Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2024-7594High· 7.5Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
CVE-2024-34158NoneStack exhaustion in Parse in go/build/constraint
Stack exhaustion in Parse in go/build/constraint
GO-2022-0920NoneIncorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper
Incorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper
CVE-2024-43406High· 8.8LF Edge eKuiper has a SQL Injection in sqlKvStore
LF Edge eKuiper has a SQL Injection in sqlKvStore
GO-2023-1804NoneKyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
CVE-2024-6984High· 8.8Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
CVE-2024-37286Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File
CVE-2024-41255Medium· 5.9Filestash configured to skip TLS certificate verification when using the FTPS protocol
Filestash configured to skip TLS certificate verification when using the FTPS protocol
CVE-2024-29069Medium· 4.8snapd failed to properly check the destination of symbolic links when extracting a snap
snapd failed to properly check the destination of symbolic links when extracting a snap
CVE-2024-29068Medium· 5.8snapd failed to properly check the file type when extracting a snap
snapd failed to properly check the file type when extracting a snap
CVE-2024-1724Medium· 6.3snapd failed to restrict writes to the $HOME/bin path
snapd failed to restrict writes to the $HOME/bin path
CVE-2024-41666Medium· 4.7The Argo CD web terminal session does not handle the revocation of user permissions properly
The Argo CD web terminal session does not handle the revocation of user permissions properly
CVE-2024-41122High· 7.5Woodpecker's custom environment variables allow to alter execution flow of plugins
Woodpecker's custom environment variables allow to alter execution flow of plugins
CVE-2024-5321Medium· 6.1Kubernetes sets incorrect permissions on Windows containers logs
Kubernetes sets incorrect permissions on Windows containers logs
CVE-2024-39907Critical· 9.8PoC1Panel has an SQL injection issue related to the orderBy clause
1Panel has an SQL injection issue related to the orderBy clause
CVE-2024-39909Medium· 6.5SQL Injection in the KubeClarity REST API
SQL Injection in the KubeClarity REST API
CVE-2024-6468High· 7.5Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
CVE-2024-39897Medium· 4.3Cache driver GetBlob() allows read access to any blob without access control check
Cache driver GetBlob() allows read access to any blob without access control check
CVE-2024-37298High· 7.5Potential memory exhaustion attack due to sparse slice deserialization
Potential memory exhaustion attack due to sparse slice deserialization
GO-2024-2941NoneACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
CVE-2024-5899NoneImproper trust check in Bazel Build intellij plugin in github.com/bazelbuild/intellij
Improper trust check in Bazel Build intellij plugin in github.com/bazelbuild/intellij
CVE-2024-37820Medium· 5.4PingCAP TiDB nil pointer dereference
PingCAP TiDB nil pointer dereference
GHSA-rvj4-q8q5-8grfMedium· 5.5ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
GO-2024-2917NoneTraefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
CVE-2024-36586High· 8.8AdGuardHome privilege escalation vulnerability
AdGuardHome privilege escalation vulnerability
CVE-2023-49559Medium· 5.3gqlparser denial of service vulnerability via the parserDirectives function
gqlparser denial of service vulnerability via the parserDirectives function
CVE-2024-5798Low· 2.6HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
GHSA-7jmw-8259-q9jxMediumTraefik has unexpected behavior with IPv4-mapped IPv6 addresses
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses
GHSA-87m9-rv8p-rgmgHigh· 7.5go-grpc-compression has a zstd decompression bombing vulnerability
go-grpc-compression has a zstd decompression bombing vulnerability
CVE-2021-41089Low· 2.8`docker cp` allows unexpected chmod of host files in Moby Docker Engine
`docker cp` allows unexpected chmod of host files in Moby Docker Engine