Msrc Cbl2 Reaper 3.1.1-19 On Cbl Mariner 2.0 vulnerabilities

12 known vulnerabilities affecting msrc/cbl2_reaper_3.1.1-19_on_cbl_mariner_2.0.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM4LOW2

Vulnerabilities

Page 1 of 1
CVE-2025-66031HIGHCVSS 8.72025-11-11
CVE-2025-66031 [HIGH] CWE-674 node-forge ASN.1 Unbounded Recursion node-forge ASN.1 Unbounded Recursion Mariner: Mariner GitHub_M: GitHub_M Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-12816HIGHCVSS 8.62025-11-11
CVE-2025-12816 [HIGH] CWE-436 CVE-2025-12816: CVE-2025-12816 Mariner: Mariner certcc: certcc Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn CVE-2025-12816 Mariner: Mariner certcc: certcc Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-66030MEDIUMCVSS 6.32025-11-11
CVE-2025-66030 [MEDIUM] CWE-190 node-forge ASN.1 OID Integer Truncation node-forge ASN.1 OID Integer Truncation Mariner: Mariner GitHub_M: GitHub_M Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-9288HIGHCVSS 7.72025-08-12
CVE-2025-9288 [CRITICAL] CWE-20 Missing type checks leading to hash rewind and passing on crafted data Missing type checks leading to hash rewind and passing on crafted data FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the op
msrc
CVE-2025-7783CRITICALCVSS 9.42025-07-08
CVE-2025-7783 [CRITICAL] CWE-330 Usage of unsafe random function in form-data for choosing boundary Usage of unsafe random function in form-data for choosing boundary FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open sour
msrc
CVE-2025-7339LOWCVSS 3.42025-07-08
CVE-2025-7339 [LOW] CWE-241 on-headers vulnerable to http response header manipulation on-headers vulnerable to http response header manipulation FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with whi
msrc
CVE-2025-48387HIGHCVSS 8.22025-06-10
CVE-2025-48387 [HIGH] CWE-22 tar-fs has issue where extract can write outside the specified dir with a specific tarball tar-fs has issue where extract can write outside the specified dir with a specific tarball FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most rece
msrc
CVE-2025-5889LOWCVSS 3.12025-06-10
CVE-2025-5889 [LOW] CWE-1333 juliangruber brace-expansion index.js expand redos juliangruber brace-expansion index.js expand redos FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro i
msrc
CVE-2024-6485MEDIUMCVSS 6.42024-07-09
CVE-2024-6485 [MEDIUM] CWE-79 XSS in Bootstrap button component XSS in Bootstrap button component Mariner: Mariner HeroDevs: HeroDevs Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2021-23445MEDIUMCVSS 6.12021-09-14
CVE-2021-23445 [LOW] CWE-79 Cross-site Scripting (XSS) Cross-site Scripting (XSS) FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparenc
msrc
CVE-2018-19827HIGHCVSS 8.82018-12-11
CVE-2018-19827 [HIGH] CWE-416 In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that may cause a denial of service (application crash) or possibly have unspecified o In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that may cause a denial of service (application crash) or possibly have unspecified other impact. Mariner: Mariner mitre: mitre Customer Action Require
msrc
CVE-2018-19797MEDIUMCVSS 6.52018-12-11
CVE-2018-19797 [MEDIUM] CWE-476 In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a Denial of Service (application c In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a Denial of Service (application crash) via a crafted sass input file. Mariner: Mariner mitre: mitr
msrc