Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
CVE-2021-41092Medium· 5.4Docker CLI leaks private registry credentials to registry-1.docker.io
Docker CLI leaks private registry credentials to registry-1.docker.io
CVE-2024-37152Medium· 5.3PoCUnauthenticated Access to sensitive settings in Argo CD
Unauthenticated Access to sensitive settings in Argo CD
CVE-2024-36106Medium· 4.3Argo-cd authenticated users can enumerate clusters by name
Argo-cd authenticated users can enumerate clusters by name
GO-2024-2880NoneTraefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik
GO-2024-2726NoneTraefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik
Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik
CVE-2024-5154High· 8.1malicious container creates symlink "mtab" on the host External
malicious container creates symlink "mtab" on the host External
CVE-2024-22261Low· 2.7SQL Injection in Harbor scan log API
SQL Injection in Harbor scan log API
CVE-2024-22244Medium· 4.3Open Redirect URL in Harbor
Open Redirect URL in Harbor
CVE-2024-35232Low· 3.7github.com/huandu/facebook may expose access_token in error message.
github.com/huandu/facebook may expose access_token in error message.
GHSA-f7cq-5v43-8pwpMedium· 5.3Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
CVE-2024-35223Medium· 5.3Dapr API Token Exposure
Dapr API Token Exposure
CVE-2024-35175Medium· 5.3sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address
sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address
CVE-2021-41244Critical· 9.1Grafana Fine-grained access control vulnerability
Grafana Fine-grained access control vulnerability
CVE-2021-43815Medium· 4.3Grafana directory traversal for .cvs files
Grafana directory traversal for .cvs files
CVE-2024-3727High· 8.3A flaw was found in the github.com/containers/image library
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
CVE-2024-34079Low· 3.7octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage
octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage
CVE-2024-32886Medium· 4.9Vitess vulnerable to infinite memory consumption and vtgate crash
Vitess vulnerable to infinite memory consumption and vtgate crash
CVE-2024-33394Medium· 5.9kubevirt allows a local attacker to execute arbitrary code via a crafted command
kubevirt allows a local attacker to execute arbitrary code via a crafted command
CVE-2024-32963Medium· 4.2Navidrome Parameter Tampering vulnerability
Navidrome Parameter Tampering vulnerability
CVE-2024-33522Medium· 6.7Calico privilege escalation vulnerability
Calico privilege escalation vulnerability
CVE-2023-46565High· 7.5Buffer Overflow vulnerability in osrg gobgp
Buffer Overflow vulnerability in osrg gobgp
CVE-2024-3154High· 7.2A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
CVE-2024-32476Medium· 6.5Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
CVE-2020-8559Medium· 6.8PoCPrivilege Escalation in Kubernetes
Privilege Escalation in Kubernetes
CVE-2021-36775High· 8.0Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
CVE-2021-31999High· 8.8Rancher Privilege escalation vulnerability via malicious "Connection" header
Rancher Privilege escalation vulnerability via malicious "Connection" header
CVE-2021-25318High· 8.8Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
CVE-2022-24769Medium· 5.9Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
CVE-2024-30257Medium· 5.91Panel's password verification is suspected to have a timing attack vulnerability
1Panel's password verification is suspected to have a timing attack vulnerability
GHSA-7f4j-64p6-5h5vMediumTraefik affected by HTTP/2 CONTINUATION flood in net/http
Traefik affected by HTTP/2 CONTINUATION flood in net/http