Vulnerabilities
Last updated 2 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass | Medium Risk 6.0 | 4 hours ago | 4 hours ago |
|
|
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts | Medium Risk 6.0 | 4 hours ago | 4 hours ago |
|
|
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass | High Risk 8.0 | 1 month ago | 18 days ago |
|
|
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks | Medium Risk 6.0 | 1 month ago | 18 days ago |
|
|
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks | Medium Risk 6.0 | 1 month ago | 18 days ago |
|
|
ip-address has XSS in Address6 HTML-emitting methods | Medium Risk 6.0 | 4 months ago | 18 days ago |
|
|
IPAM controller service account granted unnecessary full access to Secrets | Medium Risk 4.4 | 4 months ago | 3 months ago |
|
|
IPAM controller service account granted unnecessary full access to Secrets in github.com/metal3-io/ip-address-manager | Unknown | 3 months ago | 3 months ago |
Page 1