Tagged “go”
CVEs tagged go, newest first.
1746 CVEsRSS
CVE-2023-43802High· 7.3Arduino Create Agent path traversal - local privilege escalation vulnerability
Arduino Create Agent path traversal - local privilege escalation vulnerability
CVE-2023-43800High· 7.3Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability
Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability
CVE-2023-45683High· 7.1Cross-site Scripting via missing Binding syntax validation
Cross-site Scripting via missing Binding syntax validation
CVE-2023-4822Medium· 6.7grafana: incorrect assessment of permissions across organizations (CVE-2023-4822)
A flaw was found in the Grafana enterprise package. Grafana is incorrectly assessing permissions to update global roles and role assignments, therefore, users with administrator permissions in one organization can change global role permis…
CVE-2023-39325High· 7.5PoCHTTP/2 rapid reset can cause excessive work in net/http
HTTP/2 rapid reset can cause excessive work in net/http
CVE-2023-20902Medium· 5.9Harbor timing attack risk
Harbor timing attack risk
CVE-2023-32188CriticalJWT token compromise can allow malicious actions including Remote Code Execution (RCE)
JWT token compromise can allow malicious actions including Remote Code Execution (RCE)
CVE-2023-44378Medium· 5.5gnark unsoundness in variable comparison / non-unique binary decomposition
gnark unsoundness in variable comparison / non-unique binary decomposition
CVE-2023-5077High· 7.6Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2023-43645Medium· 5.9OpenFGA Vulnerable to DoS from circular relationship definitions
OpenFGA Vulnerable to DoS from circular relationship definitions
CVE-2023-40026Medium· 5.0Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
CVE-2023-41333Medium· 6.9Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
CVE-2023-41332Low· 3.5Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
CVE-2022-3962Medium· 4.3Kiali content spoofing vulnerability
Kiali content spoofing vulnerability
CVE-2023-43621Medium· 4.7Croc may expose secret to local users
Croc may expose secret to local users
CVE-2023-43618Medium· 5.3Croc requires senders to provide local IP addresses in cleartext
Croc requires senders to provide local IP addresses in cleartext
CVE-2023-43620High· 7.8Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device
Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device
CVE-2023-4680Medium· 6.8HashiCorp Vault Improper Input Validation vulnerability
HashiCorp Vault Improper Input Validation vulnerability
CVE-2023-41318Medium· 4.1matrix-media-repo: Unsafe media served inline on download endpoints
matrix-media-repo: Unsafe media served inline on download endpoints
CVE-2023-41338Medium· 5.3Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`
Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`
GHSA-6xv5-86q9-7xr8MediumSecureJoin: on windows, paths outside of the rootfs could be inadvertently produced
SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced
GHSA-23px-mw2p-46qmMediumCosmos-SDK Cosmovisor component may be vulnerable to denial of service
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
CVE-2023-28434High· 8.8CISA KEVPoCPrivilege Escalation on Linux/MacOS
Privilege Escalation on Linux/MacOS
CVE-2023-32079High· 8.8Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User
Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User
CVE-2023-32078High· 7.5Netmaker IDOR Allows User to Update Other User's Password
Netmaker IDOR Allows User to Update Other User's Password
CVE-2023-38976High· 7.5Weaviate denial of service vulnerability
Weaviate denial of service vulnerability
CVE-2023-40034High· 8.1Woodpecker does not validate webhook before changing any data
Woodpecker does not validate webhook before changing any data
CVE-2023-39965Medium· 6.51Panel Arbitrary File Download vulnerability
1Panel Arbitrary File Download vulnerability
CVE-2023-3518High· 7.4Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
CVE-2023-37896High· 7.5Nuclei Path Traversal vulnerability
Nuclei Path Traversal vulnerability