Tagged “go”
CVEs tagged go, newest first.
1746 CVEsRSS
CVE-2022-23525High· 7.5⚖ disputedhelm: Denial of service through through repository index file (CVE-2022-23525)
A flaw was found in Helm. Applications that use the _repo_ package in Helm SDK to parse an index file may suffer a denial of service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index fil…
CVE-2022-23469Low· 3.5Traefik may display authorization header in the debug logs
Traefik may display authorization header in the debug logs
CVE-2022-46153Medium· 6.5Traefik routes exposed with an empty TLSOption
Traefik routes exposed with an empty TLSOption
CVE-2022-23471Medium· 5.7containerd CRI stream server vulnerable to host memory exhaustion via terminal
containerd CRI stream server vulnerable to host memory exhaustion via terminal
CVE-2022-46146Medium· 6.2Prometheus Exporter-Toolkit is vulnerable to authentication bypass
Prometheus Exporter-Toolkit is vulnerable to authentication bypass
CVE-2022-3920High· 7.5Missing Authorization in HashiCorp Consul
Missing Authorization in HashiCorp Consul
CVE-2022-39307Medium· 5.3grafana: User enumeration via forget password (CVE-2022-39307)
An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.
CVE-2022-39306High· 8.1grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)
An authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup lin…
CVE-2022-3023Critical· 9.8TiDB vulnerable to Use of Externally-Controlled Format String
TiDB vulnerable to Use of Externally-Controlled Format String
CVE-2022-3616Medium· 5.4OctoRPKI crashes when max iterations is reached
OctoRPKI crashes when max iterations is reached
CVE-2022-31683Medium· 5.4Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
CVE-2022-32149High· 7.5golang.org/x/text/language Denial of service via crafted Accept-Language header
golang.org/x/text/language Denial of service via crafted Accept-Language header
CVE-2021-21271Medium· 6.5Tendermint Core vulnerable to Uncontrolled Resource Consumption
Tendermint Core vulnerable to Uncontrolled Resource Consumption
CVE-2020-7711High· 7.5goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
CVE-2020-15115Medium· 5.8etcd has no minimum password length
etcd has no minimum password length
CVE-2022-41715NoneMemory exhaustion when compiling regular expressions in regexp/syntax
Memory exhaustion when compiling regular expressions in regexp/syntax
CVE-2022-2880NoneIncorrect sanitization of forwarded query parameters in net/http/httputil
Incorrect sanitization of forwarded query parameters in net/http/httputil
CVE-2022-2879NoneUnbounded memory consumption when reading headers in archive/tar
Unbounded memory consumption when reading headers in archive/tar
CVE-2020-15106Medium· 5.3etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
CVE-2022-2529High· 7.5Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package
Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package
CVE-2021-41803High· 7.1HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
CVE-2021-36782Critical· 9.9PoCRancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
GHSA-qv98-3369-g364HighKubeVirt vulnerable to arbitrary file read on host
KubeVirt vulnerable to arbitrary file read on host
CVE-2022-32190NoneFailure to strip relative path components in net/url
Failure to strip relative path components in net/url
CVE-2022-27664High· 7.5golang.org/x/net/http2 Denial of Service vulnerability
golang.org/x/net/http2 Denial of Service vulnerability
GO-2022-0965NoneUnbounded recursion in JSON parsing in k8s.io/apimachinery
Unbounded recursion in JSON parsing in k8s.io/apimachinery
CVE-2022-31677Medium· 4.9Pinniped Supervisor Insufficient Session Expiration vulnerability
Pinniped Supervisor Insufficient Session Expiration vulnerability
CVE-2022-36055Medium· 6.5Helm Vulnerable to denial of service through string value parsing
Helm Vulnerable to denial of service through string value parsing
CVE-2022-3064High· 7.5go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)
A flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.
CVE-2022-36633High· 8.8PoCImproper token validation leading to code execution in Teleport
Improper token validation leading to code execution in Teleport