Vulnerability Description
apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/chainguard-dev/apko/commit/2c0533e4d52e83031a04f6a83ec63fc2a1
- https://github.com/chainguard-dev/apko/security/advisories/GHSA-v6mg-7f7p-qmqp
- https://github.com/chainguard-dev/apko/commit/2c0533e4d52e83031a04f6a83ec63fc2a1
- https://github.com/chainguard-dev/apko/security/advisories/GHSA-v6mg-7f7p-qmqp
FAQ
What is CVE-2024-36127?
CVE-2024-36127 is a vulnerability with a CVSS score of 7.5 (HIGH). apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.
How severe is CVE-2024-36127?
CVE-2024-36127 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-36127?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.