Sploitus

CVE-2024-35192

No indexed exploits for CVE-2024-35192 yet

Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR). These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. Systems are not affected if the default credential provider chain is unable to obtain valid credentials. This vulnerability only applies when scanning container images directly from a registry. This vulnerability is fixed in 0.51.2.

Fix
Available
CVSS 3.1
5.5 MEDIUM
EPSS
0.2% (9th percentile)
Weakness
CWE-522
NVD status
Deferred
Published
2024-05-20
CVE-2024-35192 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-35192 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-35192 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.