Tagged “go”
CVEs tagged go, newest first.
1746 CVEsRSS
CVE-2021-41087Medium· 5.6Improperly Implemented path matching for in-toto-golang
Improperly Implemented path matching for in-toto-golang
CVE-2020-8561Medium· 4.1Confused Deputy in Kubernetes
Confused Deputy in Kubernetes
CVE-2021-38698Medium· 6.5HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access…
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.
CVE-2021-3761High· 7.5OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values
OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values
CVE-2021-36156Medium· 5.3Path traversal in Grafana Loki
Path traversal in Grafana Loki
CVE-2021-39156High· 8.1PoCIstio Fragments in Path May Lead to Authorization Policy Bypass
Istio Fragments in Path May Lead to Authorization Policy Bypass
CVE-2021-39137Medium· 6.5Ethereum Contains Consensus Flaw During Block Processing
Ethereum Contains Consensus Flaw During Block Processing
CVE-2021-39155High· 8.3Authorization Policy Bypass Due to Case Insensitive Host Comparison
Authorization Policy Bypass Due to Case Insensitive Host Comparison
CVE-2021-32783High· 8.5ExternalName Services can be used to gain access to Envoy's admin interface
ExternalName Services can be used to gain access to Envoy's admin interface
CVE-2021-38554Medium· 5.3vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser (CVE-2021-38554)
A flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the p…
CVE-2021-32813Medium· 4.8Header dropping in traefik
Header dropping in traefik
CVE-2021-32574High· 7.5Hashicorp Consul Missing SSL Certificate Validation
Hashicorp Consul Missing SSL Certificate Validation
CVE-2021-32760Medium· 5.5containerd: pulling and extracting crafted container image may result in Unix file permission changes (CVE-2021-32760)
A flaw was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expe…
CVE-2021-3602Medium· 5.5Buildah processes using chroot isolation may leak environment values to intermediate processes
Buildah processes using chroot isolation may leak environment values to intermediate processes
CVE-2021-32721Medium· 4.7Open Redirect in github.com/AndrewBurian/powermux
Open Redirect in github.com/AndrewBurian/powermux
CVE-2020-26242Medium· 6.5Denial of service in geth
Denial of service in geth
CVE-2020-15111Medium· 4.2CRLF vulnerability in Fiber
CRLF vulnerability in Fiber
CVE-2020-26241Medium· 6.5Shallow copy bug in geth
Shallow copy bug in geth
GHSA-vfvf-6gx5-mqv6High· 7.5Incorrect Authorization in ORY Oathkeeper
Incorrect Authorization in ORY Oathkeeper
CVE-2020-27846Critical· 9.8XML Processing error in github.com/crewjam/saml
XML Processing error in github.com/crewjam/saml
CVE-2020-26279High· 7.7Path traversal in github.com/ipfs/go-ipfs
Path traversal in github.com/ipfs/go-ipfs
GHSA-qvp4-rpmr-xwrrHigh· 7.5Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
CVE-2020-4053Low· 3.7Plugin archive directory traversal in Helm
Plugin archive directory traversal in Helm
CVE-2021-32699Medium· 6.5Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
CVE-2021-21303Medium· 6.5Improper Neutralization of Special Elements in Output in helm.sh/helm/v3
Improper Neutralization of Special Elements in Output in helm.sh/helm/v3
CVE-2020-7667High· 7.5github.com/sassoftware/go-rpmutils Arbitrary File Write via Archive Extraction (Zip Slip)
github.com/sassoftware/go-rpmutils Arbitrary File Write via Archive Extraction (Zip Slip)
CVE-2020-26284High· 7.7Hugo can execute a binary from the current directory on Windows
Hugo can execute a binary from the current directory on Windows
CVE-2021-23365Critical· 9.1Authentication Bypass in tyk-identity-broker
Authentication Bypass in tyk-identity-broker
CVE-2021-32690MediumHelm passes repository credentials to alternate domain
Helm passes repository credentials to alternate domain
CVE-2021-32923Medium· 6.5vault: Token leases incorrectly treated as non-expiring (CVE-2021-32923)
A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last sec…