Tagged “go”
CVEs tagged go, newest first.
1746 CVEsRSS
CVE-2023-29194Medium· 4.1vitess allows users to create keyspaces that can deny access to already existing keyspaces
vitess allows users to create keyspaces that can deny access to already existing keyspaces
CVE-2023-28842Medium· 6.8moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)
A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…
CVE-2023-1410Medium· 6.2Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip
Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip
CVE-2022-41354Medium· 5.3Argo CD authenticated but unauthorized users may enumerate Application names via the API
Argo CD authenticated but unauthorized users may enumerate Application names via the API
CVE-2023-28119High· 7.5crewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb
crewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb
CVE-2023-28114Medium· 4.8`cilium-cli` disables etcd authorization for clustermesh clusters
`cilium-cli` disables etcd authorization for clustermesh clusters
CVE-2023-1314High· 7.5cloudflared's Installer has Local Privilege Escalation Vulnerability
cloudflared's Installer has Local Privilege Escalation Vulnerability
CVE-2023-27593Medium· 4.4cilium-agent container can access the host via `hostPath` mount
cilium-agent container can access the host via `hostPath` mount
CVE-2021-29456Medium· 5.4Authelia allows open redirects on the logout endpoint
Authelia allows open redirects on the logout endpoint
CVE-2023-27582Critical· 9.1Full authentication bypass if SASL authorization username is specified
Full authentication bypass if SASL authorization username is specified
CVE-2023-0845Medium· 6.5Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
CVE-2023-26483Medium· 5.3gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
CVE-2023-22462Medium· 6.4Grafana vulnerable to Stored Cross-site Scripting in Text plugin
Grafana vulnerable to Stored Cross-site Scripting in Text plugin
CVE-2023-0594High· 7.3grafana: cross site scripting (CVE-2023-0594)
A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…
CVE-2023-25656High· 7.5notation-go has excessive memory allocation on verification
notation-go has excessive memory allocation on verification
CVE-2023-23947Critical· 9.1Users with any cluster secret update access may update out-of-bounds cluster secrets
Users with any cluster secret update access may update out-of-bounds cluster secrets
CVE-2023-25153Medium· 5.5containerd: OCI image importer memory exhaustion (CVE-2023-25153)
A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.
CVE-2023-23631High· 7.5IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics
IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics
CVE-2023-23626Medium· 5.9IPFS go-bitfield vulnerable to DoS via malformed size arguments
IPFS go-bitfield vulnerable to DoS via malformed size arguments
GHSA-74fp-r6jw-h4mpHigh· 7.5Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
CVE-2023-25307High· 8.8mrpack-install vulnerable to path traversal with dependency
mrpack-install vulnerable to path traversal with dependency
CVE-2022-45786High· 8.1Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
CVE-2022-39324Medium· 6.7grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)
A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.
CVE-2023-22736High· 8.5Controller reconciles apps outside configured namespaces when sharding is enabled
Controller reconciles apps outside configured namespaces when sharding is enabled
CVE-2022-41721High· 7.5x/net/http2/h2c: request smuggling (CVE-2022-41721)
A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead read the b…
CVE-2023-22492Medium· 5.9Zitadel RefreshToken invalidation vulnerability
Zitadel RefreshToken invalidation vulnerability
CVE-2022-2582Medium· 4.3AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
CVE-2022-47633High· 8.1kyverno verifyImages rule bypass possible with malicious proxy/registry
kyverno verifyImages rule bypass possible with malicious proxy/registry
CVE-2022-23524High· 7.5⚖ disputedhelm: Denial of service through string value parsing (CVE-2022-23524)
A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption. Input to functions in the _strvals_ package could cause a stack overflo…
CVE-2022-23526High· 7.5⚖ disputedhelm: Denial of service through schema file (CVE-2022-23526)
A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that could cause a segmentation violation. The _chartut…