DirectorySecurity Advisories
Sign In
Security Advisories

CGA-7vjh-h2cm-m288

Published

Last updated

https://images.chainguard.dev/security/CGA-7vjh-h2cm-m288
Package

croc

Latest Update
Fixed
Fixed Version

10.0.0-r0

Aliases
  • CVE-2023-43621
  • GHSA-7g3v-4ggr-xvjf

Severity

4.7

Medium

CVSS V3

Summary

Croc may expose secret to local users

Description

An issue was discovered in Croc before 9.6.16. The shared secret, located on a command line, can be read by local users who list all processes and their arguments.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images