Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Remove target k #2356

Merged
merged 4 commits into from
Jan 1, 2024
Merged

Remove target k #2356

merged 4 commits into from
Jan 1, 2024

Conversation

nicholasdille
Copy link
Contributor

No description provided.

@nicholasdille nicholasdille merged commit 4338de8 into main Jan 1, 2024
83 checks passed
@nicholasdille nicholasdille deleted the remove-target-k branch January 1, 2024 22:10
Copy link

github-actions bot commented Jan 1, 2024

🔍 Vulnerabilities of ghcr.io/uniget-org/tools/keyoxide:0.4.4

📦 Image Reference ghcr.io/uniget-org/tools/keyoxide:0.4.4
digestsha256:005800e981d0ae7adf0da4a22e81e2ded1e40133dda70c7c26c34fe25c9f7851
vulnerabilitiescritical: 0 high: 0 medium: 1 low: 0
platformlinux/amd64
size15 MB
packages463
critical: 0 high: 0 medium: 1 low: 0 axios 0.25.0 (npm)

pkg:npm/axios@0.25.0

medium 6.5: CVE--2023--45857 Cross-Site Request Forgery (CSRF)

Affected range>=0.8.1
<1.6.0
Fixed version1.6.0
CVSS Score6.5
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Description

An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

Copy link

github-actions bot commented Jan 1, 2024

🔍 Vulnerabilities of ghcr.io/uniget-org/tools/k3sup:0.13.4

📦 Image Reference ghcr.io/uniget-org/tools/k3sup:0.13.4
digestsha256:4dacfc14dc8da502d1f404bd4cfbba02dda157454f9c3eca647fd9683c7cef99
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0
platformlinux/amd64
size2.4 MB
packages10

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant