Tagged “go”
CVEs tagged go, newest first.
1749 CVEsRSS
CVE-2021-23365Critical· 9.1Authentication Bypass in tyk-identity-broker
Authentication Bypass in tyk-identity-broker
CVE-2021-32690MediumHelm passes repository credentials to alternate domain
Helm passes repository credentials to alternate domain
CVE-2021-32923Medium· 6.5vault: Token leases incorrectly treated as non-expiring (CVE-2021-32923)
A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last sec…
CVE-2021-32635Medium· 6.3Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
CVE-2020-5303Low· 3.1Denial of service in Tendermint
Denial of service in Tendermint
CVE-2020-11091Medium· 5.8Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
CVE-2020-5300Medium· 5.8Authentication Bypass in hydra
Authentication Bypass in hydra
CVE-2021-21291Medium· 5.4Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy
Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy
CVE-2021-28955Critical· 9.8Arbitrary code execution due to an uncontrolled search path for the git binary
Arbitrary code execution due to an uncontrolled search path for the git binary
CVE-2021-30465High· 7.6mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
CVE-2021-28681Medium· 5.3In github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communication
In github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communication
CVE-2021-29482High· 7.5github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)
github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)
CVE-2020-15229High· 8.2Path traversal and files overwrite with unsquashfs in singularity
Path traversal and files overwrite with unsquashfs in singularity
CVE-2020-15223High· 8.0Ory fosite contains Improper Handling of Exceptional Conditions
Ory fosite contains Improper Handling of Exceptional Conditions
CVE-2020-15257Medium· 5.2PoCcontainerd-shim API Exposed to Host Network Containers
containerd-shim API Exposed to Host Network Containers
CVE-2020-15222High· 8.1Token reuse in Ory fosite
Token reuse in Ory fosite
CVE-2020-15233Medium· 6.1OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses
OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses
CVE-2020-13794Medium· 4.3Authenticated users can exploit an enumeration vulnerability in Harbor
Authenticated users can exploit an enumeration vulnerability in Harbor
CVE-2020-15216Medium· 5.3github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
CVE-2020-15186Low· 3.4Improper Sanitizing of plugin names in helm
Improper Sanitizing of plugin names in helm
CVE-2020-25040High· 8.8Insecure permissions on build temporary rootfs in Singularity
Insecure permissions on build temporary rootfs in Singularity
CVE-2020-15185Low· 2.2Repository index file allows for duplicates of the same chart entry in helm
Repository index file allows for duplicates of the same chart entry in helm
CVE-2020-26213Medium· 5.9Denial-of-Service within Docker container
Denial-of-Service within Docker container
CVE-2020-15187Low· 3.0plugin.yaml file allows for duplicate entries in helm
plugin.yaml file allows for duplicate entries in helm
CVE-2020-15184Low· 3.7Aliases are never checked in helm
Aliases are never checked in helm
CVE-2021-21404High· 7.5Crash due to malformed relay protocol message
Crash due to malformed relay protocol message
CVE-2021-23347Medium· 4.7Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2
CVE-2021-27098High· 8.1Legacy Node API Allows Impersonation in github.com/spiffe/spire/pkg/server/endpoints/node
Legacy Node API Allows Impersonation in github.com/spiffe/spire/pkg/server/endpoints/node
CVE-2021-29652Medium· 6.1pomerium_signature is not verified in middleware in github.com/pomerium/pomerium
pomerium_signature is not verified in middleware in github.com/pomerium/pomerium
CVE-2021-22538High· 8.8Privilege escalation in rbac
Privilege escalation in rbac