CVE-2024-36127

HIGH

apko <0.14.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.

Scores

CVSS v3 7.5
EPSS 0.0016
EPSS Percentile 36.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-522 CWE-532
Status published
Products (2)
chainguard-dev/apko < 0.14.5
chainguard.dev/apko 0 - 0.14.5Go
Published Jun 03, 2024
Tracked Since Feb 18, 2026