VulnSea

Tagged “go”

CVEs tagged go, newest first.

1749 CVEsRSS

CVE-2021-23365Critical· 9.1
5y ago

Authentication Bypass in tyk-identity-broker

Authentication Bypass in tyk-identity-broker

▾ Midnighttyktechnologies · github.com/tyktechnologies/tyk-identity-brokerEPSS 1.0%via OSV
CVE-2021-32690Medium
5y ago

Helm passes repository credentials to alternate domain

Helm passes repository credentials to alternate domain

▾ Sunlithelm · helm.sh/helm/v3EPSS 1.4%via OSV
CVE-2021-32923Medium· 6.5
5y ago

vault: Token leases incorrectly treated as non-expiring (CVE-2021-32923)

A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last sec…

▾ SunlitRed Hat · Red Hat Openshift Container Storage 4EPSS 1.4%via CSAF
CVE-2021-32635Medium· 6.3
5y ago

Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint

Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint

▾ Sunlitsylabs · github.com/sylabs/singularityEPSS 1.4%via OSV
CVE-2020-5303Low· 3.1
5y ago

Denial of service in Tendermint

Denial of service in Tendermint

▾ Sunlittendermint · github.com/tendermint/tendermintEPSS 1.4%via OSV
CVE-2020-11091Medium· 5.8
5y ago

Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements

Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements

▾ Sunlitweaveworks · github.com/weaveworks/weaveEPSS 0.86%via OSV
CVE-2020-5300Medium· 5.8
5y ago

Authentication Bypass in hydra

Authentication Bypass in hydra

▾ Sunlitory · github.com/ory/hydraEPSS 1.0%via OSV
CVE-2021-21291Medium· 5.4
5y ago

Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy

Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy

▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 1.6%via OSV
CVE-2021-28955Critical· 9.8
5y ago

Arbitrary code execution due to an uncontrolled search path for the git binary

Arbitrary code execution due to an uncontrolled search path for the git binary

▾ MidnightMichaelMure · github.com/MichaelMure/git-bugEPSS 1.7%via OSV
CVE-2021-30465High· 7.6
5y ago

mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs

mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs

▾ Twilightopencontainers · github.com/opencontainers/runcEPSS 6.6%via OSV
CVE-2021-28681Medium· 5.3
5y ago

In github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communication

In github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communication

▾ Sunlitpion · github.com/pion/webrtc/v3EPSS 0.68%via OSV
CVE-2021-29482High· 7.5
5y ago

github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

▾ Twilightulikunitz · github.com/ulikunitz/xzEPSS 1.4%via OSV
CVE-2020-15229High· 8.2
5y ago

Path traversal and files overwrite with unsquashfs in singularity

Path traversal and files overwrite with unsquashfs in singularity

▾ Twilightsylabs · github.com/sylabs/singularityEPSS 2.0%via OSV
CVE-2020-15223High· 8.0
5y ago

Ory fosite contains Improper Handling of Exceptional Conditions

Ory fosite contains Improper Handling of Exceptional Conditions

▾ Twilightory · github.com/ory/fositeEPSS 1.6%via OSV
CVE-2020-15257Medium· 5.2PoC
5y ago

containerd-shim API Exposed to Host Network Containers

containerd-shim API Exposed to Host Network Containers

▾ Twilightcontainerd · github.com/containerd/containerdEPSS 3.2%via OSV
CVE-2020-15222High· 8.1
5y ago

Token reuse in Ory fosite

Token reuse in Ory fosite

▾ Twilightory · github.com/ory/fositeEPSS 0.87%via OSV
CVE-2020-15233Medium· 6.1
5y ago

OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses

OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses

▾ Sunlitory · github.com/ory/fositeEPSS 0.80%via OSV
CVE-2020-13794Medium· 4.3
5y ago

Authenticated users can exploit an enumeration vulnerability in Harbor

Authenticated users can exploit an enumeration vulnerability in Harbor

▾ Sunlitgoharbor · github.com/goharbor/harborEPSS 1.3%via OSV
CVE-2020-15216Medium· 5.3
5y ago

github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass

github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass

▾ Sunlitrussellhaering · github.com/russellhaering/goxmldsigEPSS 0.90%via OSV
CVE-2020-15186Low· 3.4
5y ago

Improper Sanitizing of plugin names in helm

Improper Sanitizing of plugin names in helm

▾ Sunlithelm · helm.sh/helm/v3EPSS 0.96%via OSV
CVE-2020-25040High· 8.8
5y ago

Insecure permissions on build temporary rootfs in Singularity

Insecure permissions on build temporary rootfs in Singularity

▾ Twilightsylabs · github.com/sylabs/singularityEPSS 2.0%via OSV
CVE-2020-15185Low· 2.2
5y ago

Repository index file allows for duplicates of the same chart entry in helm

Repository index file allows for duplicates of the same chart entry in helm

▾ Sunlithelm · helm.sh/helm/v3EPSS 0.88%via OSV
CVE-2020-26213Medium· 5.9
5y ago

Denial-of-Service within Docker container

Denial-of-Service within Docker container

▾ Sunlitteler · ktbs.dev/telerEPSS 1.4%via OSV
CVE-2020-15187Low· 3.0
5y ago

plugin.yaml file allows for duplicate entries in helm

plugin.yaml file allows for duplicate entries in helm

▾ Sunlithelm · helm.sh/helm/v3EPSS 1.5%via OSV
CVE-2020-15184Low· 3.7
5y ago

Aliases are never checked in helm

Aliases are never checked in helm

▾ Sunlithelm · helm.sh/helm/v3EPSS 1.0%via OSV
CVE-2021-21404High· 7.5
5y ago

Crash due to malformed relay protocol message

Crash due to malformed relay protocol message

▾ Twilightsyncthing · github.com/syncthing/syncthingEPSS 2.0%via OSV
CVE-2021-23347Medium· 4.7
5y ago

Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2

Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.59%via OSV
CVE-2021-27098High· 8.1
5y ago

Legacy Node API Allows Impersonation in github.com/spiffe/spire/pkg/server/endpoints/node

Legacy Node API Allows Impersonation in github.com/spiffe/spire/pkg/server/endpoints/node

▾ Twilightspiffe · github.com/spiffe/spireEPSS 0.56%via OSV
CVE-2021-29652Medium· 6.1
5y ago

pomerium_signature is not verified in middleware in github.com/pomerium/pomerium

pomerium_signature is not verified in middleware in github.com/pomerium/pomerium

▾ Sunlitpomerium · github.com/pomerium/pomeriumEPSS 0.66%via OSV
CVE-2021-22538High· 8.8
5y ago

Privilege escalation in rbac

Privilege escalation in rbac

▾ Twilightgoogle · github.com/google/exposure-notifications-verification-serverEPSS 0.72%via OSV
CVEs tagged “go” — page 58 · VulnSea