Security Advisories for github.com/edgelesssys/contrast in go
Moderate
about 1 month ago
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
go
github.com/edgelesssys/contrast
Low
about 1 month ago
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
go
github.com/edgelesssys/contrast
High
3 months ago
Contras Affected by CopyFile Policy Subversion via Symlinks
go
github.com/edgelesssys/contrast
High
5 months ago
Contrast BadAML injection allows arbitrary code execution
go
github.com/edgelesssys/contrast
Moderate
10 months ago
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
go
github.com/edgelesssys/contrast
High
12 months ago
Contrast leaks workload secrets to logs on INFO level
go
github.com/edgelesssys/contrast
Low
about 1 year ago
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points
go
github.com/edgelesssys/contrast
High
about 1 year ago
Contrast workload secrets leak to logs on INFO level
go
github.com/edgelesssys/contrast
High
over 1 year ago
Contrast's unauthenticated recovery allows Coordinator impersonation
go
github.com/edgelesssys/contrast