Search CVE reports
1 – 3 of 3 results
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the...
1 affected package
kraken
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| kraken | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.
1 affected package
kraken
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| kraken | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
1 affected package
rake
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rake | — | — | — | — | Fixed |