Github.Com Quay Claircore vulnerabilities
2 known vulnerabilities affecting github.com/quay_claircore.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-3762P2HIGH≥ 0, < 0.4.8≥ 1.0.0, < 1.1.0+1 more2022-03-04
CVE-2021-3762 [HIGH] CWE-22 Path traversal in claircore
Path traversal in claircore
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
ghsaosv
CVE-2026-10517P3MEDIUM≥ 0, ≤ 1.5.522026-06-01
CVE-2026-10517 [MEDIUM] CWE-918 Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or scheme filtering. When PSK authentication is not configured (opt-
ghsa