Back to Argo Cd

Snyk test report

docs/snyk/master/ghcr.io_dexidp_dex_v2.45.0.html

3.4.022.0 KB
Original Source

Out-of-bounds Write

critical severity

Exploit: Not Defined



Detailed paths


NVD Description

Note: _Versions mentioned in the description apply only to the upstream zlib package and not the zlib package as distributed by Alpine._See How to fix? for Alpine:3.23 relevant fixed versions and status.

zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.

Remediation

Upgrade Alpine:3.23 zlib to version 1.3.2-r0 or higher.

References


More about this vulnerability

Untrusted Search Path

high severity

Exploit: Not Defined


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Vulnerable module: go.opentelemetry.io/otel/sdk/resource
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and go.opentelemetry.io/otel/sdk/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › go.opentelemetry.io/otel/sdk/[email protected]

Overview

Affected versions of this package are vulnerable to Untrusted Search Path in resource detection code which executes ioreg, when the PATH environment variable is modified to include a malicious executable. An attacker can execute arbitrary code within the context of the application by placing a malicious binary earlier in the search path.

Note: This vulnerability is only exploitable on MacOS/Darwin systems.

Remediation

Upgrade go.opentelemetry.io/otel/sdk/resource to version 1.40.0 or higher.

References


More about this vulnerability

Improper Validation of Specified Quantity in Input

medium severity

Exploit: Not Defined



Detailed paths


NVD Description

Note: _Versions mentioned in the description apply only to the upstream zlib package and not the zlib package as distributed by Alpine._See How to fix? for Alpine:3.23 relevant fixed versions and status.

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

Remediation

Upgrade Alpine:3.23 zlib to version 1.3.2-r0 or higher.

References


More about this vulnerability

Uncaught Exception

medium severity

Exploit: Not Defined


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/dexidp/dex › /usr/local/bin/dex
  • Package Manager: golang
  • Vulnerable module: golang.org/x/net/http2
  • Introduced through: github.com/dexidp/dex@* and golang.org/x/net/[email protected]

Detailed paths


Overview

golang.org/x/net/http2 is a work-in-progress HTTP/2 implementation for Go.

Affected versions of this package are vulnerable to Uncaught Exception due to missing nil check. An attacker can cause the server to panic and potentially disrupt service by sending specially crafted HTTP/2 frames with values between 0x0a and 0x0f.

Remediation

Upgrade golang.org/x/net/http2 to version 0.51.0 or higher.

References


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/dexidp/dex › /usr/local/bin/dex
  • Package Manager: golang
  • Module: github.com/openbao/openbao/api/v2
  • Introduced through: github.com/dexidp/dex@* and github.com/openbao/openbao/api/[email protected]

Detailed paths

  • Introduced through: github.com/dexidp/dex@* › github.com/openbao/openbao/api/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/vault/api/auth/userpass
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/vault/api/auth/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/vault/api/auth/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/vault/api/auth/aws
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/vault/api/auth/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/vault/api/auth/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/vault/api
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/vault/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/vault/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/serf/coordinate
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/serf/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/serf/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/dexidp/dex › /usr/local/bin/dex
  • Package Manager: golang
  • Module: github.com/hashicorp/hcl/v2
  • Introduced through: github.com/dexidp/dex@* and github.com/hashicorp/hcl/[email protected]

Detailed paths

  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/hcl/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/hcl/v2/ext/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/hcl/v2/ext/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/hcl/v2/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/hcl/v2/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/hcl/v2/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/hcl/v2/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/hcl/v2/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/hcl
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/[email protected]
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/hcl/hcl/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/hcl/hcl/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/golang-lru/simplelru
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/golang-lru/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/golang-lru/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/go-uuid
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/go-sockaddr
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/[email protected]
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/go-sockaddr/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/go-secure-stdlib/strutil
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/go-secure-stdlib/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/go-secure-stdlib/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/go-secure-stdlib/parseutil
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/go-secure-stdlib/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/go-secure-stdlib/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/go-secure-stdlib/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/go-secure-stdlib/awsutil
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/go-secure-stdlib/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/go-secure-stdlib/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/go-rootcerts
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/go-retryablehttp
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/go-multierror
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/go-immutable-radix
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/go-cleanhttp
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/[email protected]
  • Introduced through: github.com/dexidp/dex@* › github.com/hashicorp/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/errwrap
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/hashicorp/consul/api
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/hashicorp/consul/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/hashicorp/consul/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Module: github.com/gosimple/slug
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/gosimple/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/gosimple/[email protected]

MPL-2.0 license


More about this vulnerability

MPL-2.0 license

medium severity


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/dexidp/dex › /usr/local/bin/dex
  • Package Manager: golang
  • Module: github.com/go-sql-driver/mysql
  • Introduced through: github.com/dexidp/dex@* and github.com/go-sql-driver/[email protected]

Detailed paths

  • Introduced through: github.com/dexidp/dex@* › github.com/go-sql-driver/[email protected]

MPL-2.0 license


More about this vulnerability

Improper Validation of Integrity Check Value

medium severity

Exploit: Not Defined


  • Manifest file: ghcr.io/dexidp/dex:v2.45.0/hairyhenderson/gomplate/v5 › /usr/local/bin/gomplate
  • Package Manager: golang
  • Vulnerable module: github.com/go-git/go-git/v5/storage/filesystem
  • Introduced through: github.com/hairyhenderson/gomplate/v5@* and github.com/go-git/go-git/v5/storage/[email protected]

Detailed paths

  • Introduced through: github.com/hairyhenderson/gomplate/v5@* › github.com/go-git/go-git/v5/storage/[email protected]

Overview

Affected versions of this package are vulnerable to Improper Validation of Integrity Check Value for .idx and .pack files. An attacker can cause the application to consume corrupted files, leading to unexpected errors, due to checksums not being checked in the loadIdxFile() function.

Workaround

This vulnerability can be mitigated by running 'git fsck' from the git CLI to check for data corruption on a given repository.

Remediation

Upgrade github.com/go-git/go-git/v5/storage/filesystem to version 5.16.5 or higher.

References


More about this vulnerability