VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2024-7594High· 7.5
2y ago

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.27%via OSV
CVE-2024-34158None
2y ago

Stack exhaustion in Parse in go/build/constraint

Stack exhaustion in Parse in go/build/constraint

▾ Sunlitstdlib · stdlibEPSS 1.0%via OSV
GO-2022-0920None
2y ago

Incorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper

Incorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper

▾ Sunlitory · github.com/ory/oathkeepervia OSV
CVE-2024-43406High· 8.8
2y ago

LF Edge eKuiper has a SQL Injection in sqlKvStore

LF Edge eKuiper has a SQL Injection in sqlKvStore

▾ Twilightlf-edge · github.com/lf-edge/ekuiperEPSS 0.89%via OSV
GO-2023-1804None
2y ago

Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno

Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno

▾ Sunlitkyverno · github.com/kyverno/kyvernovia OSV
CVE-2024-6984High· 8.8
2y ago

Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm

Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm

▾ Twilightjuju · github.com/juju/jujuEPSS 0.38%via OSV
CVE-2024-37286Medium· 5.7
2y ago

APM Server vulnerable to Insertion of Sensitive Information into Log File

APM Server vulnerable to Insertion of Sensitive Information into Log File

▾ Sunlitelastic · github.com/elastic/apm-serverEPSS 0.49%via OSV
CVE-2024-41255Medium· 5.9
2y ago

Filestash configured to skip TLS certificate verification when using the FTPS protocol

Filestash configured to skip TLS certificate verification when using the FTPS protocol

▾ Sunlitmickael-kerjean · github.com/mickael-kerjean/filestashEPSS 0.26%via OSV
CVE-2024-29069Medium· 4.8
2y ago

snapd failed to properly check the destination of symbolic links when extracting a snap

snapd failed to properly check the destination of symbolic links when extracting a snap

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.23%via OSV
CVE-2024-29068Medium· 5.8
2y ago

snapd failed to properly check the file type when extracting a snap

snapd failed to properly check the file type when extracting a snap

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.21%via OSV
CVE-2024-1724Medium· 6.3
2y ago

snapd failed to restrict writes to the $HOME/bin path

snapd failed to restrict writes to the $HOME/bin path

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.31%via OSV
CVE-2024-41666Medium· 4.7
2y ago

The Argo CD web terminal session does not handle the revocation of user permissions properly

The Argo CD web terminal session does not handle the revocation of user permissions properly

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.69%via OSV
CVE-2024-41122High· 7.5
2y ago

Woodpecker's custom environment variables allow to alter execution flow of plugins

Woodpecker's custom environment variables allow to alter execution flow of plugins

▾ Twilightwoodpecker · go.woodpecker-ci.org/woodpecker/v2EPSS 0.62%via OSV
CVE-2024-5321Medium· 6.1
2y ago

Kubernetes sets incorrect permissions on Windows containers logs

Kubernetes sets incorrect permissions on Windows containers logs

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.31%via OSV
CVE-2024-39907Critical· 9.8PoC
2y ago

1Panel has an SQL injection issue related to the orderBy clause

1Panel has an SQL injection issue related to the orderBy clause

▾ Abyssal1Panel-dev · github.com/1Panel-dev/1PanelEPSS 29%via OSV
CVE-2024-39909Medium· 6.5
2y ago

SQL Injection in the KubeClarity REST API

SQL Injection in the KubeClarity REST API

▾ Sunlitopenclarity · github.com/openclarity/kubeclarity/backendEPSS 0.44%via OSV
CVE-2024-6468High· 7.5
2y ago

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.49%via OSV
CVE-2024-39897Medium· 4.3
2y ago

Cache driver GetBlob() allows read access to any blob without access control check

Cache driver GetBlob() allows read access to any blob without access control check

▾ Sunlitzot · zotregistry.io/zotEPSS 0.30%via OSV
CVE-2024-37298High· 7.5
2y ago

Potential memory exhaustion attack due to sparse slice deserialization

Potential memory exhaustion attack due to sparse slice deserialization

▾ Twilightgorilla · github.com/gorilla/schemaEPSS 1.1%via OSV
GO-2024-2941None
2y ago

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik

▾ Sunlittraefik · github.com/traefik/traefikvia OSV
CVE-2024-5899None
2y ago

Improper trust check in Bazel Build intellij plugin in github.com/bazelbuild/intellij

Improper trust check in Bazel Build intellij plugin in github.com/bazelbuild/intellij

▾ Sunlitbazelbuild · github.com/bazelbuild/intellijEPSS 0.11%via OSV
CVE-2024-37820Medium· 5.4
2y ago

PingCAP TiDB nil pointer dereference

PingCAP TiDB nil pointer dereference

▾ Sunlitpingcap · github.com/pingcap/tidbEPSS 0.38%via OSV
GHSA-rvj4-q8q5-8grfMedium· 5.5
2y ago

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability

▾ Sunlittraefik · github.com/traefik/traefik/v3via OSV
GO-2024-2917None
2y ago

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik

▾ Sunlittraefik · github.com/traefik/traefikvia OSV
CVE-2024-36586High· 8.8
2y ago

AdGuardHome privilege escalation vulnerability

AdGuardHome privilege escalation vulnerability

▾ TwilightAdguardTeam · github.com/AdguardTeam/AdGuardHomeEPSS 0.21%via OSV
CVE-2023-49559Medium· 5.3
2y ago

gqlparser denial of service vulnerability via the parserDirectives function

gqlparser denial of service vulnerability via the parserDirectives function

▾ Sunlitvektah · github.com/vektah/gqlparser/v2EPSS 0.60%via OSV
CVE-2024-5798Low· 2.6
2y ago

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.34%via OSV
GHSA-7jmw-8259-q9jxMedium
2y ago

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

▾ Sunlittraefik · github.com/traefik/traefik/v3via OSV
GHSA-87m9-rv8p-rgmgHigh· 7.5
2y ago

go-grpc-compression has a zstd decompression bombing vulnerability

go-grpc-compression has a zstd decompression bombing vulnerability

▾ Twilightmostynb · github.com/mostynb/go-grpc-compressionvia OSV
CVE-2021-41089Low· 2.8
2y ago

`docker cp` allows unexpected chmod of host files in Moby Docker Engine

`docker cp` allows unexpected chmod of host files in Moby Docker Engine

▾ Sunlitdocker · github.com/docker/dockerEPSS 0.29%via OSV
CVEs tagged “go” — page 45 · VulnSea