Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Report: Image Vulnerabilities #1958

Closed
github-actions bot opened this issue Sep 1, 2024 · 0 comments
Closed

Security Report: Image Vulnerabilities #1958

github-actions bot opened this issue Sep 1, 2024 · 0 comments
Labels
frontend Indicates frontend related issue or feature security

Comments

@github-actions
Copy link

github-actions bot commented Sep 1, 2024

Last scan date

10/15/2024

Present Vulnerabilities

Vulnerability IDPkgNameTitleSeverityStatusFixed VersionPublished DateAffectsLinks
CVE-2024-6655gtk-update-icon-cachegtk3: gtk2: Library injection from CWDHIGHfixed3.24.38-2~deb12u22024-07-16T15:15:12.597Z
  • e2e-test
    CVE-2024-32002gitgit: Recursive clones RCECRITICALfixed1:2.39.5-0+deb12u12024-05-14T19:15:10.81Z
    • e2e-test
    • e2e-test
    CVE-2023-25652gitgit: by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contentsHIGHfixed1:2.39.5-0+deb12u12023-04-25T20:15:09.933Z
    • e2e-test
    • e2e-test
    CVE-2023-29007gitgit: arbitrary configuration injection when renaming or deleting a section from a configuration fileHIGHfixed1:2.39.5-0+deb12u12023-04-25T21:15:10.403Z
    • e2e-test
    • e2e-test
    CVE-2024-32004gitgit: RCE while cloning local reposHIGHfixed1:2.39.5-0+deb12u12024-05-14T19:15:11.377Z
    • e2e-test
    • e2e-test
    CVE-2024-32465gitgit: additional local RCEHIGHfixed1:2.39.5-0+deb12u12024-05-14T20:15:14.54Z
    • e2e-test
    • e2e-test
    CVE-2024-45490libexpat1libexpat: Negative Length Parsing Vulnerability in libexpatCRITICALfixed2.5.0-1+deb12u12024-08-30T03:15:03.757Z
    • e2e-test
      CVE-2024-45491libexpat1libexpat: Integer Overflow or WraparoundCRITICALfixed2.5.0-1+deb12u12024-08-30T03:15:03.85Z
      • e2e-test
        CVE-2024-45492libexpat1libexpat: integer overflowCRITICALfixed2.5.0-1+deb12u12024-08-30T03:15:03.93Z
        • e2e-test
          CVE-2024-47175libcups2cups: libppd: remote command injection via attacker controlled data in PPD fileHIGHfixed2.4.2-3+deb12u82024-09-26T22:15:04.283Z
          • e2e-test
          @issuelabeler issuelabeler bot added the frontend Indicates frontend related issue or feature label Sep 6, 2024
          @galethil galethil added this to the Trubudget 2.17.0 milestone Nov 8, 2024
          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
          Labels
          frontend Indicates frontend related issue or feature security
          Projects
          Development

          No branches or pull requests

          1 participant