VulnSea

Tagged “go”

CVEs tagged go, newest first.

1746 CVEsRSS

CVE-2023-29194Medium· 4.1
3y ago

vitess allows users to create keyspaces that can deny access to already existing keyspaces

vitess allows users to create keyspaces that can deny access to already existing keyspaces

▾ Sunlitvitess · vitess.io/vitessEPSS 0.78%via OSV
CVE-2023-28842Medium· 6.8
3y ago

moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)

A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…

▾ SunlitRed Hat · multicluster engine for Kubernetes 2.4 for RHEL 8EPSS 1.4%via CSAF
CVE-2023-1410Medium· 6.2
3y ago

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 0.96%via OSV
CVE-2022-41354Medium· 5.3
3y ago

Argo CD authenticated but unauthorized users may enumerate Application names via the API

Argo CD authenticated but unauthorized users may enumerate Application names via the API

▾ Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.64%via OSV
CVE-2023-28119High· 7.5
3y ago

crewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb

crewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb

▾ Twilightcrewjam · github.com/crewjam/samlEPSS 0.96%via OSV
CVE-2023-28114Medium· 4.8
3y ago

`cilium-cli` disables etcd authorization for clustermesh clusters

`cilium-cli` disables etcd authorization for clustermesh clusters

▾ Sunlitcilium · github.com/cilium/cilium-cliEPSS 0.19%via OSV
CVE-2023-1314High· 7.5
3y ago

cloudflared's Installer has Local Privilege Escalation Vulnerability

cloudflared's Installer has Local Privilege Escalation Vulnerability

▾ Twilightcloudflare · github.com/cloudflare/cloudflaredEPSS 0.26%via OSV
CVE-2023-27593Medium· 4.4
3y ago

cilium-agent container can access the host via `hostPath` mount

cilium-agent container can access the host via `hostPath` mount

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.22%via OSV
CVE-2021-29456Medium· 5.4
3y ago

Authelia allows open redirects on the logout endpoint

Authelia allows open redirects on the logout endpoint

▾ Sunlitauthelia · github.com/authelia/authelia/v4EPSS 0.51%via OSV
CVE-2023-27582Critical· 9.1
3y ago

Full authentication bypass if SASL authorization username is specified

Full authentication bypass if SASL authorization username is specified

▾ Midnightfoxcpp · github.com/foxcpp/maddyEPSS 1.0%via OSV
CVE-2023-0845Medium· 6.5
3y ago

Consul Server Panic when Ingress and API Gateways Configured with Peering Connections

Consul Server Panic when Ingress and API Gateways Configured with Peering Connections

▾ Sunlithashicorp · github.com/hashicorp/consulEPSS 1.0%via OSV
CVE-2023-26483Medium· 5.3
3y ago

gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb

gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb

▾ Sunlitrussellhaering · github.com/russellhaering/gosaml2EPSS 0.96%via OSV
CVE-2023-22462Medium· 6.4
3y ago

Grafana vulnerable to Stored Cross-site Scripting in Text plugin

Grafana vulnerable to Stored Cross-site Scripting in Text plugin

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.6%via OSV
CVE-2023-0594High· 7.3
3y ago

grafana: cross site scripting (CVE-2023-0594)

A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…

▾ TwilightRed Hat · Red Hat Ceph Storage 5.3 ToolsEPSS 9.2%via CSAF
CVE-2023-25656High· 7.5
3y ago

notation-go has excessive memory allocation on verification

notation-go has excessive memory allocation on verification

▾ Twilightnotaryproject · github.com/notaryproject/notation-goEPSS 0.44%via OSV
CVE-2023-23947Critical· 9.1
3y ago

Users with any cluster secret update access may update out-of-bounds cluster secrets

Users with any cluster secret update access may update out-of-bounds cluster secrets

▾ Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.67%via OSV
CVE-2023-25153Medium· 5.5
3y ago

containerd: OCI image importer memory exhaustion (CVE-2023-25153)

A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.

▾ SunlitRed Hat · Red Hat Ceph Storage 9.0 ToolsEPSS 0.36%via CSAF
CVE-2023-23631High· 7.5
3y ago

IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics

IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics

▾ Twilightipfs · github.com/ipfs/go-unixfsnodeEPSS 0.91%via OSV
CVE-2023-23626Medium· 5.9
3y ago

IPFS go-bitfield vulnerable to DoS via malformed size arguments

IPFS go-bitfield vulnerable to DoS via malformed size arguments

▾ Sunlitipfs · github.com/ipfs/go-bitfieldEPSS 0.91%via OSV
GHSA-74fp-r6jw-h4mpHigh· 7.5
3y ago

Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing

Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing

▾ Twilightapimachinery · k8s.io/apimachineryvia OSV
CVE-2023-25307High· 8.8
3y ago

mrpack-install vulnerable to path traversal with dependency

mrpack-install vulnerable to path traversal with dependency

▾ Twilightnothub · github.com/nothub/mrpack-installEPSS 0.60%via OSV
CVE-2022-45786High· 8.1
3y ago

Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection

Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection

▾ Twilightapache · github.com/apache/age/drivers/golangEPSS 0.96%via OSV
CVE-2022-39324Medium· 6.7
3y ago

grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)

A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.83%via CSAF
CVE-2023-22736High· 8.5
3y ago

Controller reconciles apps outside configured namespaces when sharding is enabled

Controller reconciles apps outside configured namespaces when sharding is enabled

▾ Twilightargoproj · github.com/argoproj/argo-cd/v2EPSS 0.78%via OSV
CVE-2022-41721High· 7.5
3y ago

x/net/http2/h2c: request smuggling (CVE-2022-41721)

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead read the b…

▾ TwilightRed Hat · OpenShift Service Mesh 2.1EPSS 1.8%via CSAF
CVE-2023-22492Medium· 5.9
3y ago

Zitadel RefreshToken invalidation vulnerability

Zitadel RefreshToken invalidation vulnerability

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.60%via OSV
CVE-2022-2582Medium· 4.3
3y ago

AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field

AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field

▾ Sunlitaws · github.com/aws/aws-sdk-goEPSS 0.48%via OSV
CVE-2022-47633High· 8.1
3y ago

kyverno verifyImages rule bypass possible with malicious proxy/registry

kyverno verifyImages rule bypass possible with malicious proxy/registry

▾ Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.96%via OSV
CVE-2022-23524High· 7.5⚖ disputed
3y ago

helm: Denial of service through string value parsing (CVE-2022-23524)

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption. Input to functions in the _strvals_ package could cause a stack overflo…

▾ TwilightRed Hat · RHACS 4.0 for RHEL 8EPSS 0.78%via CSAF
CVE-2022-23526High· 7.5⚖ disputed
3y ago

helm: Denial of service through schema file (CVE-2022-23526)

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that could cause a segmentation violation. The _chartut…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.86%via CSAF
CVEs tagged “go” — page 52 · VulnSea