VulnSea

Tagged “go”

CVEs tagged go, newest first.

1746 CVEsRSS

CVE-2021-41087Medium· 5.6
5y ago

Improperly Implemented path matching for in-toto-golang

Improperly Implemented path matching for in-toto-golang

▾ Sunlitin-toto · github.com/in-toto/in-toto-golangEPSS 0.43%via OSV
CVE-2020-8561Medium· 4.1
5y ago

Confused Deputy in Kubernetes

Confused Deputy in Kubernetes

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 2.1%via OSV
CVE-2021-38698Medium· 6.5
5y ago

HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access…

HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.

▾ Sunlithashicorp · github.com/hashicorp/consulEPSS 1.4%via OSV
CVE-2021-3761High· 7.5
5y ago

OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values

OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values

▾ Twilightcloudflare · github.com/cloudflare/cfrpkiEPSS 1.2%via OSV
CVE-2021-36156Medium· 5.3
5y ago

Path traversal in Grafana Loki

Path traversal in Grafana Loki

▾ Sunlitgrafana · github.com/grafana/lokiEPSS 1.5%via OSV
CVE-2021-39156High· 8.1PoC
5y ago

Istio Fragments in Path May Lead to Authorization Policy Bypass

Istio Fragments in Path May Lead to Authorization Policy Bypass

▾ Midnightistio · istio.io/istioEPSS 1.2%via OSV
CVE-2021-39137Medium· 6.5
5y ago

Ethereum Contains Consensus Flaw During Block Processing

Ethereum Contains Consensus Flaw During Block Processing

▾ Sunlitethereum · github.com/ethereum/go-ethereumEPSS 1.3%via OSV
CVE-2021-39155High· 8.3
5y ago

Authorization Policy Bypass Due to Case Insensitive Host Comparison

Authorization Policy Bypass Due to Case Insensitive Host Comparison

▾ Twilightistio · istio.io/istioEPSS 1.2%via OSV
CVE-2021-32783High· 8.5
5y ago

ExternalName Services can be used to gain access to Envoy's admin interface

ExternalName Services can be used to gain access to Envoy's admin interface

▾ Twilightprojectcontour · github.com/projectcontour/contourEPSS 1.2%via OSV
CVE-2021-38554Medium· 5.3
5y ago

vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser (CVE-2021-38554)

A flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the p…

▾ SunlitRed Hat · Red Hat Openshift Container Storage 4EPSS 0.91%via CSAF
CVE-2021-32813Medium· 4.8
5y ago

Header dropping in traefik

Header dropping in traefik

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 1.1%via OSV
CVE-2021-32574High· 7.5
5y ago

Hashicorp Consul Missing SSL Certificate Validation

Hashicorp Consul Missing SSL Certificate Validation

▾ Twilighthashicorp · github.com/hashicorp/consulEPSS 1.5%via OSV
CVE-2021-32760Medium· 5.5
5y ago

containerd: pulling and extracting crafted container image may result in Unix file permission changes (CVE-2021-32760)

A flaw was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expe…

▾ SunlitRed Hat · RHOSSM 2.4 for RHEL 8EPSS 1.6%via CSAF
CVE-2021-3602Medium· 5.5
5y ago

Buildah processes using chroot isolation may leak environment values to intermediate processes

Buildah processes using chroot isolation may leak environment values to intermediate processes

▾ Sunlitcontainers · github.com/containers/buildahEPSS 0.33%via OSV
CVE-2021-32721Medium· 4.7
5y ago

Open Redirect in github.com/AndrewBurian/powermux

Open Redirect in github.com/AndrewBurian/powermux

▾ SunlitAndrewBurian · github.com/AndrewBurian/powermuxEPSS 0.61%via OSV
CVE-2020-26242Medium· 6.5
5y ago

Denial of service in geth

Denial of service in geth

▾ Sunlitethereum · github.com/ethereum/go-ethereumEPSS 1.5%via OSV
CVE-2020-15111Medium· 4.2
5y ago

CRLF vulnerability in Fiber

CRLF vulnerability in Fiber

▾ Sunlitgofiber · github.com/gofiber/fiberEPSS 0.86%via OSV
CVE-2020-26241Medium· 6.5
5y ago

Shallow copy bug in geth

Shallow copy bug in geth

▾ Sunlitethereum · github.com/ethereum/go-ethereumEPSS 1.2%via OSV
GHSA-vfvf-6gx5-mqv6High· 7.5
5y ago

Incorrect Authorization in ORY Oathkeeper

Incorrect Authorization in ORY Oathkeeper

▾ Twilightory · github.com/ory/oathkeepervia OSV
CVE-2020-27846Critical· 9.8
5y ago

XML Processing error in github.com/crewjam/saml

XML Processing error in github.com/crewjam/saml

▾ Midnightcrewjam · github.com/crewjam/samlEPSS 4.9%via OSV
CVE-2020-26279High· 7.7
5y ago

Path traversal in github.com/ipfs/go-ipfs

Path traversal in github.com/ipfs/go-ipfs

▾ Twilightipfs · github.com/ipfs/go-ipfsEPSS 1.7%via OSV
GHSA-qvp4-rpmr-xwrrHigh· 7.5
5y ago

Possible bypass of token claim validation when OAuth2 Introspection caching is enabled

Possible bypass of token claim validation when OAuth2 Introspection caching is enabled

▾ Twilightory · github.com/ory/oathkeepervia OSV
CVE-2020-4053Low· 3.7
5y ago

Plugin archive directory traversal in Helm

Plugin archive directory traversal in Helm

▾ Sunlithelm · helm.sh/helm/v3EPSS 1.5%via OSV
CVE-2021-32699Medium· 6.5
5y ago

Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings

Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings

▾ Sunlitpterodactyl · github.com/pterodactyl/wingsEPSS 0.27%via OSV
CVE-2021-21303Medium· 6.5
5y ago

Improper Neutralization of Special Elements in Output in helm.sh/helm/v3

Improper Neutralization of Special Elements in Output in helm.sh/helm/v3

▾ Sunlithelm · helm.sh/helm/v3EPSS 1.0%via OSV
CVE-2020-7667High· 7.5
5y ago

github.com/sassoftware/go-rpmutils Arbitrary File Write via Archive Extraction (Zip Slip)

github.com/sassoftware/go-rpmutils Arbitrary File Write via Archive Extraction (Zip Slip)

▾ Twilightsassoftware · github.com/sassoftware/go-rpmutilsEPSS 1.6%via OSV
CVE-2020-26284High· 7.7
5y ago

Hugo can execute a binary from the current directory on Windows

Hugo can execute a binary from the current directory on Windows

▾ Twilightgohugoio · github.com/gohugoio/hugoEPSS 1.5%via OSV
CVE-2021-23365Critical· 9.1
5y ago

Authentication Bypass in tyk-identity-broker

Authentication Bypass in tyk-identity-broker

▾ Midnighttyktechnologies · github.com/tyktechnologies/tyk-identity-brokerEPSS 1.0%via OSV
CVE-2021-32690Medium
5y ago

Helm passes repository credentials to alternate domain

Helm passes repository credentials to alternate domain

▾ Sunlithelm · helm.sh/helm/v3EPSS 1.4%via OSV
CVE-2021-32923Medium· 6.5
5y ago

vault: Token leases incorrectly treated as non-expiring (CVE-2021-32923)

A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last sec…

▾ SunlitRed Hat · Red Hat Openshift Container Storage 4EPSS 1.4%via CSAF
CVEs tagged “go” — page 57 · VulnSea