Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-RU-2026:20161-1

Опубликовано: 27 янв. 2026
Источник: suse-cvrf

Описание

Recommended update for hauler

This update for hauler fixes the following issues:

Changes in hauler:

  • Update to version 1.4.1 (bsc#1256546, CVE-2026-22772):

    • fixed typos for containerd imports (#493)
    • fix and support containerd imports of hauls (#492)
    • bump github.com/sigstore/fulcio (#489)
  • Update to version 1.4.0:

    • added/updated logging for serve and remove (#487)
    • added/fixed helm chart images/dependencies features (#485)
    • more experimental feature updates (#486)
    • add experimental notes (#483)
    • updated tempdir flag to store persistent flags (#484)
    • delete artifacts from store (#473)
    • path rewrites (#475)
    • updated/fixed workflow dependency versions (#478)
  • Update to version 1.3.2:

    • bump to latest cosign fork release (#481)
    • Bump golang.org/x/crypto in the go_modules group across 1 directory (#476)

Список пакетов

openSUSE Leap 16.0
hauler-1.4.1-bp160.1.1

Описание

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal services. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. This vulnerability is fixed in 1.8.5.


Затронутые продукты
openSUSE Leap 16.0:hauler-1.4.1-bp160.1.1

Ссылки
Уязвимость openSUSE-RU-2026:20161-1