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45290

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-03-05 23:15 修改: 2024-11-07 11:35

stdlib CVE-2024-24783 中危 1.20.10 1.21.8, 1.22.1 golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24783

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-03-05 23:15 修改: 2024-11-05 17:35

stdlib CVE-2024-24784 中危 1.20.10 1.21.8, 1.22.1 golang: net/mail: comments in display names are incorrectly handled

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24784

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-03-05 23:15 修改: 2024-08-05 21:35

stdlib CVE-2024-24785 中危 1.20.10 1.21.8, 1.22.1 golang: html/template: errors returned from MarshalJSON methods may break template escaping

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24785

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-03-05 23:15 修改: 2024-05-01 17:15

stdlib CVE-2024-24789 中危 1.20.10 1.21.11, 1.22.4 golang: archive/zip: Incorrect handling of certain ZIP files

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24789

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-06-05 16:15 修改: 2024-07-03 01:48

stdlib CVE-2024-24791 中危 1.20.10 1.21.12, 1.22.5 net/http: Denial of service due to improper 100-continue handling in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24791

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-07-02 22:15 修改: 2024-07-08 14:17

stdlib CVE-2024-34155 中危 1.20.10 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.20.10 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:286f803479f2f29196670ab6bec698245911cbcc37b2b024545692208a7aad89

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

usr/local/bin/devpod (gobinary)
低危漏洞:1 中危漏洞:5 高危漏洞:3 严重漏洞:4
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
github.com/docker/docker CVE-2024-41110 严重 v25.0.5+incompatible 23.0.15, 26.1.5, 27.1.1, 25.0.6 moby: Authz zero length regression

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41110

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-07-24 17:15 修改: 2024-07-30 20:15

github.com/moby/buildkit CVE-2024-23652 严重 v0.11.6 0.12.5 moby/buildkit: possible host system access from mount stub cleaner

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23652

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:44

github.com/moby/buildkit CVE-2024-23653 严重 v0.11.6 0.12.5 moby/buildkit: Buildkit's interactive containers API does not validate entitlements check

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23653

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:44

golang.org/x/crypto CVE-2024-45337 严重 v0.27.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45337

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-12-12 02:02 修改: 2024-12-12 21:15

github.com/moby/buildkit CVE-2024-23651 高危 v0.11.6 0.12.5 moby/buildkit: possible race condition with accessing subpaths from cache mounts

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23651

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:43

golang.org/x/net CVE-2024-45338 高危 v0.29.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-12-18 21:15 修改: 2024-12-31 20:16

stdlib CVE-2024-34156 高危 1.22.5 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

github.com/moby/buildkit CVE-2024-23650 中危 v0.11.6 0.12.5 moby/buildkit: Possible race condition with accessing subpaths from cache mounts

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23650

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:38

gopkg.in/square/go-jose.v2 CVE-2024-28180 中危 v2.6.0 jose-go: improper handling of highly compressed data

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-28180

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-03-09 01:15 修改: 2024-06-12 02:15

github.com/containerd/containerd GHSA-7ww5-4wqc-m92c 中危 v1.6.20 1.6.26, 1.7.11 containerd allows RAPL to be accessible to a container

漏洞详情: https://github.com/advisories/GHSA-7ww5-4wqc-m92c

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

stdlib CVE-2024-34155 中危 1.22.5 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.22.5 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

github.com/golang-jwt/jwt/v4 CVE-2024-51744 低危 v4.5.0 4.5.1 golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-51744

镜像层: sha256:06e6f80100a6c10f7f89fe207fbd5822e0644caca9df357e59352d903b703bd5

发布日期: 2024-11-04 22:15 修改: 2024-11-05 16:04

usr/local/bin/docker (gobinary)
低危漏洞:0 中危漏洞:11 高危漏洞:3 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
stdlib CVE-2024-24790 严重 1.20.10 1.21.11, 1.22.4 golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24790

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-06-05 16:15 修改: 2024-09-03 18:35

stdlib CVE-2023-45283 高危 1.20.10 1.20.11, 1.21.4, 1.20.12, 1.21.5 The filepath package does not recognize paths with a \??\ prefix as sp ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45283

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2023-11-09 17:15 修改: 2023-12-14 10:15

stdlib CVE-2023-45288 高危 1.20.10 1.21.9, 1.22.2 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-04-04 21:15 修改: 2024-08-26 21:35

stdlib CVE-2024-34156 高危 1.20.10 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

stdlib CVE-2023-39326 中危 1.20.10 1.20.12, 1.21.5 golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-39326

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2023-12-06 17:15 修改: 2024-01-20 04:15

stdlib CVE-2023-45284 中危 1.20.10 1.20.11, 1.21.4 On Windows, The IsLocal function does not correctly detect reserved de ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45284

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2023-11-09 17:15 修改: 2024-09-03 19:35

stdlib CVE-2023-45289 中危 1.20.10 1.21.8, 1.22.1 golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45289

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-03-05 23:15 修改: 2024-11-04 19:35

stdlib CVE-2023-45290 中危 1.20.10 1.21.8, 1.22.1 golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45290

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-03-05 23:15 修改: 2024-11-07 11:35

stdlib CVE-2024-24783 中危 1.20.10 1.21.8, 1.22.1 golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24783

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-03-05 23:15 修改: 2024-11-05 17:35

stdlib CVE-2024-24784 中危 1.20.10 1.21.8, 1.22.1 golang: net/mail: comments in display names are incorrectly handled

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24784

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-03-05 23:15 修改: 2024-08-05 21:35

stdlib CVE-2024-24785 中危 1.20.10 1.21.8, 1.22.1 golang: html/template: errors returned from MarshalJSON methods may break template escaping

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24785

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-03-05 23:15 修改: 2024-05-01 17:15

stdlib CVE-2024-24789 中危 1.20.10 1.21.11, 1.22.4 golang: archive/zip: Incorrect handling of certain ZIP files

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24789

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-06-05 16:15 修改: 2024-07-03 01:48

stdlib CVE-2024-24791 中危 1.20.10 1.21.12, 1.22.5 net/http: Denial of service due to improper 100-continue handling in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24791

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-07-02 22:15 修改: 2024-07-08 14:17

stdlib CVE-2024-34155 中危 1.20.10 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.20.10 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:c02e3ce859706443d3b536b2fdb504572ede2fc5eac0d1bec84ef6bb23e8131a

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

usr/local/bin/docker-proxy (gobinary)
低危漏洞:0 中危漏洞:12 高危漏洞:3 严重漏洞:2
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
github.com/docker/docker CVE-2024-41110 严重 24.0.7 23.0.15, 26.1.5, 27.1.1, 25.0.6 moby: Authz zero length regression

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41110

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-07-24 17:15 修改: 2024-07-30 20:15

stdlib CVE-2024-24790 严重 1.20.10 1.21.11, 1.22.4 golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24790

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-06-05 16:15 修改: 2024-09-03 18:35

stdlib CVE-2023-45283 高危 1.20.10 1.20.11, 1.21.4, 1.20.12, 1.21.5 The filepath package does not recognize paths with a \??\ prefix as sp ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45283

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2023-11-09 17:15 修改: 2023-12-14 10:15

stdlib CVE-2023-45288 高危 1.20.10 1.21.9, 1.22.2 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-04-04 21:15 修改: 2024-08-26 21:35

stdlib CVE-2024-34156 高危 1.20.10 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

github.com/docker/docker CVE-2024-24557 中危 24.0.7 24.0.9, 25.0.2 moby: classic builder cache poisoning

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24557

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-02-01 17:15 修改: 2024-02-09 20:21

stdlib CVE-2023-39326 中危 1.20.10 1.20.12, 1.21.5 golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-39326

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2023-12-06 17:15 修改: 2024-01-20 04:15

stdlib CVE-2023-45284 中危 1.20.10 1.20.11, 1.21.4 On Windows, The IsLocal function does not correctly detect reserved de ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45284

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2023-11-09 17:15 修改: 2024-09-03 19:35

stdlib CVE-2023-45289 中危 1.20.10 1.21.8, 1.22.1 golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45289

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-03-05 23:15 修改: 2024-11-04 19:35

stdlib CVE-2023-45290 中危 1.20.10 1.21.8, 1.22.1 golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45290

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-03-05 23:15 修改: 2024-11-07 11:35

stdlib CVE-2024-24783 中危 1.20.10 1.21.8, 1.22.1 golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24783

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-03-05 23:15 修改: 2024-11-05 17:35

stdlib CVE-2024-24784 中危 1.20.10 1.21.8, 1.22.1 golang: net/mail: comments in display names are incorrectly handled

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24784

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-03-05 23:15 修改: 2024-08-05 21:35

stdlib CVE-2024-24785 中危 1.20.10 1.21.8, 1.22.1 golang: html/template: errors returned from MarshalJSON methods may break template escaping

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24785

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-03-05 23:15 修改: 2024-05-01 17:15

stdlib CVE-2024-24789 中危 1.20.10 1.21.11, 1.22.4 golang: archive/zip: Incorrect handling of certain ZIP files

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24789

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-06-05 16:15 修改: 2024-07-03 01:48

stdlib CVE-2024-24791 中危 1.20.10 1.21.12, 1.22.5 net/http: Denial of service due to improper 100-continue handling in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24791

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-07-02 22:15 修改: 2024-07-08 14:17

stdlib CVE-2024-34155 中危 1.20.10 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.20.10 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:622d09e765e7cb83326b82780432b59aabde4696001eee045a36be0d97a0be7c

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

usr/local/bin/dockerd (gobinary)
低危漏洞:1 中危漏洞:20 高危漏洞:10 严重漏洞:5
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
github.com/docker/docker CVE-2024-41110 严重 24.0.7 23.0.15, 26.1.5, 27.1.1, 25.0.6 moby: Authz zero length regression

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41110

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-07-24 17:15 修改: 2024-07-30 20:15

github.com/moby/buildkit CVE-2024-23652 严重 v0.11.7-0.20230908085316-d3e6c1360f6e 0.12.5 moby/buildkit: possible host system access from mount stub cleaner

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23652

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:44

github.com/moby/buildkit CVE-2024-23653 严重 v0.11.7-0.20230908085316-d3e6c1360f6e 0.12.5 moby/buildkit: Buildkit's interactive containers API does not validate entitlements check

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23653

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:44

golang.org/x/crypto CVE-2024-45337 严重 v0.14.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45337

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-12-12 02:02 修改: 2024-12-12 21:15

stdlib CVE-2024-24790 严重 1.20.10 1.21.11, 1.22.4 golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24790

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-06-05 16:15 修改: 2024-09-03 18:35

go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc CVE-2023-47108 高危 v0.29.0 0.46.0 opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-47108

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2023-11-10 19:15 修改: 2023-11-20 19:34

go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace CVE-2023-45142 高危 v0.29.0 0.44.0 opentelemetry: DoS vulnerability in otelhttp

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45142

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2023-10-12 17:15 修改: 2024-02-19 03:15

go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp CVE-2023-45142 高危 v0.29.0 0.44.0 opentelemetry: DoS vulnerability in otelhttp

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45142

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2023-10-12 17:15 修改: 2024-02-19 03:15

github.com/moby/buildkit CVE-2024-23651 高危 v0.11.7-0.20230908085316-d3e6c1360f6e 0.12.5 moby/buildkit: possible race condition with accessing subpaths from cache mounts

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23651

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:43

golang.org/x/net CVE-2024-45338 高危 v0.17.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-12-18 21:15 修改: 2024-12-31 20:16

google.golang.org/grpc GHSA-m425-mq94-257g 高危 v1.50.1 1.56.3, 1.57.1, 1.58.3 gRPC-Go HTTP/2 Rapid Reset vulnerability

漏洞详情: https://github.com/advisories/GHSA-m425-mq94-257g

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

github.com/opencontainers/runc CVE-2024-21626 高危 v1.1.7 1.1.12 runc: file descriptor leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-21626

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-01-31 22:15 修改: 2024-02-19 03:15

stdlib CVE-2023-45283 高危 1.20.10 1.20.11, 1.21.4, 1.20.12, 1.21.5 The filepath package does not recognize paths with a \??\ prefix as sp ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45283

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2023-11-09 17:15 修改: 2023-12-14 10:15

stdlib CVE-2023-45288 高危 1.20.10 1.21.9, 1.22.2 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-04-04 21:15 修改: 2024-08-26 21:35

stdlib CVE-2024-34156 高危 1.20.10 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

github.com/opencontainers/runc CVE-2024-45310 中危 v1.1.7 1.1.14, 1.2.0-rc.3 runc: runc can be tricked into creating empty files/directories on host

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45310

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-09-03 19:15 修改: 2024-09-03 19:40

golang.org/x/net CVE-2023-45288 中危 v0.17.0 0.23.0 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-04-04 21:15 修改: 2024-08-26 21:35

github.com/containerd/containerd GHSA-7ww5-4wqc-m92c 中危 v1.6.22 1.6.26, 1.7.11 containerd allows RAPL to be accessible to a container

漏洞详情: https://github.com/advisories/GHSA-7ww5-4wqc-m92c

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

google.golang.org/grpc CVE-2023-44487 中危 v1.50.1 1.58.3, 1.57.1, 1.56.3 HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-44487

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2023-10-10 14:15 修改: 2024-12-20 17:40

google.golang.org/protobuf CVE-2024-24786 中危 v1.28.1 1.33.0 golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24786

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-03-05 23:15 修改: 2024-11-07 17:35

github.com/docker/docker CVE-2024-24557 中危 24.0.7 24.0.9, 25.0.2 moby: classic builder cache poisoning

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24557

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-02-01 17:15 修改: 2024-02-09 20:21

github.com/moby/buildkit CVE-2024-23650 中危 v0.11.7-0.20230908085316-d3e6c1360f6e 0.12.5 moby/buildkit: Possible race condition with accessing subpaths from cache mounts

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23650

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:38

github.com/cyphar/filepath-securejoin GHSA-6xv5-86q9-7xr8 中危 v0.2.3 0.2.4 SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced

漏洞详情: https://github.com/advisories/GHSA-6xv5-86q9-7xr8

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

golang.org/x/crypto CVE-2023-48795 中危 v0.14.0 0.17.0 ssh: Prefix truncation attack on Binary Packet Protocol (BPP)

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-48795

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2023-12-18 16:15 修改: 2024-12-02 14:54

stdlib CVE-2023-39326 中危 1.20.10 1.20.12, 1.21.5 golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-39326

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2023-12-06 17:15 修改: 2024-01-20 04:15

stdlib CVE-2023-45284 中危 1.20.10 1.20.11, 1.21.4 On Windows, The IsLocal function does not correctly detect reserved de ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45284

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2023-11-09 17:15 修改: 2024-09-03 19:35

stdlib CVE-2023-45289 中危 1.20.10 1.21.8, 1.22.1 golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45289

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-03-05 23:15 修改: 2024-11-04 19:35

stdlib CVE-2023-45290 中危 1.20.10 1.21.8, 1.22.1 golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45290

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-03-05 23:15 修改: 2024-11-07 11:35

stdlib CVE-2024-24783 中危 1.20.10 1.21.8, 1.22.1 golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24783

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-03-05 23:15 修改: 2024-11-05 17:35

stdlib CVE-2024-24784 中危 1.20.10 1.21.8, 1.22.1 golang: net/mail: comments in display names are incorrectly handled

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24784

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-03-05 23:15 修改: 2024-08-05 21:35

stdlib CVE-2024-24785 中危 1.20.10 1.21.8, 1.22.1 golang: html/template: errors returned from MarshalJSON methods may break template escaping

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24785

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-03-05 23:15 修改: 2024-05-01 17:15

stdlib CVE-2024-24789 中危 1.20.10 1.21.11, 1.22.4 golang: archive/zip: Incorrect handling of certain ZIP files

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24789

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-06-05 16:15 修改: 2024-07-03 01:48

stdlib CVE-2024-24791 中危 1.20.10 1.21.12, 1.22.5 net/http: Denial of service due to improper 100-continue handling in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24791

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-07-02 22:15 修改: 2024-07-08 14:17

stdlib CVE-2024-34155 中危 1.20.10 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.20.10 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

github.com/golang-jwt/jwt/v4 CVE-2024-51744 低危 v4.4.2 4.5.1 golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-51744

镜像层: sha256:24dd6d9cc8027a98118ddf4eedc7ac700c57190cf3e0ec36f4aa5c679d2e7766

发布日期: 2024-11-04 22:15 修改: 2024-11-05 16:04

usr/local/bin/helm (gobinary)
低危漏洞:0 中危漏洞:12 高危漏洞:3 严重漏洞:3
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
github.com/docker/docker CVE-2024-41110 严重 v24.0.7+incompatible 23.0.15, 26.1.5, 27.1.1, 25.0.6 moby: Authz zero length regression

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41110

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-07-24 17:15 修改: 2024-07-30 20:15

golang.org/x/crypto CVE-2024-45337 严重 v0.17.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45337

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-12-12 02:02 修改: 2024-12-12 21:15

stdlib CVE-2024-24790 严重 1.21.6 1.21.11, 1.22.4 golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24790

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-06-05 16:15 修改: 2024-09-03 18:35

golang.org/x/net CVE-2024-45338 高危 v0.17.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-12-18 21:15 修改: 2024-12-31 20:16

stdlib CVE-2023-45288 高危 1.21.6 1.21.9, 1.22.2 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-04-04 21:15 修改: 2024-08-26 21:35

stdlib CVE-2024-34156 高危 1.21.6 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

github.com/docker/docker CVE-2024-24557 中危 v24.0.7+incompatible 24.0.9, 25.0.2 moby: classic builder cache poisoning

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24557

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-02-01 17:15 修改: 2024-02-09 20:21

golang.org/x/net CVE-2023-45288 中危 v0.17.0 0.23.0 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-04-04 21:15 修改: 2024-08-26 21:35

google.golang.org/protobuf CVE-2024-24786 中危 v1.31.0 1.33.0 golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24786

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-03-05 23:15 修改: 2024-11-07 17:35

stdlib CVE-2023-45289 中危 1.21.6 1.21.8, 1.22.1 golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45289

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-03-05 23:15 修改: 2024-11-04 19:35

stdlib CVE-2023-45290 中危 1.21.6 1.21.8, 1.22.1 golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45290

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-03-05 23:15 修改: 2024-11-07 11:35

stdlib CVE-2024-24783 中危 1.21.6 1.21.8, 1.22.1 golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24783

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-03-05 23:15 修改: 2024-11-05 17:35

stdlib CVE-2024-24784 中危 1.21.6 1.21.8, 1.22.1 golang: net/mail: comments in display names are incorrectly handled

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24784

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-03-05 23:15 修改: 2024-08-05 21:35

stdlib CVE-2024-24785 中危 1.21.6 1.21.8, 1.22.1 golang: html/template: errors returned from MarshalJSON methods may break template escaping

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24785

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-03-05 23:15 修改: 2024-05-01 17:15

stdlib CVE-2024-24789 中危 1.21.6 1.21.11, 1.22.4 golang: archive/zip: Incorrect handling of certain ZIP files

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24789

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-06-05 16:15 修改: 2024-07-03 01:48

stdlib CVE-2024-24791 中危 1.21.6 1.21.12, 1.22.5 net/http: Denial of service due to improper 100-continue handling in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24791

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-07-02 22:15 修改: 2024-07-08 14:17

stdlib CVE-2024-34155 中危 1.21.6 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.21.6 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:5f5203d2d25822107d228c71232b461649281a15fd845961b2755ba2bb634f01

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

usr/local/bin/kine (gobinary)
低危漏洞:0 中危漏洞:0 高危漏洞:1 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
golang.org/x/crypto CVE-2024-45337 严重 v0.27.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45337

镜像层: sha256:c3cfe8e0af17ef4f4bc3850e7a55caa4868b068312a005cdd913b83540abc3c8

发布日期: 2024-12-12 02:02 修改: 2024-12-12 21:15

golang.org/x/net CVE-2024-45338 高危 v0.29.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:c3cfe8e0af17ef4f4bc3850e7a55caa4868b068312a005cdd913b83540abc3c8

发布日期: 2024-12-18 21:15 修改: 2024-12-31 20:16

usr/local/bin/kube-apiserver (gobinary)
低危漏洞:0 中危漏洞:3 高危漏洞:3 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
golang.org/x/crypto CVE-2024-45337 严重 v0.21.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45337

镜像层: sha256:5b1454075d25e68f04e5f1dbaad8840614d65a66ec469c614f58ac521b9ec32f

发布日期: 2024-12-12 02:02 修改: 2024-12-12 21:15

go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc CVE-2023-47108 高危 v0.42.0 0.46.0 opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-47108

镜像层: sha256:5b1454075d25e68f04e5f1dbaad8840614d65a66ec469c614f58ac521b9ec32f

发布日期: 2023-11-10 19:15 修改: 2023-11-20 19:34

golang.org/x/net CVE-2024-45338 高危 v0.23.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:5b1454075d25e68f04e5f1dbaad8840614d65a66ec469c614f58ac521b9ec32f

发布日期: 2024-12-18 21:15 修改: 2024-12-31 20:16

stdlib CVE-2024-34156 高危 1.22.5 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:5b1454075d25e68f04e5f1dbaad8840614d65a66ec469c614f58ac521b9ec32f

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

gopkg.in/square/go-jose.v2 CVE-2024-28180 中危 v2.6.0 jose-go: improper handling of highly compressed data

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-28180

镜像层: sha256:5b1454075d25e68f04e5f1dbaad8840614d65a66ec469c614f58ac521b9ec32f

发布日期: 2024-03-09 01:15 修改: 2024-06-12 02:15

stdlib CVE-2024-34155 中危 1.22.5 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:5b1454075d25e68f04e5f1dbaad8840614d65a66ec469c614f58ac521b9ec32f

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.22.5 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:5b1454075d25e68f04e5f1dbaad8840614d65a66ec469c614f58ac521b9ec32f

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

usr/local/bin/kube-controller-manager (gobinary)
低危漏洞:0 中危漏洞:4 高危漏洞:3 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
golang.org/x/crypto CVE-2024-45337 严重 v0.21.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45337

镜像层: sha256:5c9bf2501a248fc80d98896f4c8e5cec5cda624c79c670ef6caa5955b8774c96

发布日期: 2024-12-12 02:02 修改: 2024-12-12 21:15

go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc CVE-2023-47108 高危 v0.42.0 0.46.0 opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-47108

镜像层: sha256:5c9bf2501a248fc80d98896f4c8e5cec5cda624c79c670ef6caa5955b8774c96

发布日期: 2023-11-10 19:15 修改: 2023-11-20 19:34

golang.org/x/net CVE-2024-45338 高危 v0.23.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:5c9bf2501a248fc80d98896f4c8e5cec5cda624c79c670ef6caa5955b8774c96

发布日期: 2024-12-18 21:15 修改: 2024-12-31 20:16

stdlib CVE-2024-34156 高危 1.22.5 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:5c9bf2501a248fc80d98896f4c8e5cec5cda624c79c670ef6caa5955b8774c96

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

gopkg.in/square/go-jose.v2 CVE-2024-28180 中危 v2.6.0 jose-go: improper handling of highly compressed data

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-28180

镜像层: sha256:5c9bf2501a248fc80d98896f4c8e5cec5cda624c79c670ef6caa5955b8774c96

发布日期: 2024-03-09 01:15 修改: 2024-06-12 02:15

github.com/opencontainers/runc CVE-2024-45310 中危 v1.1.12 1.1.14, 1.2.0-rc.3 runc: runc can be tricked into creating empty files/directories on host

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45310

镜像层: sha256:5c9bf2501a248fc80d98896f4c8e5cec5cda624c79c670ef6caa5955b8774c96

发布日期: 2024-09-03 19:15 修改: 2024-09-03 19:40

stdlib CVE-2024-34155 中危 1.22.5 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:5c9bf2501a248fc80d98896f4c8e5cec5cda624c79c670ef6caa5955b8774c96

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.22.5 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:5c9bf2501a248fc80d98896f4c8e5cec5cda624c79c670ef6caa5955b8774c96

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

usr/local/bin/kubectl (gobinary)
低危漏洞:0 中危漏洞:2 高危漏洞:2 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
golang.org/x/net CVE-2024-45338 高危 v0.26.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:f84724cfc8d27c33f8849003333f2b0021dd2733a028082092336cb64695064a

发布日期: 2024-12-18 21:15 修改: 2024-12-31 20:16

stdlib CVE-2024-34156 高危 1.22.5 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:f84724cfc8d27c33f8849003333f2b0021dd2733a028082092336cb64695064a

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

stdlib CVE-2024-34155 中危 1.22.5 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:f84724cfc8d27c33f8849003333f2b0021dd2733a028082092336cb64695064a

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.22.5 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:f84724cfc8d27c33f8849003333f2b0021dd2733a028082092336cb64695064a

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35

usr/local/bin/loft (gobinary)
低危漏洞:0 中危漏洞:2 高危漏洞:2 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
golang.org/x/crypto CVE-2024-45337 严重 v0.27.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45337

镜像层: sha256:300726913e5089de884625ffab253ff835ae5187c78a9bdd21c26d168898ee85

发布日期: 2024-12-12 02:02 修改: 2024-12-12 21:15

github.com/gorilla/schema CVE-2024-37298 高危 v1.2.0 1.4.1 gorilla/schema: Potential memory exhaustion attack due to sparse slice deserialization

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-37298

镜像层: sha256:300726913e5089de884625ffab253ff835ae5187c78a9bdd21c26d168898ee85

发布日期: 2024-07-01 19:15 修改: 2024-07-02 12:09

golang.org/x/net CVE-2024-45338 高危 v0.29.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45338

镜像层: sha256:300726913e5089de884625ffab253ff835ae5187c78a9bdd21c26d168898ee85

发布日期: 2024-12-18 21:15 修改: 2024-12-31 20:16

github.com/go-jose/go-jose/v3 CVE-2024-28180 中危 v3.0.1 3.0.3 jose-go: improper handling of highly compressed data

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-28180

镜像层: sha256:300726913e5089de884625ffab253ff835ae5187c78a9bdd21c26d168898ee85

发布日期: 2024-03-09 01:15 修改: 2024-06-12 02:15

gopkg.in/square/go-jose.v2 CVE-2024-28180 中危 v2.6.0 jose-go: improper handling of highly compressed data

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-28180

镜像层: sha256:300726913e5089de884625ffab253ff835ae5187c78a9bdd21c26d168898ee85

发布日期: 2024-03-09 01:15 修改: 2024-06-12 02:15

usr/local/bin/runc (gobinary)
低危漏洞:0 中危漏洞:11 高危漏洞:3 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
stdlib CVE-2024-24790 严重 1.20.10 1.21.11, 1.22.4 golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24790

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-06-05 16:15 修改: 2024-09-03 18:35

stdlib CVE-2023-45283 高危 1.20.10 1.20.11, 1.21.4, 1.20.12, 1.21.5 The filepath package does not recognize paths with a \??\ prefix as sp ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45283

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2023-11-09 17:15 修改: 2023-12-14 10:15

stdlib CVE-2023-45288 高危 1.20.10 1.21.9, 1.22.2 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-04-04 21:15 修改: 2024-08-26 21:35

stdlib CVE-2024-34156 高危 1.20.10 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-09-06 21:15 修改: 2024-09-09 15:35

stdlib CVE-2023-39326 中危 1.20.10 1.20.12, 1.21.5 golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-39326

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2023-12-06 17:15 修改: 2024-01-20 04:15

stdlib CVE-2023-45284 中危 1.20.10 1.20.11, 1.21.4 On Windows, The IsLocal function does not correctly detect reserved de ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45284

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2023-11-09 17:15 修改: 2024-09-03 19:35

stdlib CVE-2023-45289 中危 1.20.10 1.21.8, 1.22.1 golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45289

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-03-05 23:15 修改: 2024-11-04 19:35

stdlib CVE-2023-45290 中危 1.20.10 1.21.8, 1.22.1 golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45290

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-03-05 23:15 修改: 2024-11-07 11:35

stdlib CVE-2024-24783 中危 1.20.10 1.21.8, 1.22.1 golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24783

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-03-05 23:15 修改: 2024-11-05 17:35

stdlib CVE-2024-24784 中危 1.20.10 1.21.8, 1.22.1 golang: net/mail: comments in display names are incorrectly handled

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24784

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-03-05 23:15 修改: 2024-08-05 21:35

stdlib CVE-2024-24785 中危 1.20.10 1.21.8, 1.22.1 golang: html/template: errors returned from MarshalJSON methods may break template escaping

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24785

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-03-05 23:15 修改: 2024-05-01 17:15

stdlib CVE-2024-24789 中危 1.20.10 1.21.11, 1.22.4 golang: archive/zip: Incorrect handling of certain ZIP files

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24789

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-06-05 16:15 修改: 2024-07-03 01:48

stdlib CVE-2024-24791 中危 1.20.10 1.21.12, 1.22.5 net/http: Denial of service due to improper 100-continue handling in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24791

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-07-02 22:15 修改: 2024-07-08 14:17

stdlib CVE-2024-34155 中危 1.20.10 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-09-06 21:15 修改: 2024-11-04 17:35

stdlib CVE-2024-34158 中危 1.20.10 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:bb819376a9bb7132ef5f5f807f2ea0bd019a00a502ff4cfc117c987c10798406

发布日期: 2024-09-06 21:15 修改: 2024-09-09 14:35