Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

go Security Advisories

Loading...
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZodjMtN2MzNC00aHg4
Hashicorp Nomad Information Exposure Through Environmental Variables
Ecosystems: go
Packages: github.com/hashicorp/nomad
Source: GitHub Advisory Database
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS02Z2NnLWhwMngtcTU0aM4AAgdM
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server
Ecosystems: go
Packages: github.com/argoproj/argo-cd/v2
Source: GitHub Advisory Database
Published: about 1 year ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc2djItcWNobS1ncmo3
Insecure permissions on user namespace / fakeroot temporary rootfs in Singularity
Ecosystems: go
Packages: github.com/sylabs/singularity
Source: GitHub Advisory Database
Published: over 1 year ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWp2OWMtdzc0cS02NzYy
Insecure permissions on build temporary rootfs in Singularity
Ecosystems: go
Packages: github.com/sylabs/singularity
Source: GitHub Advisory Database
Published: about 2 years ago
Critical
GSA_kwCzR0hTQS1qcnBnLTM1aHctbTRwOc0ptg
Capture-replay in Gitea
Ecosystems: go
Packages: github.com/go-gitea/gitea
Source: GitHub Advisory Database
Published: over 1 year ago
High
GSA_kwCzR0hTQS03N3JtLTl4OWgteGozZ80mxQ
NULL Pointer Dereference in Protocol Buffers
Ecosystems: pypi, go, maven, packagist, nuget
Packages: protobuf, github.com/protocolbuffers/protobuf, com.google.protobuf:protobuf-parent, google/protobuf, Google.Protobuf
Source: GitHub Advisory Database
Published: over 1 year ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW01NHItdnJtdi1odzMz
Improper Sanitizing of plugin names in helm
Ecosystems: go
Packages: helm.sh/helm/v3/pkg/plugin, helm.sh/helm, helm.sh/helm/v3
Source: GitHub Advisory Database
Published: about 2 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM1MmYtcHE0Ny0ycjlq
plugin.yaml file allows for duplicate entries in helm
Ecosystems: go
Packages: helm.sh/helm/v3/pkg/plugin, helm.sh/helm, helm.sh/helm/v3
Source: GitHub Advisory Database
Published: about 2 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE1NDctZ21mOC04anI3
Signature Validation Bypass in goxmldsig
Ecosystems: go
Packages: github.com/russellhaering/goxmldsig
Source: GitHub Advisory Database
Published: about 2 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdyZnAtcTJtbS1oZnA2
Redirect URL matching ignores character casing
Ecosystems: go
Packages: github.com/ory/fosite
Source: GitHub Advisory Database
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS0zM3BnLW02amgtNTIzN84AAyiu
Docker Swarm encrypted overlay network traffic may be unencrypted
Ecosystems: go
Packages: github.com/docker/docker
Source: GitHub Advisory Database
Published: 2 months ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJmcTMtdzU0Yy1mOXE1
OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses
Ecosystems: go
Packages: github.com/ory/fosite
Source: GitHub Advisory Database
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS02d3JmLW14ZmotcGY1cM4AAyit
Docker Swarm encrypted overlay network with a single endpoint is unauthenticated
Ecosystems: go
Packages: github.com/docker/docker
Source: GitHub Advisory Database
Published: 2 months ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTM2eHctZng3OC1jNXI0
containerd-shim API Exposed to Host Network Containers
Ecosystems: go
Packages: github.com/containerd/containerd/cmd, github.com/containerd/containerd
Source: GitHub Advisory Database
Published: about 2 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpoajYtNW1oNi00cHZm
Denial-of-Service within Docker container
Ecosystems: go
Packages: ktbs.dev/teler/pkg/errors
Source: GitHub Advisory Database
Published: about 2 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW04OTgtaDRwbS1wcWZy
Arbitrary code execution due to an uncontrolled search path for the git binary
Ecosystems: go
Packages: github.com/MichaelMure/git-bug/repository, github.com/MichaelMure/git-bug
Source: GitHub Advisory Database
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS01M2M0LWhobWgtdnc1cc4AAwWx
Helm vulnerable to denial of service through through repository index file
Ecosystems: go
Packages: helm.sh/helm/v3
Source: GitHub Advisory Database
Published: 6 months ago
Moderate
GSA_kwCzR0hTQS14eGZ4LXcycnctZ2g2M84AAwVh
csaf-poc/csaf_distribution Cross-site Scripting vulnerability
Ecosystems: go
Packages: github.com/csaf-poc/csaf_distribution
Source: GitHub Advisory Database
Published: 6 months ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV2OTUtdjhjOC0zcmg2
Privilege escalation in rbac
Ecosystems: go
Packages: github.com/google/exposure-notifications-verification-server
Source: GitHub Advisory Database
Published: about 2 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW00NWctZjQ1eC12djIy
Improper input validation in CNCF Cortex
Ecosystems: go
Packages: github.com/cortexproject/cortex
Source: GitHub Advisory Database
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS02NXY4LTZwdnctand2cc4AAyq3
Answer vulnerable to Insertion of Sensitive Information Into Sent Data
Ecosystems: go
Packages: github.com/answerdev/answer
Source: GitHub Advisory Database
Published: about 2 months ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg0NjItODlwZi02cjVo
Crash due to malformed relay protocol message
Ecosystems: go
Packages: github.com/syncthing/syncthing
Source: GitHub Advisory Database
Published: about 2 years ago
High
GSA_kwCzR0hTQS00OTk5LTY1OXctbXEzNs0XMg
Authentication bypass issue in the Operator Console
Ecosystems: go
Packages: github.com/minio/console
Source: GitHub Advisory Database
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS05NTdtLWc2cmYtNGMybc4AAwQc
Alist Cross-site Scripting vulnerability
Ecosystems: go
Packages: github.com/alist-org/alist/v3
Source: GitHub Advisory Database
Published: 6 months ago
High
GSA_kwCzR0hTQS00Z2pyLXZnZngtOXF2d84AAwP5
AList vulnerable to Improper Preservation of Permissions
Ecosystems: go
Packages: github.com/alist-org/alist/v3
Source: GitHub Advisory Database
Published: 6 months ago
High
GSA_kwCzR0hTQS00cjc4LWh4NzUtampqMs39zQ
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
Ecosystems: go
Packages: golang.org/x/net, golang.org/x/net/html
Source: GitHub Advisory Database
Published: about 1 year ago
High
GSA_kwCzR0hTQS1mY2Y5LTZmdjItZmM1ds39nQ
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
Ecosystems: go
Packages: golang.org/x/net, golang.org/x/net/html
Source: GitHub Advisory Database
Published: about 1 year ago
High
GSA_kwCzR0hTQS1wZzVwLXd3cDgtOTdnOM4AAy3v
Debug mode leaks confidential data in Cilium
Ecosystems: go
Packages: github.com/cilium/cilium
Source: GitHub Advisory Database
Published: about 2 months ago
Moderate
GSA_kwCzR0hTQS00Y3J3LXc4cHctMmhtZs4AAwOT
Buildah (as part of Podman) vulnerable to Link Following
Ecosystems: go
Packages: github.com/containers/podman/v4
Source: GitHub Advisory Database
Published: 6 months ago
High
GSA_kwCzR0hTQS14MzlqLWg4NWgtM2Y0Ns4AAwNX
go-merkledag's ProtoNode may be modified such that common method calls may panic
Ecosystems: go
Packages: github.com/ipfs/go-merkledag
Source: GitHub Advisory Database
Published: 6 months ago
Moderate
GSA_kwCzR0hTQS00Njh3LTh4MzktZ2o1ds4AAwNU
Traefik routes exposed with an empty TLSOption
Ecosystems: go
Packages: github.com/traefik/traefik/v2
Source: GitHub Advisory Database
Published: 6 months ago
Low
GSA_kwCzR0hTQS1odzdjLTNyZmctcDQ2as4AAyHf
Panic leading to denial of service
Ecosystems: go
Packages: google.golang.org/protobuf
Source: GitHub Advisory Database
Published: 3 months ago
High
GSA_kwCzR0hTQS0zOXFjLTk2aDctOTU2Zs4AAhsE
golang.org/x/net/http vulnerable to a reset flood
Ecosystems: go
Packages: golang.org/x/net, golang.org/x/net/http
Source: GitHub Advisory Database
Published: about 1 year ago
High
GSA_kwCzR0hTQS1mOTNmLTU1YzItOGM4Oc4AAwL_
Casdoor arbitrary file deletion vulnerability via uploadFile function
Ecosystems: go
Packages: github.com/casdoor/casdoor
Source: GitHub Advisory Database
Published: 6 months ago
High
GSA_kwCzR0hTQS1xcmc3LWhmeDctOTVjNc4AAxJC
Command injection in Git package in Wrangler
Ecosystems: go
Packages: github.com/rancher/wrangler
Source: GitHub Advisory Database
Published: 4 months ago
High
GSA_kwCzR0hTQS00djQ4LTRxNW0tOHZ4NM4AAwJ2
Prometheus vulnerable to basic authentication bypass
Ecosystems: go
Packages: github.com/prometheus/prometheus/v2, github.com/prometheus/prometheus
Source: GitHub Advisory Database
Published: 6 months ago
Moderate
GSA_kwCzR0hTQS00N3hoLXF4cXYtbWd2Z84AAwIN
kube-httpcache is vulnerable to Cross-Site Request Forgery (CSRF)
Ecosystems: go
Packages: github.com/mittwald/kube-httpcache
Source: GitHub Advisory Database
Published: 6 months ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhoZzItcnZtOC13Mmpo
Cross-site Request Forgery (CSRF)
Ecosystems: go
Packages: github.com/rancher/rancher/server
Source: GitHub Advisory Database
Published: about 2 years ago
Critical
GSA_kwCzR0hTQS1jdmg0LWNqYzktODRxbc4AAwFH
owncast is vulnerable to SQL Injection
Ecosystems: go
Packages: github.com/owncast/owncast
Source: GitHub Advisory Database
Published: 6 months ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg2bWotdzRqZi1qbWd3
Server Side Request Forgery (SSRF) in Kubernetes
Ecosystems: go
Packages: github.com/kubernetes/kubernetes/pkg/volume/storageos
Source: GitHub Advisory Database
Published: over 1 year ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI1eGotODlnNS1mbTZo
Information Disclosure in HashiCorp Vault
Ecosystems: go
Packages: github.com/hashicorp/vault/command
Source: GitHub Advisory Database
Published: about 2 years ago
Low
GSA_kwCzR0hTQS00MzQ4LXgyOTItaDQzN84AAwoe
GoBase Race Condition vulnerability
Ecosystems: go
Packages: github.com/ntbosscher/gobase
Source: GitHub Advisory Database
Published: 5 months ago
High
GSA_kwCzR0hTQS12dnB4LWo4ZjMtM3c2aM4AAxtM
Uncontrolled Resource Consumption
Ecosystems: go
Packages: golang.org/x/net
Source: GitHub Advisory Database
Published: 4 months ago
Moderate
GSA_kwCzR0hTQS1jbTl4LWMzcmgtN3JjNM4AAwpl
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
Ecosystems: go
Packages: github.com/cri-o/cri-o
Source: GitHub Advisory Database
Published: 5 months ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM3MnAtOXhtai1yeDN3
Archive package allows chmod of file outside of unpack target directory
Ecosystems: go
Packages: github.com/containerd/containerd
Source: GitHub Advisory Database
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS01anBoLXdycTctdjloZs4AAwBJ
Denial of service in Mattermost
Ecosystems: go
Packages: github.com/mattermost/mattermost-server
Source: GitHub Advisory Database
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS1xd3F2LXJxZ2YtOHFoOM4AAyWs
Podman Time-of-check Time-of-use (TOCTOU) Race Condition
Ecosystems: go
Packages: github.com/containers/podman/v4
Source: GitHub Advisory Database
Published: 2 months ago
Critical
GSA_kwCzR0hTQS1wbWcyLXJwaDgtcDhyNs4AAwYe
Alist vulnerable to Path Traversal
Ecosystems: go
Packages: github.com/alist-org/alist/v3
Source: GitHub Advisory Database
Published: 6 months ago
High
GSA_kwCzR0hTQS1wNWdjLTk1N3gtZ2Z3Oc4AAWV1
Go Ethereum LES protocol implementation vulnerable to Denial of Service
Ecosystems: go
Packages: github.com/ethereum/go-ethereum, github.com/ethereum/go-ethereum/les
Source: GitHub Advisory Database
Published: about 1 year ago
High
GSA_kwCzR0hTQS1ndzJnLWhoYzktd2dqaM4AAv5M
Missing Authorization in HashiCorp Consul
Ecosystems: go
Packages: github.com/hashicorp/consul
Source: GitHub Advisory Database
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS02N2Z4LXd4NzgtangzM84AAwWy
Helm vulnerable to denial of service through schema file
Ecosystems: go
Packages: helm.sh/helm/v3
Source: GitHub Advisory Database
Published: 6 months ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdxdzgtODQ3Zi1wZ2dt
Improper Locking in github.com/containers/storage
Ecosystems: go
Packages: github.com/containers/storage
Source: GitHub Advisory Database
Published: about 2 years ago
High
GSA_kwCzR0hTQS1meGc1LXdxNngtdnI0d84AAw-p
golang.org/x/net/http2/h2c vulnerable to request smuggling attack
Ecosystems: go
Packages: golang.org/x/net, golang.org/x/net/http2/h2c
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1xY2NtLXdtY3EtcHdyNs4AAv_M
Tailscale daemon is vulnerable to information disclosure via CSRF
Ecosystems: go
Packages: tailscale.com/cmd
Source: GitHub Advisory Database
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS02NzJwLW01anEtbXJoOM4AAv-o
Insufficient Verification of Proofs generated by the immudb server in client SDK.
Ecosystems: go
Packages: github.com/codenotary/immudb
Source: GitHub Advisory Database
Published: 7 months ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWMzeG0tcHZnNy1naDdy
mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
Ecosystems: go
Packages: github.com/opencontainers/runc
Source: GitHub Advisory Database
Published: about 2 years ago
High
GSA_kwCzR0hTQS1qcjc3LThneDQtaDVxaM4AAv0s
MessagePack for Golang subject to DoS via Unmarshal panic
Ecosystems: go
Packages: github.com/shamaton/msgpack/v2
Source: GitHub Advisory Database
Published: 7 months ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdxNXItY2M0dy1nOHhm
gosaml2 is vulnerable to NULL Pointer Dereference
Ecosystems: go
Packages: github.com/russellhaering/goxmldsig, github.com/russellhaering/gosaml2
Source: GitHub Advisory Database
Published: almost 2 years ago
High
GSA_kwCzR0hTQS04Z2c4LXdyNGotdjJ3cs4AAyPI
Gophish vulnerable to Denial of Service via crafted payload involving autofocus
Ecosystems: go
Packages: github.com/gophish/gophish
Source: GitHub Advisory Database
Published: 3 months ago
High
GSA_kwCzR0hTQS13NHhoLXczM3AtNHYyOc4AATSj
GitHub Git LFS Improper Input Validation vulnerability
Ecosystems: go
Packages: github.com/git-lfs/git-lfs, github.com/git-lfs/git-lfs/lfsapi
Source: GitHub Advisory Database
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS05OWc1LTU2NDMteHBocM4AAv0J
mm-wiki is vulnerable to Cross-Site Scripting (XSS)
Ecosystems: go
Packages: github.com/phachon/mm-wiki
Source: GitHub Advisory Database
Published: 7 months ago
High
GSA_kwCzR0hTQS02YzZwLWg3OWYtZzZwNM4AAvxx
Istio may allow identity impersonation if user has localhost access
Ecosystems: go
Packages: github.com/istio/istio
Source: GitHub Advisory Database
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS01NW05LWhtOTIteG04as4AAyPG
Gophish vulnerable to Cross-site Scripting via crafted landing page
Ecosystems: go
Packages: github.com/gophish/gophish
Source: GitHub Advisory Database
Published: 3 months ago
High
GSA_kwCzR0hTQS12cHZtLTN3cTItMnd2bc4AAx7I
Opencontainers runc Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/opencontainers/runc
Source: GitHub Advisory Database
Published: 3 months ago
High
GSA_kwCzR0hTQS13bXJ4LTU3aG0tbXc3cs0s7Q
Arbitrary file reads in HashiCorp Nomad
Ecosystems: go
Packages: github.com/hashicorp/nomad
Source: GitHub Advisory Database
Published: over 1 year ago
Critical
GSA_kwCzR0hTQS03ZnhqLWZyM3Ytcjlnas4AAvtj
TiDB vulnerable to Use of Externally-Controlled Format String
Ecosystems: go
Packages: github.com/pingcap/tidb
Source: GitHub Advisory Database
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS02NDJxLTJxNjgtOWozcM4AAwp-
usememos/memos Cross-Site Request Forgery vulnerability
Ecosystems: go
Packages: github.com/usememos/memos
Source: GitHub Advisory Database
Published: 5 months ago
Moderate
GSA_kwCzR0hTQS14Mjc5LTY4cnItanA0cM4AAvME
Blst vulnerable to incorrect results for some inputs in blst_fp_eucl_inverse function
Ecosystems: go
Packages: github.com/supranational/blst
Source: GitHub Advisory Database
Published: 8 months ago
Critical
GSA_kwCzR0hTQS03Z2M0LXI1anItOWh4ds4AAvim
Gin-vue-admin subject to Remote Code Execution via file upload vulnerability
Ecosystems: go
Packages: github.com/flipped-aurora/gin-vue-admin/server
Source: GitHub Advisory Database
Published: 8 months ago
Critical
GSA_kwCzR0hTQS13OHh3LTdjcmYtaDIzeM4AAvXZ
Gitea vulnerable to Argument Injection
Ecosystems: go
Packages: github.com/go-gitea/gitea
Source: GitHub Advisory Database
Published: 8 months ago
High
GSA_kwCzR0hTQS1wbXc5LTU2N3AtNjhwY84AAvmZ
OctoRPKI crashes when max iterations is reached
Ecosystems: go
Packages: github.com/cloudflare/cfrpki/cmd/octorpki
Source: GitHub Advisory Database
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS14cXYyLTN2dnEtcWc2cs4AAvkJ
Hashicorp Boundary vulnerable to clickjacking
Ecosystems: go
Packages: github.com/hashicorp/boundary
Source: GitHub Advisory Database
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS01OWhqLTYyZjUtZmdtY84AAvg6
free5GC vulnerable to malformed NGAP message crashing the AMF and NGAP decoders
Ecosystems: go
Packages: github.com/free5gc/free5gc
Source: GitHub Advisory Database
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS1mNHA1LXg0dmMtbWg0ds4AAvcq
Improper use of metav1.Duration allows for Denial of Service
Ecosystems: go
Packages: github.com/fluxcd/image-reflector-controller, github.com/fluxcd/image-automation-controller, github.com/fluxcd/notification-controller, github.com/fluxcd/helm-controller, github.com/fluxcd/kustomize-controller, github.com/fluxcd/source-controller, github.com/fluxcd/flux2
Source: GitHub Advisory Database
Published: 8 months ago
High
GSA_kwCzR0hTQS1qOTJjLW1tZjctajV4Nc4AAvaR
Potential inter-blockchain communication (IBC) protocol compromise via "Dragonberry" vulnerability in cheqd
Ecosystems: go
Packages: github.com/cheqd/cheqd-node
Source: GitHub Advisory Database
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS1td3djLTNqdjItNjJqM84AAvPW
AdGuardHome vulnerable to Cross-Site Request Forgery
Ecosystems: go
Packages: github.com/AdguardTeam/AdGuardHome
Source: GitHub Advisory Database
Published: 8 months ago
High
GSA_kwCzR0hTQS1oYzgyLXc5djgtODNwcs4AAv8P
Witness Block Parsing DoS Vulnerability
Ecosystems: go
Packages: github.com/lightningnetwork/lnd
Source: GitHub Advisory Database
Published: 7 months ago
Low
GSA_kwCzR0hTQS1mOWpnLThwMzItMmY1Nc0hRw
ANSI escape characters not filtered
Ecosystems: go
Packages: k8s.io/kubernetes/pkg/kubectl
Source: GitHub Advisory Database
Published: over 1 year ago
Critical
GSA_kwCzR0hTQS1ncjd3LXgyanAtM3hnd84AAvLr
Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication
Ecosystems: go
Packages: github.com/caddyserver/caddy
Source: GitHub Advisory Database
Published: 8 months ago
Low
GSA_kwCzR0hTQS1oOGc5LTZndmgtNW1yY84AAvLt
etcd vulnerable to TOCTOU of gateway endpoint authentication
Ecosystems: go
Packages: go.etcd.io/etcd/v3
Source: GitHub Advisory Database
Published: 8 months ago
High
GSA_kwCzR0hTQS13cjNjLWczMjYtNDg2Y84AAw0t
GitOps Run allows for Kubernetes workload injection
Ecosystems: go
Packages: github.com/weaveworks/weave-gitops
Source: GitHub Advisory Database
Published: 5 months ago
Critical
GSA_kwCzR0hTQS1wZm13LXZqNzQtcGg4Z80YjQ
HashiCorp Vault Incorrect Permission Assignment for Critical Resource
Ecosystems: go
Packages: github.com/hashicorp/vault
Source: GitHub Advisory Database
Published: over 1 year ago
Critical
GSA_kwCzR0hTQS01bTdnLXBqOHctNzU5M84AAvxv
Vela Insecure Defaults
Ecosystems: go
Packages: github.com/go-vela/worker, github.com/go-vela/server
Source: GitHub Advisory Database
Published: 7 months ago
High
GSA_kwCzR0hTQS0ydzZtLXE5NDYtMzk5cs4AAvKQ
Dapr Dashboard vulnerable to Incorrect Access Control
Ecosystems: go
Packages: github.com/dapr/dashboard
Source: GitHub Advisory Database
Published: 8 months ago
Critical
GSA_kwCzR0hTQS12aDdnLXAyNmMtajJjd84AAvJw
Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code
Ecosystems: go
Packages: github.com/dexidp/dex
Source: GitHub Advisory Database
Published: 8 months ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZnNWYtZjVwbS1tanJn
Vulnerability in Istio
Ecosystems: go
Packages: istio.io/istio/pkg/log
Source: GitHub Advisory Database
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS1jdng4LXBwbWMtNzhobc4AAuFn
Duplicate Advisory: KubeVirt arbitrary host file read from the VM
Ecosystems: go
Packages: kubevirt.io/kubevirt
Source: GitHub Advisory Database
Published: 10 months ago
High
GSA_kwCzR0hTQS1wNmZoLXhjNnItZzVod84AAvFp
Brokercap Bifrost subject to authentication bypass when using HTTP basic authentication
Ecosystems: go
Packages: github.com/brokercap/Bifrost
Source: GitHub Advisory Database
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS05dzh4LTVodjUtcjZnd84AAxpQ
Cross Site Scripting in usememos/memos
Ecosystems: go
Packages: github.com/usememos/memos
Source: GitHub Advisory Database
Published: 4 months ago
Critical
GSA_kwCzR0hTQS1nN2o3LWg0cTgtOHcyZs4AAvAZ
Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
Ecosystems: go
Packages: github.com/rancher/rancher
Source: GitHub Advisory Database
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS1mZzI1LWdxOWctMzJteM4AAu9Y
Cross site scripting in Cloudreve
Ecosystems: go
Packages: github.com/cloudreve/Cloudreve/v3, github.com/HFO4/cloudreve
Source: GitHub Advisory Database
Published: 9 months ago
High
GSA_kwCzR0hTQS1waGpyLThqOTItdzV2N84AAu6n
CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure
Ecosystems: go
Packages: github.com/cri-o/cri-o
Source: GitHub Advisory Database
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS1jZjdnLWNtN3EtcnE3Zs4AAu8S
SFTPGo WebClient vulnerable to Cross-site Scripting
Ecosystems: go
Packages: github.com/drakkan/sftpgo
Source: GitHub Advisory Database
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS02Y3ZmLW01OHEtaDl3Zs4AAxwk
Answer vulnerable to Cross-site Scripting
Ecosystems: go
Packages: github.com/answerdev/answer
Source: GitHub Advisory Database
Published: 4 months ago
Critical
GSA_kwCzR0hTQS1ocm0zLTN4bTYteDMzaM4AAwoO
golang-nanoauth authentication bypass vulnerability
Ecosystems: go
Packages: github.com/nanobox-io/golang-nanoauth
Source: GitHub Advisory Database
Published: 5 months ago
High
GSA_kwCzR0hTQS1xajZyLWZocmMtamo1cs4AAvUB
Remote denial of service in Hyperledger Fabric Gateway
Ecosystems: go
Packages: github.com/hyperledger/fabric
Source: GitHub Advisory Database
Published: 8 months ago
High
GSA_kwCzR0hTQS14aG1mLW1tdjItNGhoeM4AAu14
Go-CVSS has Out-of-bounds Read vulnerability in ParseVector function
Ecosystems: go
Packages: github.com/pandatix/go-cvss
Source: GitHub Advisory Database
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS1yYzRyLXdoMnEtcTZjNM4AAu15
Moby supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions
Ecosystems: go
Packages: github.com/moby/moby
Source: GitHub Advisory Database
Published: 9 months ago
High
GSA_kwCzR0hTQS1wMmc3LXh3dnItcnJ3M84AAu1q
Helm Controller denial of service
Ecosystems: go
Packages: github.com/fluxcd/flux2, github.com/fluxcd/helm-controller
Source: GitHub Advisory Database
Published: 9 months ago
High
GSA_kwCzR0hTQS1nd2M5LW03cmgtajJ3d84AAup1
x/crypto/ssh vulnerable to panic via SSH server
Ecosystems: go
Packages: golang.org/x/crypto
Source: GitHub Advisory Database
Published: 9 months ago
Filter by Package
github.com/usememos/memos 55 github.com/answerdev/answer 29 gogs.io/gogs 22 github.com/argoproj/argo-cd 19 github.com/hashicorp/nomad 18 github.com/ethereum/go-ethereum 15 github.com/rancher/rancher 14 helm.sh/helm/v3 13 github.com/hashicorp/vault 13 k8s.io/kubernetes 13 github.com/goharbor/harbor 13 github.com/docker/docker 12 github.com/argoproj/argo-cd/v2 12 golang.org/x/net 12 github.com/hashicorp/consul 12 github.com/containerd/containerd 11 github.com/opencontainers/runc 11 github.com/mattermost/mattermost-server/v6 11 github.com/cilium/cilium 10 code.gitea.io/gitea 9 github.com/grafana/grafana 9 github.com/traefik/traefik/v2 8 github.com/kubeedge/kubeedge 8 github.com/nats-io/nats-server/v2 8 github.com/pomerium/pomerium 8 github.com/go-gitea/gitea 7 github.com/cri-o/cri-o 7 github.com/mattermost/mattermost-server 7 golang.org/x/crypto 7 github.com/google/fscrypt 7 github.com/kubernetes/kubernetes 7 github.com/sylabs/singularity 6 golang.org/x/net/html 6 github.com/cloudflare/cfrpki/cmd/octorpki 6 github.com/russellhaering/gosaml2 6 github.com/fluxcd/flux2 6 github.com/pion/dtls 6 github.com/beego/beego/v2 6 github.com/beego/beego 6 github.com/hashicorp/go-getter 6 github.com/russellhaering/goxmldsig 5 github.com/hashicorp/go-getter/v2 5 github.com/fluxcd/kustomize-controller 5 github.com/pion/dtls/v2 5 github.com/moby/moby 5 github.com/openfga/openfga 5 github.com/tidwall/gjson 5 istio.io/istio 5 github.com/mattermost/mattermost-server/v5 5 github.com/foxcpp/maddy 5 github.com/cloudflare/cfrpki 5 github.com/pterodactyl/wings 5 github.com/hashicorp/go-getter/s3/v2 4 github.com/ory/fosite 4 helm.sh/helm 4 github.com/containers/podman/v4 4 github.com/git-lfs/git-lfs 4 go.etcd.io/etcd/v3 4 github.com/hyperledger/fabric 4 github.com/ipfs/go-ipfs 4 github.com/nats-io/jwt 4 github.com/hashicorp/go-getter/gcs/v2 4 github.com/argoproj/argo-workflows/v3 4 github.com/tendermint/tendermint 4 github.com/kiali/kiali 4 github.com/oauth2-proxy/oauth2-proxy 4 github.com/gin-gonic/gin 4 github.com/dhowden/tag 4 github.com/open-policy-agent/opa 4 github.com/kyverno/kyverno 4 github.com/containers/buildah 3 github.com/aws/aws-sdk-go 3 github.com/alist-org/alist/v3 3 github.com/casdoor/casdoor 3 github.com/phachon/mm-wiki 3 github.com/gophish/gophish 3 github.com/fluxcd/helm-controller 3 github.com/caddyserver/caddy 3 github.com/lightningnetwork/lnd 3 github.com/weaveworks/weave-gitops 3 kubevirt.io/kubevirt 3 github.com/dexidp/dex 3 github.com/traefik/traefik 3 github.com/openshift/origin 3 github.com/ory/oathkeeper 3 go.etcd.io/etcd 3 github.com/KubeOperator/kubepi 3 github.com/dutchcoders/transfer.sh 3 github.com/ElrondNetwork/elrond-go 3 github.com/sigstore/cosign 3 github.com/gravitl/netmaker 3 github.com/coredns/coredns 3 github.com/apache/trafficcontrol 3 github.com/crypto-org-chain/cronos 3 github.com/crewjam/saml 3 github.com/containers/podman/v3 3 github.com/docker/distribution 3 github.com/miekg/dns 3 github.com/nats-io/nats-server/v2/server 3 github.com/go-gitea/gitea/models 3 go.etcd.io/etcd/client/v3 3 gopkg.in/yaml.v2 3 github.com/square/go-jose 2 Google.Protobuf 2 protobuf 2 google/protobuf 2 github.com/protocolbuffers/protobuf 2 com.google.protobuf:protobuf-parent 2 helm.sh/helm/v3/pkg/plugin 2 github.com/syncthing/syncthing 2 github.com/cortexproject/cortex 2 github.com/google/exposure-notifications-verification-server 2 github.com/minio/console 2 github.com/prometheus/prometheus 2 golang.org/x/net/http 2 github.com/Masterminds/goutils 2 github.com/authzed/spicedb 2 github.com/concourse/concourse 2 github.com/kitabisa/teler-waf 2 github.com/gotify/server 2 github.com/aws/aws-sdk-go/service/s3/s3crypto 2 github.com/ecnepsnai/web 2 github.com/pydio/cells 2 github.com/labstack/echo/v4 2 github.com/cosmos/cosmos-sdk 2 github.com/sajari/docconv 2 rancher/rancher 2 github.com/notaryproject/notation 2 github.com/notaryproject/notation-go 2 code.sajari.com/docconv 2 sigs.k8s.io/secrets-store-csi-driver 2 github.com/buger/jsonparser 2 github.com/netlify/gotrue 2 github.com/imgproxy/imgproxy/v3 2 github.com/bitly/oauth2_proxy 2 github.com/goharbor/harbor/src/core/api 2 github.com/kubernetes/kubernetes/pkg/kubectl/cmd/cp 2 github.com/cloudflare/cloudflared 2 github.com/kata-containers/runtime 2 github.com/cosmos/ethermint 2 github.com/cosmos/ethermint/rpc/namespaces/eth 2 github.com/unknwon/cae 2 golang.org/x/crypto/ssh 2 github.com/caddyserver/caddy/v2 2 vitess.io/vitess 2 github.com/argoproj/argo-events 2 github.com/rancher/wrangler 2 github.com/owncast/owncast 2 github.com/ntbosscher/gobase 2 github.com/codenotary/immudb 2 github.com/pingcap/tidb 2 github.com/free5gc/free5gc 2 github.com/cheqd/cheqd-node 2 github.com/brokercap/Bifrost 2 github.com/go-vela/server 2 github.com/go-yaml/yaml 2 github.com/talos-systems/talos 2 github.com/theupdateframework/go-tuf 2 github.com/flyteorg/flyteadmin 2 github.com/edgelesssys/constellation/v2 2 golang.org/x/net/http2 2 github.com/zalando/skipper 2 github.com/edgexfoundry/app-functions-sdk-go/v2 2 github.com/coreos/ignition/v2 2 k8s.io/ingress-nginx 2 github.com/fkie-cad/yapscan 2 github.com/gphper/ginadmin 2 github.com/stripe/smokescreen 2 github.com/ipld/go-codec-dagpb 2 github.com/treeverse/lakefs 2 tailscale.com 2 github.com/flynn/noise 2 github.com/nats-io/nats-streaming-server 2 github.com/tharsis/evmos 2 github.com/containers/podman 2 mellium.im/xmpp 2 golang.org/x/text 2 golang.org/x/text/language 2 gopkg.in/square/go-jose.v1 2 github.com/authelia/authelia/v4 2 github.com/matrix-org/dendrite 2 www.velocidex.com/golang/velociraptor 2 github.com/microcosm-cc/bluemonday 2 github.com/fleetdm/fleet/v4 2 github.com/mutagen-io/mutagen 2 github.com/peterzen/goresolver 2 k8s.io/client-go 2 github.com/zitadel/zitadel 2 github.com/sigstore/rekor 2 github.com/pires/go-proxyproto 2 github.com/ulikunitz/xz 2 github.com/charmbracelet/charm 1 github.com/shiyanhui/dht 1 github.com/gen2brain/go-unarr 1 github.com/ginuerzh/gost 1 github.com/goreleaser/nfpm 1 github.com/dgraph-io/dgraph 1 github.com/Masterminds/vcs 1 github.com/nothub/mrpack-install 1 github.com/juju/juju 1 github.com/beego/beego/v2/server/web 1 github.com/u-root/u-root/pkg/tarutil 1 github.com/kubernetes/client-go/discovery/cached/disk 1 github.com/oam-dev/kubevela 1 github.com/containers/buildah/imagebuildah 1 k8s.io/kubernetes/staging/src/k8s.io/apiserver/pkg/server 1 github.com/mutagen-io/mutagen-compose 1 github.com/kubernetes/kubernetes/pkg/apiserver 1 github.com/jaegertracing/jaeger/pkg/kafka/auth 1 github.com/evanphx/json-patch 1 github.com/yi-ge/unzip 1 github.com/artdarek/go-unzip 1 github.com/libp2p/go-libp2p 1 github.com/concourse/concourse/skymarshal/skyserver 1 github.com/unknwon/cae/zip 1 github.com/concourse/concourse/atc/db 1 github.com/ipld/go-car/v2 1 github.com/ethereum/go-ethereum/eth 1 github.com/kubernetes-csi/external-snapshotter/v2 1 github.com/kubernetes-csi/external-snapshotter/v3 1 golang.org/x/sys/unix 1 golang.org/x/sys 1 github.com/influxdata/influxdb/services/httpd 1 github.com/hashicorp/consul/agent 1 github.com/hashicorp/consul/agent/consul/discoverychain 1 github.com/swaggo/http-swagger 1 gopkg.in/macaron.v1 1 github.com/go-aah/aah 1 github.com/hashicorp/terraform/backend/remote-state/azure 1 github.com/elastic/cloud-on-k8s 1 github.com/kata-containers/agent 1 github.com/duke-git/lancet 1 github.com/grafana/grafana/pkg/middleware 1 github.com/hashicorp/nomad/command/agent 1 github.com/seccomp/libseccomp-golang 1 github.com/couchbase/sync_gateway/db 1 github.com/sjqzhang/go-fastdfs 1 github.com/etcd-io/etcd 1 k8s.io/kubernetes/pkg/apiserver 1 github.com/mholt/archiver/cmd/arc 1 code.cloudfoundry.org/gorouter 1 github.com/cloudfoundry/gorouter 1 github.com/cloudwego/hertz 1 k8s.io/apimachinery/pkg/runtime/serializer/json 1 k8s.io/apimachinery/pkg/util/json 1 k8s.io/apimachinery 1 github.com/duke-git/lancet/v2 1 github.com/hashicorp/consul/agent/consul 1 golang.org/x/net/http/httpguts 1 github.com/lxc/lxd/shared 1 github.com/lxc/lxd 1 go.pinniped.dev 1 go.opentelemetry.io/contrib/instrumentation/github.com/astaxie/beego/otelbeego 1 github.com/etcd-io/etcd/wal 1 github.com/hashicorp/consul/agent/config 1 github.com/ipfs/go-libipfs 1 github.com/appc/docker2aci 1 github.com/opencontainers/umoci 1 github.com/google/exposure-notifications-server 1 github.com/github/hub 1 github.com/pomerium/pomerium/authenticate 1 github.com/kubernetes-sigs/aws-efs-csi-driver 1 github.com/grafana/grafana/pkg/api 1 github.com/bytom/bytom 1 github.com/ipfs/go-bitswap 1 github.com/ipfs/kubo 1 github.com/cloudflare/tableflip 1 github.com/spiffe/spire/pkg/server/endpoints/node 1 github.com/matrix-org/gomatrixserverlib 1 github.com/go-vela/compiler 1 github.com/gohugoio/hugo 1 github.com/dgrijalva/jwt-go 1 github.com/flipped-aurora/gin-vue-admin 1 github.com/oauth2-proxy/oauth2-proxy/v7 1 github.com/containernetworking/cni/pkg/invoke 1 github.com/dgrijalva/jwt-go/v4 1 github.com/moov-io/customers 1 github.com/nats-io/nats-server/server 1 code.cloudfoundry.org/archiver 1 helm.sh/helm/v3/pkg/chartutil 1 github.com/argoproj/argo-cd/util/cache 1 github.com/gofiber/fiber 1 helm.sh/helm/v3/pkg/plugin/installer 1 go.elastic.co/apm 1 github.com/containernetworking/cni 1 sigs.k8s.io/secrets-store-csi-driver/pkg/secrets-store 1 github.com/ory/hydra 1 github.com/cloudfoundry/archiver 1 github.com/docker/distribution/registry/handlers 1 github.com/ThomasLeister/prosody-filer 1 github.com/ory/hydra/oauth2 1 github.com/docker/distribution/registry/storage 1 github.com/sigstore/policy-controller 1 github.com/git-lfs/git-lfs/v3 1 github.com/robbert229/jwt 1 github.com/go-macaron/i18n 1 github.com/blevesearch/bleve 1 github.com/binance-chain/tss-lib/ecdsa/keygen 1 teler.app 1 k8s.io/kube-state-metrics 1