CVE-2024-36127

HIGH

apko <0.14.4 - Info Disclosure

Title source: llm

Description

apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.

Scores

CVSS v3 7.5
EPSS 0.0021
EPSS Percentile 42.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522 CWE-532
Status draft

Affected Products (1)

chainguard.dev/apko < 0.14.5Go

Timeline

Published Jun 03, 2024
Tracked Since Feb 18, 2026