Tagged “go”
CVEs tagged go, newest first.
1746 CVEsRSS
CVE-2022-27649High· 7.5Podman's default inheritable capabilities for linux container not empty
Podman's default inheritable capabilities for linux container not empty
CVE-2022-27651Medium· 6.8Non-empty default inheritable capabilities for linux container in Buildah
Non-empty default inheritable capabilities for linux container in Buildah
CVE-2022-1025Critical· 9.9Improper access control allows admin privilege escalation in Argo CD
Improper access control allows admin privilege escalation in Argo CD
CVE-2022-21221High· 7.5Path traversal in github.com/valyala/fasthttp
Path traversal in github.com/valyala/fasthttp
CVE-2022-0811High· 8.8PoCCode Injection in CRI-O
Code Injection in CRI-O
CVE-2022-26652Medium· 6.5Arbitrary file write in nats-server
Arbitrary file write in nats-server
CVE-2020-8552Medium· 5.3Kubernetes API Server DoS Via API Requests
Kubernetes API Server DoS Via API Requests
CVE-2021-3127Criticalnats-io/jwt not enforcing checking of Import token permissions
nats-io/jwt not enforcing checking of Import token permissions
CVE-2018-1002207Medium· 5.5Arbitrary File Write via Archive Extraction in mholt/archiver
Arbitrary File Write via Archive Extraction in mholt/archiver
CVE-2018-1002105Critical· 9.8PoCPrivilege Escalation in Kubernetes
Privilege Escalation in Kubernetes
CVE-2019-1002101Medium· 5.5PoCSymlink Attack in kubectl cp
Symlink Attack in kubectl cp
CVE-2020-8551Medium· 4.3Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes
Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes
CVE-2020-13597Medium· 6.0Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico
Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico
CVE-2020-28466High· 7.5Denial of service in github.com/nats-io/nats-server/server
Denial of service in github.com/nats-io/nats-server/server
CVE-2020-26294High· 7.4Exposure of server configuration in github.com/go-vela/server
Exposure of server configuration in github.com/go-vela/server
CVE-2021-21272High· 7.7Zip slip directory exploit in github.com/deislabs/oras
Zip slip directory exploit in github.com/deislabs/oras
CVE-2021-21237High· 7.2Git LFS can execute a Git binary from the current directory on Windows
Git LFS can execute a Git binary from the current directory on Windows
CVE-2021-29136Medium· 5.5Improper input validation in umoci
Improper input validation in umoci
CVE-2021-21403High· 7.5Authentication Bypass by Primary Weakness in github.com/kongchuanhujiao/server
Authentication Bypass by Primary Weakness in github.com/kongchuanhujiao/server
CVE-2021-21432High· 7.5Reject unauthorized access with GitHub PATs
Reject unauthorized access with GitHub PATs
CVE-2020-26277Medium· 6.1Symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations in dbdeployer
Symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations in dbdeployer
CVE-2020-29662Medium· 5.3"catalog's registry v2 api exposed on unauthenticated path in Harbor"
"catalog's registry v2 api exposed on unauthenticated path in Harbor"
CVE-2020-8912Low· 2.5In-band key negotiation issue in AWS S3 Crypto SDK for golang
In-band key negotiation issue in AWS S3 Crypto SDK for golang
CVE-2020-15157Medium· 6.1containerd v1.2.x can be coerced into leaking credentials during image pull
containerd v1.2.x can be coerced into leaking credentials during image pull
CVE-2020-26892Critical· 9.8Incorrect handling of credential expiry by /nats-io/nats-server
Incorrect handling of credential expiry by /nats-io/nats-server
CVE-2020-15129Medium· 6.1PoCTraefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header
Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header
CVE-2020-8918High· 7.1TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm
TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm
GHSA-qq97-vm5h-rrhgLow· 3.0OCI Manifest Type Confusion Issue
OCI Manifest Type Confusion Issue
CVE-2022-24348High· 7.7PoCPath traversal and dereference of symlinks in Argo CD
Path traversal and dereference of symlinks in Argo CD
CVE-2021-43816High· 8.0Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux
Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux