Tagged “go”
CVEs tagged go, newest first.
1749 CVEsRSS
CVE-2023-30617Medium· 6.5Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster
Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster
CVE-2023-46739Medium· 6.5CubeFS timing attack can leak user passwords
CubeFS timing attack can leak user passwords
CVE-2023-46740Medium· 6.5Insecure random string generator used for sensitive data
Insecure random string generator used for sensitive data
CVE-2023-49568High· 7.5Maliciously crafted Git server replies can cause DoS on go-git clients
Maliciously crafted Git server replies can cause DoS on go-git clients
GHSA-7ww5-4wqc-m92cMediumcontainerd allows RAPL to be accessible to a container
containerd allows RAPL to be accessible to a container
CVE-2023-50422Critical· 9.1Improper Privilege Management in github.com/sap/cloud-security-client-go
Improper Privilege Management in github.com/sap/cloud-security-client-go
CVE-2023-6458High· 7.1Mattermost Injection vulnerability
Mattermost Injection vulnerability
CVE-2023-6459Medium· 5.3Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-49290Medium· 5.3lestrrat-go/jwx's malicious parameters in JWE can cause a DOS
lestrrat-go/jwx's malicious parameters in JWE can cause a DOS
CVE-2023-47106Medium· 6.5Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
CVE-2023-47124Medium· 5.9Traefik vulnerable to potential DDoS via ACME HTTPChallenge
Traefik vulnerable to potential DDoS via ACME HTTPChallenge
CVE-2023-47633High· 7.5Traefik docker container using 100% CPU
Traefik docker container using 100% CPU
CVE-2023-49097High· 8.1ZITADEL Account Takeover via Malicious Host Header Injection
ZITADEL Account Takeover via Malicious Host Header Injection
CVE-2023-6202Medium· 4.3Mattermost Improper Access Control vulnerability
Mattermost Improper Access Control vulnerability
CVE-2023-47168Medium· 4.3Mattermost Open Redirect vulnerability
Mattermost Open Redirect vulnerability
CVE-2023-48369Medium· 5.3Mattermost Uncontrolled Resource Consumption vulnerability
Mattermost Uncontrolled Resource Consumption vulnerability
GHSA-2c7c-3mj9-8fqhMediumDecryption of malicious PBES2 JWE objects can consume unbounded system resources
Decryption of malicious PBES2 JWE objects can consume unbounded system resources
CVE-2023-46402High· 7.5Inefficient Regular Expression Complexity in git-urls
Inefficient Regular Expression Complexity in git-urls
CVE-2023-47630High· 7.1⚠ Exploited0dayAttacker can cause Kyverno user to unintentionally consume insecure image
Attacker can cause Kyverno user to unintentionally consume insecure image
CVE-2023-5954High· 7.5HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
CVE-2023-47111High· 7.3ZITADEL race condition in lockout policy execution
ZITADEL race condition in lockout policy execution
CVE-2023-46254Medium· 4.3capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name
capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name
CVE-2023-41378High· 7.5Calico Typha denial of service vulnerability
Calico Typha denial of service vulnerability
CVE-2023-3676High· 8.8Kubernetes privilege escalation vulnerability
Kubernetes privilege escalation vulnerability
CVE-2023-46239High· 7.5quic-go vulnerable to pointer dereference that can lead to panic
quic-go vulnerable to pointer dereference that can lead to panic
CVE-2021-25736Medium· 5.8Kube-proxy may unintentionally forward traffic
Kube-proxy may unintentionally forward traffic
CVE-2022-4886High· 8.8Ingress-nginx path sanitization can be bypassed
Ingress-nginx path sanitization can be bypassed
CVE-2023-5043High· 7.6PoCIngress nginx annotation injection causes arbitrary command execution
Ingress nginx annotation injection causes arbitrary command execution
CVE-2023-43651Medium· 6.4Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell
Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell
CVE-2023-47090HighNATS.io: Adding accounts for just the system account adds auth bypass
NATS.io: Adding accounts for just the system account adds auth bypass