Security Advisories for github.com/free5gc/udr in go
Moderate
2 months ago
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence
go
github.com/free5gc/udr
Moderate
3 months ago
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
go
github.com/free5gc/udr
Moderate
3 months ago
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)
go
github.com/free5gc/udr
Moderate
4 months ago
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation
go
github.com/free5gc/udr
Moderate
4 months ago
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors
go
github.com/free5gc/udr
High
4 months ago
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions
go
github.com/free5gc/udr
High
4 months ago
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions
go
github.com/free5gc/udr
High
4 months ago
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
go
github.com/free5gc/udr
High
4 months ago
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication
go
github.com/free5gc/udr