Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2023-32192High· 8.3Rancher API Server Cross-site Scripting Vulnerability
Rancher API Server Cross-site Scripting Vulnerability
CVE-2024-23448Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File
GHSA-5x4g-q5rc-36jpLowEtcd pkg Insecure ciphers are allowed by default
Etcd pkg Insecure ciphers are allowed by default
CVE-2021-43798High· 7.5CISA KEVPoCGrafana path traversal
Grafana path traversal
CVE-2020-27534Medium· 5.3Path Traversal in Moby builder
Path Traversal in Moby builder
CVE-2024-23652Critical· 10.0PoCBuildKit vulnerable to possible host system access from mount stub cleaner
BuildKit vulnerable to possible host system access from mount stub cleaner
CVE-2019-19499Medium· 6.5Grafana Arbitrary File Read
Grafana Arbitrary File Read
CVE-2020-15114High· 7.7Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
CVE-2021-21284Medium· 6.8moby Access to remapped root allows privilege escalation to real root
moby Access to remapped root allows privilege escalation to real root
CVE-2021-21334Medium· 6.3containerd environment variable leak
containerd environment variable leak
CVE-2021-21285Medium· 6.5moby docker daemon crash during image pull of malicious image
moby docker daemon crash during image pull of malicious image
CVE-2021-41091Medium· 5.9PoCMoby (Docker Engine) Insufficiently restricted permissions on data directory
Moby (Docker Engine) Insufficiently restricted permissions on data directory
CVE-2024-23332Medium· 4.0Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from co…
Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from compromised registry
CVE-2024-22424High· 8.3github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
CVE-2024-22199Critical· 9.3Django Template Engine Vulnerable to XSS
Django Template Engine Vulnerable to XSS
CVE-2023-49569Critical· 9.8Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
CVE-2023-30617Medium· 6.5Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster
Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster
CVE-2023-46739Medium· 6.5CubeFS timing attack can leak user passwords
CubeFS timing attack can leak user passwords
CVE-2023-46740Medium· 6.5Insecure random string generator used for sensitive data
Insecure random string generator used for sensitive data
CVE-2023-49568High· 7.5Maliciously crafted Git server replies can cause DoS on go-git clients
Maliciously crafted Git server replies can cause DoS on go-git clients
GHSA-7ww5-4wqc-m92cMediumcontainerd allows RAPL to be accessible to a container
containerd allows RAPL to be accessible to a container
CVE-2023-50422Critical· 9.1Improper Privilege Management in github.com/sap/cloud-security-client-go
Improper Privilege Management in github.com/sap/cloud-security-client-go
CVE-2023-6458High· 7.1Mattermost Injection vulnerability
Mattermost Injection vulnerability
CVE-2023-6459Medium· 5.3Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-49290Medium· 5.3lestrrat-go/jwx's malicious parameters in JWE can cause a DOS
lestrrat-go/jwx's malicious parameters in JWE can cause a DOS
CVE-2023-47106Medium· 6.5Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
CVE-2023-47124Medium· 5.9Traefik vulnerable to potential DDoS via ACME HTTPChallenge
Traefik vulnerable to potential DDoS via ACME HTTPChallenge
CVE-2023-47633High· 7.5Traefik docker container using 100% CPU
Traefik docker container using 100% CPU
CVE-2023-49097High· 8.1ZITADEL Account Takeover via Malicious Host Header Injection
ZITADEL Account Takeover via Malicious Host Header Injection
CVE-2023-6202Medium· 4.3Mattermost Improper Access Control vulnerability
Mattermost Improper Access Control vulnerability