Tagged “go”
CVEs tagged go, newest first.
1746 CVEsRSS
CVE-2023-3978Medium· 6.1Improper rendering of text nodes in golang.org/x/net/html
Improper rendering of text nodes in golang.org/x/net/html
CVE-2023-37900Low· 3.4Denial of service from large image
Denial of service from large image
CVE-2023-37916Medium· 6.5KubePi may leak password hash of any user
KubePi may leak password hash of any user
CVE-2023-37917Critical· 9.1KubePi Privilege Escalation vulnerability
KubePi Privilege Escalation vulnerability
CVE-2023-37918Medium· 6.8Dapr API token authentication bypass in HTTP endpoints
Dapr API token authentication bypass in HTTP endpoints
CVE-2023-37788High· 7.5goproxy Denial of Service vulnerability
goproxy Denial of Service vulnerability
CVE-2023-34236High· 8.5Weave GitOps Terraform Controller Information Disclosure Vulnerability
Weave GitOps Terraform Controller Information Disclosure Vulnerability
GHSA-2w8w-qhg4-f78jMedium· 6.5A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries
A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries
CVE-2023-36458Medium· 6.31Panel vulnerable to command injection when entering the container terminal
1Panel vulnerable to command injection when entering the container terminal
CVE-2023-3128Critical· 9.4PoCGrafana vulnerable to Authentication Bypass by Spoofing
Grafana vulnerable to Authentication Bypass by Spoofing
CVE-2023-34758High· 8.1Silver vulnerable to MitM attack against implants due to a cryptography vulnerability
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability
CVE-2023-2183Medium· 4.1Grafana has Broken Access Control in Alert manager: Viewer can send test alerts
Grafana has Broken Access Control in Alert manager: Viewer can send test alerts
CVE-2023-33967High· 8.2SQL injection when using MySQL/PostgreSQL data checking
SQL injection when using MySQL/PostgreSQL data checking
CVE-2023-2801High· 7.5Grafana Missing Synchronization vulnerability
Grafana Missing Synchronization vulnerability
CVE-2023-22647Critical· 9.9Rancher vulnerable to Privilege Escalation via manipulation of Secrets
Rancher vulnerable to Privilege Escalation via manipulation of Secrets
CVE-2020-10676High· 8.8Rancher users retain access after moving namespaces into projects they don't have access to
Rancher users retain access after moving namespaces into projects they don't have access to
CVE-2022-43760High· 8.4Rancher UI has multiple Cross-Site Scripting (XSS) issues
Rancher UI has multiple Cross-Site Scripting (XSS) issues
CVE-2023-34091Medium· 6.5Kyverno resource with a deletionTimestamp may allow policy circumvention
Kyverno resource with a deletionTimestamp may allow policy circumvention
CVE-2023-33964High· 8.6mx-chain-go does not treat invalid transaction with wrong username correctly
mx-chain-go does not treat invalid transaction with wrong username correctly
GHSA-hgv6-w7r3-w4qwMediumKyverno vulnerable due to usage of insecure cipher
Kyverno vulnerable due to usage of insecure cipher
CVE-2023-33191Medium· 4.6kyverno seccomp control can be circumvented
kyverno seccomp control can be circumvented
CVE-2023-32698High· 7.1nfpm has incorrect default permissions
nfpm has incorrect default permissions
CVE-2021-25748Medium· 6.5Ingress-nginx `path` sanitization can be bypassed with newline character
Ingress-nginx `path` sanitization can be bypassed with newline character
CVE-2023-30851Medium· 5.3Potential HTTP policy bypass when using header rules in Cilium
Potential HTTP policy bypass when using header rules in Cilium
CVE-2023-32082Low· 3.1etcd Key name can be accessed via LeaseTimeToLive API
etcd Key name can be accessed via LeaseTimeToLive API
CVE-2023-1732Medium· 5.3Improper random reading in CIRCL
Improper random reading in CIRCL
CVE-2023-30551High· 7.5Rekor's compressed archives can result in OOM conditions
Rekor's compressed archives can result in OOM conditions
CVE-2023-22651Critical· 9.9Rancher Webhook is misconfigured during upgrade process
Rancher Webhook is misconfigured during upgrade process
CVE-2023-30622Medium· 6.7A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation
A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation
CVE-2023-29013High· 7.5Traefik HTTP header parsing could cause a denial of service
Traefik HTTP header parsing could cause a denial of service