Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Anchore/
  3. Anchore Enforce

Anchore Enforce

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 7 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~40 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Policy enforcement & compliance mgmt for container security across SDLC

by Anchore · anchore.com · source ↗

Known CVEs (7)1 newAbout this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-63727 ↗HIGH 8.8new2026

    Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Ancho…

  • CVE-2026-25076 ↗HIGH 7.32026

    Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenticated attacker that is able to access the GraphQL API could execute arbitrary SQ…

  • CVE-2022-41225 ↗MEDIUM 5.42022

    Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable…

  • CVE-2022-1766 ↗HIGH 7.52022

    Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the…

  • CVE-2020-11075 ↗HIGH 7.72020

    In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer service during an imag…

  • CVE-2019-16542 ↗MEDIUM 6.52019

    Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read perm…

  • CVE-2018-1999033 ↗MEDIUM 6.52018

    An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permis…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Container Security products

see all →
  • AI EdgeLabs Kubernetes & Container Security · AI EdgeLabs
  • Anchore Secure · Anchore
  • Aqua Security Holistic Kubernetes Security · Aqua Security
  • Aqua Security Lifecycle Container Security · Aqua Security
  • Bitdefender GravityZone Security for Containers · Bitdefender
  • Chainguard · Chainguard
  • Checkmarx Container Security · Checkmarx
  • CloudMatos Kubernetes Security Posture Management (KSPM) Solution · CloudMatos