Exposure of HTTP Basic Authentication Credentials in apko by Chainguard
CVE-2024-36127

Currently unrated

Key Information:

Vendor

Chainguard

Status
Vendor
CVE Published:
3 June 2024

What is CVE-2024-36127?

The apko image builder, developed by Chainguard, reveals HTTP basic authentication credentials in logs associated with repository and keyring URLs. This exposure can lead to unauthorized access if sensitive information is captured, highlighting the importance of secure logging practices. This issue was rectified in version 0.14.5, underscoring the need for users to update promptly to maintain security.

References

Timeline

  • Vulnerability published

.