Vulnerability Description
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl version 0.1.4 should upgrade to anchorectl version 0.1.5 to resolve this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Anchore | Anchore | < 4.0.1 |
| Anchore | Anchorectl | < 0.1.5 |
Related Weaknesses (CWE)
References
- https://docs.anchore.com/current/docs/releasenotes/401/Release NotesVendor Advisory
- https://docs.anchore.com/current/docs/releasenotes/401/Release NotesVendor Advisory
FAQ
What is CVE-2022-1766?
CVE-2022-1766 is a vulnerability with a CVSS score of 7.5 (HIGH). Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the...
How severe is CVE-2022-1766?
CVE-2022-1766 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1766?
Check the references section above for vendor advisories and patch information. Affected products include: Anchore Anchore, Anchore Anchorectl.