Vulnerability Scan Report for registry.suse.com/bci/bci-init:15.5.15.1
Systemd environment for containers based on the SLE Base Container Image. This container is only supported with podman.
Last scanned on: April 01, 2025 14:32

Systemd environment for containers based on the SLE Base Container Image. This container is only supported with podman.
Last scanned on: April 01, 2025 14:32
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
libcurl4 | MEDIUM | fixed |
Security update for curl Vulnerability ID: SUSE-SU-2024:3211-1 Installed Version: 8.0.1-150400.5.41.1 Fixed Version: 8.0.1-150400.5.50.1 This update for curl fixes the following issues: - CVE-2024-8096: OCSP stapling bypass with GnuTLS. (bsc#1230093) |
||
libcurl4 | MEDIUM | fixed |
Security update for curl Vulnerability ID: SUSE-SU-2024:3926-1 Installed Version: 8.0.1-150400.5.41.1 Fixed Version: 8.0.1-150400.5.56.1 This update for curl fixes the following issues: - CVE-2024-9681: Fixed HSTS subdomain overwrites parent cache entry (bsc#1232528) |
||
libcurl4 | MEDIUM | fixed |
Security update for curl Vulnerability ID: SUSE-SU-2024:4359-1 Installed Version: 8.0.1-150400.5.41.1 Fixed Version: 8.0.1-150400.5.59.1 This update for curl fixes the following issues: - CVE-2024-11053: Fixed password leak in curl used for the first host to the followed-to host under certain circumstances (bsc#1234068) |
||
libcurl4 | MEDIUM | fixed |
Security update for curl Vulnerability ID: SUSE-SU-2025:0370-1 Installed Version: 8.0.1-150400.5.41.1 Fixed Version: 8.0.1-150400.5.62.1 This update for curl fixes the following issues: - CVE-2025-0725: Fixed gzip integer overflow (bsc#1236590) - CVE-2025-0167: Fixed netrc and default credential leak (bsc#1236588) |
||
libexpat1 | HIGH | fixed |
Security update for expat Vulnerability ID: SUSE-SU-2024:1129-1 Installed Version: 2.4.4-150400.3.12.1 Fixed Version: 2.4.4-150400.3.17.1 This update for expat fixes the following issues: - CVE-2023-52425: Fixed a DoS caused by processing large tokens. (bsc#1219559) - CVE-2024-28757: Fixed an XML Entity Expansion. (bsc#1221289) |