CVE-2022-1766

HIGH

anchore/anchorectl < 0.1.5 - Insufficiently Protected Credentials in SBOM Generation

Title source: llm
STIX 2.1

Description

Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl version 0.1.4 should upgrade to anchorectl version 0.1.5 to resolve this issue.

References (1)

Core 1
Core References
Release Notes, Vendor Advisory x_refsource_confirm
https://docs.anchore.com/current/docs/releasenotes/401/

Scores

CVSS v3 7.5
EPSS 0.0057
EPSS Percentile 42.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (2)
anchore/anchore < 4.0.1
anchore/anchorectl < 0.1.5
Published Jul 20, 2022
Tracked Since Feb 18, 2026