[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2DOCKER-2024-037 --- containerd

ID: oval:org.secpod.oval:def:1702111Date: (C)2024-02-28   (M)2024-04-29
Class: PATCHFamily: unix




The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack

Platform:
Amazon Linux 2
Product:
containerd
Reference:
ALAS2DOCKER-2024-037
CVE-2023-39325
CVE-2023-3978
CVE-2023-47108
CVE-2023-39326
CVE    4
CVE-2023-3978
CVE-2023-47108
CVE-2023-39326
CVE-2023-39325
...
CPE    2
cpe:/o:amazon:linux:2
cpe:/a:containerd.io:containerd

© SecPod Technologies