Vulnerabilities

Last updated 46 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
zotregistry.dev/zot/v2 zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion High Risk 8.1 10 days ago 4 hours ago
zotregistry.dev/zot zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot Unknown 5 hours ago 4 hours ago
zotregistry.dev/zot/v2 zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot Unknown 5 hours ago 4 hours ago
zotregistry.dev/zot Zot IdP group membership revocation ignored High Risk 7.3 1 year ago 18 days ago
zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check Medium Risk 4.3 2 years ago 18 days ago
zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) High Risk 7.7 6 months ago 6 months ago
zotregistry.dev/zot/v2 zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) High Risk 7.7 6 months ago 6 months ago
zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot Unknown 6 months ago 6 months ago
zotregistry.dev/zot/v2 zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot Unknown 6 months ago 6 months ago
zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Unknown 1 year ago 6 months ago
zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Unknown 2 years ago 7 months ago
zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot Unknown 1 year ago 7 months ago
zotregistry.dev/zot zot logs secrets Medium Risk 6.0 1 year ago 1 year ago