HIGH🇵🇱 Wersja polska

CVE-2022-1766

CVSS 7.5v3.1pub. 2022-07-20upd. 2024-11-21

Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl version 0.1.4 should upgrade to anchorectl version 0.1.5 to resolve this issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Anchore

    APP
    Anchore
    < 4.0.1
  • Anchore Anchorectl

    APP
    Anchore
    < 0.1.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-11075HIGH7.7same vendor

In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be...

CVE-2026-33481MEDIUM5.3same vendor

Syft to narzędzie CLI i biblioteka Go do generowania Software Bill of Materials (SBOM) z obrazów kontenerowych...

CVE-2026-31959MEDIUM5.3same vendor

Quill — narzędzie do podpisywania i notaryzacji binariów macOS z dowolnej platformy. Wersje przed v0.7.1 zawie...

CVE-2026-31960MEDIUM5.3same vendor

Quill zapewnia proste podpisywanie i notaryzację plików binarnych macOS z dowolnej platformy. Wersje Quill prz...

CVE-2026-31961MEDIUM5.5same vendor

Quill zapewnia proste podpisywanie i notaryzowanie binarnych plików macOS z dowolnej platformy. Quill w wersji...