CVE-2024-36127 Information

Description

apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.

Reference

https://github.com/chainguard-dev/apko/security/advisories/GHSA-v6mg-7f7p-qmqp https://github.com/chainguard-dev/apko/commit/2c0533e4d52e83031a04f6a83ec63fc2a11eff01

Share on: