cbcvebase.
CVE-2024-36127
published 2024-06-03

CVE-2024-36127: apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed…

PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.44%
35.8th percentile
apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.

Affected

2 ranges
VendorProductVersion rangeFixed in
chainguard-devapko< 0.14.50.14.5
chainguard.devapko>= 0 < 0.14.50.14.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.