drakkan/sftpgo:plugins (debian 12.9) - Trivy Report - 2025-10-14 15:10:58.011521904 +0000 UTC m=+7.576297657

debian
Package Vulnerability ID Severity Installed Version Fixed Version Links
apt CVE-2011-3374 LOW 2.6.1
bash TEMP-0841856-B18BAF LOW 5.2.15-2+b7
bsdutils CVE-2022-0563 LOW 1:2.38.1-5+deb12u3
coreutils CVE-2016-2781 LOW 9.1-1
coreutils CVE-2017-18018 LOW 9.1-1
coreutils CVE-2025-5278 LOW 9.1-1
dpkg CVE-2025-6297 LOW 1.21.22
gcc-12-base CVE-2022-27943 LOW 12.2.0-14
gcc-12-base CVE-2023-4039 LOW 12.2.0-14 12.2.0-14+deb12u1
git CVE-2025-48384 HIGH 1:2.39.5-0+deb12u2
git CVE-2025-48385 HIGH 1:2.39.5-0+deb12u2
git CVE-2025-27613 MEDIUM 1:2.39.5-0+deb12u2
git CVE-2018-1000021 LOW 1:2.39.5-0+deb12u2
git CVE-2022-24975 LOW 1:2.39.5-0+deb12u2
git CVE-2024-52005 LOW 1:2.39.5-0+deb12u2
git CVE-2025-46835 LOW 1:2.39.5-0+deb12u2
git-man CVE-2025-48384 HIGH 1:2.39.5-0+deb12u2
git-man CVE-2025-48385 HIGH 1:2.39.5-0+deb12u2
git-man CVE-2025-27613 MEDIUM 1:2.39.5-0+deb12u2
git-man CVE-2018-1000021 LOW 1:2.39.5-0+deb12u2
git-man CVE-2022-24975 LOW 1:2.39.5-0+deb12u2
git-man CVE-2024-52005 LOW 1:2.39.5-0+deb12u2
git-man CVE-2025-46835 LOW 1:2.39.5-0+deb12u2
gpgv CVE-2025-30258 MEDIUM 2.2.40-1.1
gpgv CVE-2022-3219 LOW 2.2.40-1.1
jq CVE-2025-48060 HIGH 1.6-2.1 1.6-2.1+deb12u1
jq CVE-2024-23337 LOW 1.6-2.1
jq CVE-2025-9403 LOW 1.6-2.1
libapt-pkg6.0 CVE-2011-3374 LOW 2.6.1
libblkid1 CVE-2022-0563 LOW 2.38.1-5+deb12u3
libc-bin CVE-2025-4802 HIGH 2.36-9+deb12u9 2.36-9+deb12u11
libc-bin CVE-2025-0395 MEDIUM 2.36-9+deb12u9 2.36-9+deb12u10
libc-bin CVE-2025-8058 MEDIUM 2.36-9+deb12u9 2.36-9+deb12u13
libc-bin CVE-2010-4756 LOW 2.36-9+deb12u9
libc-bin CVE-2018-20796 LOW 2.36-9+deb12u9
libc-bin CVE-2019-1010022 LOW 2.36-9+deb12u9
libc-bin CVE-2019-1010023 LOW 2.36-9+deb12u9
libc-bin CVE-2019-1010024 LOW 2.36-9+deb12u9
libc-bin CVE-2019-1010025 LOW 2.36-9+deb12u9
libc-bin CVE-2019-9192 LOW 2.36-9+deb12u9
libc6 CVE-2025-4802 HIGH 2.36-9+deb12u9 2.36-9+deb12u11
libc6 CVE-2025-0395 MEDIUM 2.36-9+deb12u9 2.36-9+deb12u10
libc6 CVE-2025-8058 MEDIUM 2.36-9+deb12u9 2.36-9+deb12u13
libc6 CVE-2010-4756 LOW 2.36-9+deb12u9
libc6 CVE-2018-20796 LOW 2.36-9+deb12u9
libc6 CVE-2019-1010022 LOW 2.36-9+deb12u9
libc6 CVE-2019-1010023 LOW 2.36-9+deb12u9
libc6 CVE-2019-1010024 LOW 2.36-9+deb12u9
libc6 CVE-2019-1010025 LOW 2.36-9+deb12u9
libc6 CVE-2019-9192 LOW 2.36-9+deb12u9
libcap2 CVE-2025-1390 MEDIUM 1:2.66-4 1:2.66-4+deb12u1
libcurl3-gnutls CVE-2024-11053 MEDIUM 7.88.1-10+deb12u8 7.88.1-10+deb12u10
libcurl3-gnutls CVE-2024-9681 MEDIUM 7.88.1-10+deb12u8 7.88.1-10+deb12u9
libcurl3-gnutls CVE-2025-10148 MEDIUM 7.88.1-10+deb12u8
libcurl3-gnutls CVE-2025-9086 MEDIUM 7.88.1-10+deb12u8
libcurl3-gnutls CVE-2024-2379 LOW 7.88.1-10+deb12u8
libcurl3-gnutls CVE-2025-0167 LOW 7.88.1-10+deb12u8 7.88.1-10+deb12u11
libcurl3-gnutls CVE-2025-0725 LOW 7.88.1-10+deb12u8
libexpat1 CVE-2023-52425 HIGH 2.5.0-1+deb12u1 2.5.0-1+deb12u2
libexpat1 CVE-2024-8176 HIGH 2.5.0-1+deb12u1 2.5.0-1+deb12u2
libexpat1 CVE-2024-50602 MEDIUM 2.5.0-1+deb12u1 2.5.0-1+deb12u2
libexpat1 CVE-2025-59375 MEDIUM 2.5.0-1+deb12u1
libexpat1 CVE-2023-52426 LOW 2.5.0-1+deb12u1
libexpat1 CVE-2024-28757 LOW 2.5.0-1+deb12u1
libgcc-s1 CVE-2022-27943 LOW 12.2.0-14
libgcc-s1 CVE-2023-4039 LOW 12.2.0-14 12.2.0-14+deb12u1
libgcrypt20 CVE-2018-6829 LOW 1.10.1-3
libgcrypt20 CVE-2024-2236 LOW 1.10.1-3
libgnutls30 CVE-2025-32988 HIGH 3.7.9-2+deb12u4 3.7.9-2+deb12u5
libgnutls30 CVE-2025-32990 HIGH 3.7.9-2+deb12u4 3.7.9-2+deb12u5
libgnutls30 CVE-2025-32989 MEDIUM 3.7.9-2+deb12u4 3.7.9-2+deb12u5
libgnutls30 CVE-2025-6395 MEDIUM 3.7.9-2+deb12u4 3.7.9-2+deb12u5
libgnutls30 CVE-2011-3389 LOW 3.7.9-2+deb12u4
libgssapi-krb5-2 CVE-2024-26462 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u3
libgssapi-krb5-2 CVE-2025-24528 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u3
libgssapi-krb5-2 CVE-2025-3576 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u4
libgssapi-krb5-2 CVE-2018-5709 LOW 1.20.1-2+deb12u2
libgssapi-krb5-2 CVE-2024-26458 LOW 1.20.1-2+deb12u2
libgssapi-krb5-2 CVE-2024-26461 LOW 1.20.1-2+deb12u2
libjq1 CVE-2025-48060 HIGH 1.6-2.1 1.6-2.1+deb12u1
libjq1 CVE-2024-23337 LOW 1.6-2.1
libjq1 CVE-2025-9403 LOW 1.6-2.1
libk5crypto3 CVE-2024-26462 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u3
libk5crypto3 CVE-2025-24528 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u3
libk5crypto3 CVE-2025-3576 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u4
libk5crypto3 CVE-2018-5709 LOW 1.20.1-2+deb12u2
libk5crypto3 CVE-2024-26458 LOW 1.20.1-2+deb12u2
libk5crypto3 CVE-2024-26461 LOW 1.20.1-2+deb12u2
libkrb5-3 CVE-2024-26462 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u3
libkrb5-3 CVE-2025-24528 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u3
libkrb5-3 CVE-2025-3576 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u4
libkrb5-3 CVE-2018-5709 LOW 1.20.1-2+deb12u2
libkrb5-3 CVE-2024-26458 LOW 1.20.1-2+deb12u2
libkrb5-3 CVE-2024-26461 LOW 1.20.1-2+deb12u2
libkrb5support0 CVE-2024-26462 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u3
libkrb5support0 CVE-2025-24528 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u3
libkrb5support0 CVE-2025-3576 MEDIUM 1.20.1-2+deb12u2 1.20.1-2+deb12u4
libkrb5support0 CVE-2018-5709 LOW 1.20.1-2+deb12u2
libkrb5support0 CVE-2024-26458 LOW 1.20.1-2+deb12u2
libkrb5support0 CVE-2024-26461 LOW 1.20.1-2+deb12u2
libldap-2.5-0 CVE-2023-2953 HIGH 2.5.13+dfsg-5
libldap-2.5-0 CVE-2015-3276 LOW 2.5.13+dfsg-5
libldap-2.5-0 CVE-2017-14159 LOW 2.5.13+dfsg-5
libldap-2.5-0 CVE-2017-17740 LOW 2.5.13+dfsg-5
libldap-2.5-0 CVE-2020-15719 LOW 2.5.13+dfsg-5
liblzma5 CVE-2025-31115 HIGH 5.4.1-0.2 5.4.1-1
libmount1 CVE-2022-0563 LOW 2.38.1-5+deb12u3
libpam-modules CVE-2025-6020 HIGH 1.5.2-6+deb12u1
libpam-modules CVE-2024-10041 MEDIUM 1.5.2-6+deb12u1
libpam-modules CVE-2024-22365 MEDIUM 1.5.2-6+deb12u1
libpam-modules-bin CVE-2025-6020 HIGH 1.5.2-6+deb12u1
libpam-modules-bin CVE-2024-10041 MEDIUM 1.5.2-6+deb12u1
libpam-modules-bin CVE-2024-22365 MEDIUM 1.5.2-6+deb12u1
libpam-runtime CVE-2025-6020 HIGH 1.5.2-6+deb12u1
libpam-runtime CVE-2024-10041 MEDIUM 1.5.2-6+deb12u1
libpam-runtime CVE-2024-22365 MEDIUM 1.5.2-6+deb12u1
libpam0g CVE-2025-6020 HIGH 1.5.2-6+deb12u1
libpam0g CVE-2024-10041 MEDIUM 1.5.2-6+deb12u1
libpam0g CVE-2024-22365 MEDIUM 1.5.2-6+deb12u1
libperl5.36 CVE-2023-31484 HIGH 5.36.0-7+deb12u1 5.36.0-7+deb12u3
libperl5.36 CVE-2024-56406 HIGH 5.36.0-7+deb12u1 5.36.0-7+deb12u2
libperl5.36 CVE-2025-40909 MEDIUM 5.36.0-7+deb12u1 5.36.0-7+deb12u3
libperl5.36 CVE-2011-4116 LOW 5.36.0-7+deb12u1
libperl5.36 CVE-2023-31486 LOW 5.36.0-7+deb12u1
libsmartcols1 CVE-2022-0563 LOW 2.38.1-5+deb12u3
libssl3 CVE-2024-13176 MEDIUM 3.0.15-1~deb12u1 3.0.16-1~deb12u1
libssl3 CVE-2025-9230 MEDIUM 3.0.15-1~deb12u1 3.0.17-1~deb12u3
libssl3 CVE-2025-27587 LOW 3.0.15-1~deb12u1
libssl3 CVE-2025-9232 LOW 3.0.15-1~deb12u1 3.0.17-1~deb12u3
libstdc++6 CVE-2022-27943 LOW 12.2.0-14
libstdc++6 CVE-2023-4039 LOW 12.2.0-14 12.2.0-14+deb12u1
libsystemd0 CVE-2025-4598 MEDIUM 252.33-1~deb12u1 252.38-1~deb12u1
libsystemd0 CVE-2013-4392 LOW 252.33-1~deb12u1
libsystemd0 CVE-2023-31437 LOW 252.33-1~deb12u1
libsystemd0 CVE-2023-31438 LOW 252.33-1~deb12u1
libsystemd0 CVE-2023-31439 LOW 252.33-1~deb12u1
libtinfo6 CVE-2023-50495 MEDIUM 6.4-4
libtinfo6 CVE-2025-6141 LOW 6.4-4
libudev1 CVE-2025-4598 MEDIUM 252.33-1~deb12u1 252.38-1~deb12u1
libudev1 CVE-2013-4392 LOW 252.33-1~deb12u1
libudev1 CVE-2023-31437 LOW 252.33-1~deb12u1
libudev1 CVE-2023-31438 LOW 252.33-1~deb12u1
libudev1 CVE-2023-31439 LOW 252.33-1~deb12u1
libuuid1 CVE-2022-0563 LOW 2.38.1-5+deb12u3
login CVE-2023-4641 MEDIUM 1:4.13+dfsg1-1+b1 1:4.13+dfsg1-1+deb12u1
login CVE-2007-5686 LOW 1:4.13+dfsg1-1+b1
login CVE-2023-29383 LOW 1:4.13+dfsg1-1+b1 1:4.13+dfsg1-1+deb12u1
login CVE-2024-56433 LOW 1:4.13+dfsg1-1+b1
login TEMP-0628843-DBAD28 LOW 1:4.13+dfsg1-1+b1
mount CVE-2022-0563 LOW 2.38.1-5+deb12u3
ncurses-base CVE-2023-50495 MEDIUM 6.4-4
ncurses-base CVE-2025-6141 LOW 6.4-4
ncurses-bin CVE-2023-50495 MEDIUM 6.4-4
ncurses-bin CVE-2025-6141 LOW 6.4-4
openssl CVE-2024-13176 MEDIUM 3.0.15-1~deb12u1 3.0.16-1~deb12u1
openssl CVE-2025-9230 MEDIUM 3.0.15-1~deb12u1 3.0.17-1~deb12u3
openssl CVE-2025-27587 LOW 3.0.15-1~deb12u1
openssl CVE-2025-9232 LOW 3.0.15-1~deb12u1 3.0.17-1~deb12u3
passwd CVE-2023-4641 MEDIUM 1:4.13+dfsg1-1+b1 1:4.13+dfsg1-1+deb12u1
passwd CVE-2007-5686 LOW 1:4.13+dfsg1-1+b1
passwd CVE-2023-29383 LOW 1:4.13+dfsg1-1+b1 1:4.13+dfsg1-1+deb12u1
passwd CVE-2024-56433 LOW 1:4.13+dfsg1-1+b1
passwd TEMP-0628843-DBAD28 LOW 1:4.13+dfsg1-1+b1
perl CVE-2023-31484 HIGH 5.36.0-7+deb12u1 5.36.0-7+deb12u3
perl CVE-2024-56406 HIGH 5.36.0-7+deb12u1 5.36.0-7+deb12u2
perl CVE-2025-40909 MEDIUM 5.36.0-7+deb12u1 5.36.0-7+deb12u3
perl CVE-2011-4116 LOW 5.36.0-7+deb12u1
perl CVE-2023-31486 LOW 5.36.0-7+deb12u1
perl-base CVE-2023-31484 HIGH 5.36.0-7+deb12u1 5.36.0-7+deb12u3
perl-base CVE-2024-56406 HIGH 5.36.0-7+deb12u1 5.36.0-7+deb12u2
perl-base CVE-2025-40909 MEDIUM 5.36.0-7+deb12u1 5.36.0-7+deb12u3
perl-base CVE-2011-4116 LOW 5.36.0-7+deb12u1
perl-base CVE-2023-31486 LOW 5.36.0-7+deb12u1
perl-modules-5.36 CVE-2023-31484 HIGH 5.36.0-7+deb12u1 5.36.0-7+deb12u3
perl-modules-5.36 CVE-2024-56406 HIGH 5.36.0-7+deb12u1 5.36.0-7+deb12u2
perl-modules-5.36 CVE-2025-40909 MEDIUM 5.36.0-7+deb12u1 5.36.0-7+deb12u3
perl-modules-5.36 CVE-2011-4116 LOW 5.36.0-7+deb12u1
perl-modules-5.36 CVE-2023-31486 LOW 5.36.0-7+deb12u1
sysvinit-utils TEMP-0517018-A83CE6 LOW 3.06-4
tar CVE-2005-2541 LOW 1.34+dfsg-1.2+deb12u1
tar TEMP-0290435-0B57B5 LOW 1.34+dfsg-1.2+deb12u1
util-linux CVE-2022-0563 LOW 2.38.1-5+deb12u3
util-linux-extra CVE-2022-0563 LOW 2.38.1-5+deb12u3
zlib1g CVE-2023-45853 CRITICAL 1:1.2.13.dfsg-1
No Misconfigurations found
gobinary
Package Vulnerability ID Severity Installed Version Fixed Version Links
github.com/go-acme/lego/v4 CVE-2025-54799 LOW v4.21.0 4.25.2
github.com/go-chi/chi/v5 GHSA-vrw8-fxc6-2r93 MEDIUM v5.2.0 5.2.2
github.com/go-jose/go-jose/v4 CVE-2025-27144 MEDIUM v4.0.4 4.0.5
github.com/wneessen/go-mail CVE-2025-59937 HIGH v0.6.2 0.7.1
golang.org/x/net CVE-2025-22870 MEDIUM v0.35.0 0.36.0
golang.org/x/net CVE-2025-22872 MEDIUM v0.35.0 0.38.0
stdlib CVE-2025-47907 HIGH v1.23.6 1.23.12, 1.24.6
stdlib CVE-2025-0913 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-22871 MEDIUM v1.23.6 1.23.8, 1.24.2
stdlib CVE-2025-4673 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.23.6 1.23.12, 1.24.6
No Misconfigurations found
gobinary
Package Vulnerability ID Severity Installed Version Fixed Version Links
golang.org/x/net CVE-2025-22870 MEDIUM v0.35.0 0.36.0
golang.org/x/net CVE-2025-22872 MEDIUM v0.35.0 0.38.0
stdlib CVE-2025-47907 HIGH v1.23.6 1.23.12, 1.24.6
stdlib CVE-2025-0913 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-22871 MEDIUM v1.23.6 1.23.8, 1.24.2
stdlib CVE-2025-4673 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.23.6 1.23.12, 1.24.6
No Misconfigurations found
gobinary
Package Vulnerability ID Severity Installed Version Fixed Version Links
golang.org/x/net CVE-2025-22870 MEDIUM v0.35.0 0.36.0
golang.org/x/net CVE-2025-22872 MEDIUM v0.35.0 0.38.0
stdlib CVE-2025-47907 HIGH v1.23.6 1.23.12, 1.24.6
stdlib CVE-2025-0913 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-22871 MEDIUM v1.23.6 1.23.8, 1.24.2
stdlib CVE-2025-4673 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.23.6 1.23.12, 1.24.6
No Misconfigurations found
gobinary
Package Vulnerability ID Severity Installed Version Fixed Version Links
golang.org/x/net CVE-2025-22870 MEDIUM v0.35.0 0.36.0
golang.org/x/net CVE-2025-22872 MEDIUM v0.35.0 0.38.0
stdlib CVE-2025-47907 HIGH v1.23.6 1.23.12, 1.24.6
stdlib CVE-2025-0913 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-22871 MEDIUM v1.23.6 1.23.8, 1.24.2
stdlib CVE-2025-4673 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.23.6 1.23.12, 1.24.6
No Misconfigurations found
gobinary
Package Vulnerability ID Severity Installed Version Fixed Version Links
golang.org/x/net CVE-2025-22870 MEDIUM v0.35.0 0.36.0
golang.org/x/net CVE-2025-22872 MEDIUM v0.35.0 0.38.0
stdlib CVE-2025-47907 HIGH v1.23.6 1.23.12, 1.24.6
stdlib CVE-2025-0913 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-22871 MEDIUM v1.23.6 1.23.8, 1.24.2
stdlib CVE-2025-4673 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.23.6 1.23.12, 1.24.6
No Misconfigurations found
gobinary
Package Vulnerability ID Severity Installed Version Fixed Version Links
github.com/go-jose/go-jose/v4 CVE-2025-27144 MEDIUM v4.0.4 4.0.5
github.com/golang-jwt/jwt/v5 CVE-2025-30204 HIGH v5.2.1 5.2.2
golang.org/x/net CVE-2025-22870 MEDIUM v0.35.0 0.36.0
golang.org/x/net CVE-2025-22872 MEDIUM v0.35.0 0.38.0
stdlib CVE-2025-47907 HIGH v1.23.6 1.23.12, 1.24.6
stdlib CVE-2025-0913 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-22871 MEDIUM v1.23.6 1.23.8, 1.24.2
stdlib CVE-2025-4673 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.23.6 1.23.12, 1.24.6
No Misconfigurations found
gobinary
Package Vulnerability ID Severity Installed Version Fixed Version Links
github.com/golang-jwt/jwt/v5 CVE-2025-30204 HIGH v5.2.1 5.2.2
golang.org/x/net CVE-2025-22870 MEDIUM v0.35.0 0.36.0
golang.org/x/net CVE-2025-22872 MEDIUM v0.35.0 0.38.0
stdlib CVE-2025-47907 HIGH v1.23.6 1.23.12, 1.24.6
stdlib CVE-2025-0913 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-22871 MEDIUM v1.23.6 1.23.8, 1.24.2
stdlib CVE-2025-4673 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.23.6 1.23.12, 1.24.6
No Misconfigurations found