Msrc Azl3 Moby-Engine 25.0.3-1 vulnerabilities
4 known vulnerabilities affecting msrc/azl3_moby-engine_25.0.3-1.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2022-41717MEDIUMCVSS 5.32022-12-13
CVE-2022-41717 [MEDIUM] CWE-770 Excessive memory growth in net/http and golang.org/x/net/http2
Excessive memory growth in net/http and golang.org/x/net/http2
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librar
msrc
CVE-2022-29526MEDIUMCVSS 5.32022-06-14
CVE-2022-29526 [MEDIUM] CWE-269 Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter the Faccessat function could incorrectly report that a file is accessible.
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter the Faccessat function could incorrectly report that a file is accessible.
FAQ: Is Azure Linux the only Microsoft product that includes this open-
msrc
CVE-2022-21698HIGHCVSS 7.52022-02-08
CVE-2022-21698 [HIGH] CWE-770 Uncontrolled Resource Consumption in promhttp
Uncontrolled Resource Consumption in promhttp
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compose
msrc
CVE-2021-44716HIGHCVSS 7.52022-01-11
CVE-2021-44716 [HIGH] CWE-400 net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main be
msrc