Tagged “go”
CVEs tagged go, newest first.
1746 CVEsRSS
CVE-2021-43839High· 7.5Drainage of FeeCollector's Block Transaction Fees in cronos
Drainage of FeeCollector's Block Transaction Fees in cronos
CVE-2020-5233Medium· 5.9The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect
The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect
CVE-2020-13845High· 7.5Execution Control List (ECL) Is Insecure in Singularity
Execution Control List (ECL) Is Insecure in Singularity
CVE-2020-13846High· 7.5"Verify All" Returns Success Despite Validation Failures in Singularity
"Verify All" Returns Success Despite Validation Failures in Singularity
CVE-2020-15091Medium· 6.5Denial of Service in TenderMint
Denial of Service in TenderMint
CVE-2021-32637Critical· 10.0Authelia vulnerable to an authentication bypassed with malformed request URI on nginx
Authelia vulnerable to an authentication bypassed with malformed request URI on nginx
CVE-2020-5415High· 7.5GitLab auth uses full name instead of username as user ID, allowing impersonation
GitLab auth uses full name instead of username as user ID, allowing impersonation
CVE-2020-4037Medium· 4.3Open Redirect in OAuth2 Proxy
Open Redirect in OAuth2 Proxy
CVE-2020-26290Critical· 9.8Authentication Bypass in dex
Authentication Bypass in dex
CVE-2021-39183High· 8.2Unsafe inline XSS in pasting DOM element into chat
Unsafe inline XSS in pasting DOM element into chat
CVE-2021-41090Medium· 6.5Instance config inline secret exposure in Grafana
Instance config inline secret exposure in Grafana
CVE-2021-43784Medium· 6.0Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
CVE-2021-41278Medium· 5.4PoCBroken encryption in EdgeX Foundry
Broken encryption in EdgeX Foundry
GHSA-77vh-xpmg-72qhLow· 3.0Clarify `mediaType` handling
Clarify `mediaType` handling
GHSA-5j5w-g665-5m35Low· 3.0Ambiguous OCI manifest parsing
Ambiguous OCI manifest parsing
CVE-2021-41190Low· 3.0Clarify Content-Type handling
Clarify Content-Type handling
CVE-2021-41254High· 8.8Privilege escalation to cluster admin on multi-tenant environments
Privilege escalation to cluster admin on multi-tenant environments
CVE-2021-22565Medium· 6.5Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server
Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server
CVE-2021-3911Medium· 4.2Misconfigured IP address field in ROA leads to OctoRPKI crash
Misconfigured IP address field in ROA leads to OctoRPKI crash
CVE-2021-41230Medium· 5.3OIDC claims not updated from Identity Provider in Pomerium
OIDC claims not updated from Identity Provider in Pomerium
CVE-2021-3912Medium· 4.2OctoRPKI crashes when processing GZIP bomb returned via malicious repository
OctoRPKI crashes when processing GZIP bomb returned via malicious repository
CVE-2021-3908Medium· 5.9Infinite certificate chain depth results in OctoRPKI running forever
Infinite certificate chain depth results in OctoRPKI running forever
CVE-2021-3909Medium· 4.4Infinite open connection causes OctoRPKI to hang forever
Infinite open connection causes OctoRPKI to hang forever
CVE-2021-3910High· 7.5NUL character in ROA causes OctoRPKI to crash
NUL character in ROA causes OctoRPKI to crash
CVE-2021-41232High· 8.1Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker
Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker
CVE-2021-41173Medium· 5.7Geth Node Vulnerable to DoS via maliciously crafted p2p message
Geth Node Vulnerable to DoS via maliciously crafted p2p message
CVE-2021-41135Medium· 6.5Authz Module Non-Determinism
Authz Module Non-Determinism
CVE-2021-39226High· 7.3CISA KEVPoCAuthentication bypass for viewing and deletions of snapshots
Authentication bypass for viewing and deletions of snapshots
CVE-2021-41103Medium· 5.9Insufficiently restricted permissions on plugin directories
Insufficiently restricted permissions on plugin directories
CVE-2021-41088High· 8.0Elvish vulnerable to remote code execution via the web UI backend
Elvish vulnerable to remote code execution via the web UI backend