github.com/snapcore/snapd vulnerabilities
CVEs whose affected-version data names the github.com/snapcore/snapd package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2024-5138Medium· 4.0CVE-2024-5138: snapd snapctl auth bypass
CVE-2024-5138: snapd snapctl auth bypass
▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.83%via OSV
CVE-2024-29069Medium· 4.8snapd failed to properly check the destination of symbolic links when extracting a snap
snapd failed to properly check the destination of symbolic links when extracting a snap
▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.23%via OSV
CVE-2024-29068Medium· 5.8snapd failed to properly check the file type when extracting a snap
snapd failed to properly check the file type when extracting a snap
▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.21%via OSV
CVE-2024-1724Medium· 6.3snapd failed to restrict writes to the $HOME/bin path
snapd failed to restrict writes to the $HOME/bin path
▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.31%via OSV