Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-qwgc-rr35-h4x9
  • Go/github.com/external-secrets/external-secrets
External Secrets Operator vulnerable to privilege escalation 2 days ago
  • Fix available
  • Severity - 8.3 (High)
GHSA-pv7h-hg6m-82j8
  • Go/github.com/gouniverse/cms
Gouniverse GoLang CMS vulnerable to Cross-site Scripting 4 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-9j4f-f249-q5w8
  • Go/github.com/grafana/synthetic-monitoring-agent/cmd/synthetic-monitoring-agent
  • Go/github.com/grafana/synthetic-monitoring-agent
Default installation of `synthetic-monitoring-agent` exposes sensitive information 5 days ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-q98f-2x4p-prjr
  • Go/github.com/pomerium/pomerium
Exposure of debug and metrics endpoints in Pomerium 5 days ago
  • Fix available
  • Severity - 6.9 (Medium)
GO-2024-3108
  • Go/github.com/SpectoLabs/hoverfly
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly 5 days ago
  • Fix available
GO-2024-3110
  • Go/github.com/opencontainers/runc
runc can be confused to create empty files/directories on the host in github.com/opencontainers/runc 5 days ago
  • Fix available
GO-2024-3113
  • Go/github.com/hashicorp/vault
Vault Leaks Client Token and Token Accessor in Audit Devices in github.com/hashicorp/vault 5 days ago
  • Fix available
GO-2024-3114
  • Go/github.com/projectdiscovery/nuclei
  • Go/github.com/projectdiscovery/nuclei/v2
  • Go/github.com/projectdiscovery/nuclei/v3
Nuclei Template Signature Verification Bypass in github.com/projectdiscovery/nuclei 5 days ago
  • Fix available
GO-2024-3116
  • Go/github.com/sigstore/sigstore-go
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack in github.com/sigstore/sigstore-go 5 days ago
  • Fix available
GO-2024-3118
  • Go/github.com/windmill-labs/windmill
Windmill HTTP Request users.rs excessive authentication in github.com/windmill-labs/windmill 5 days ago
  • No fix available
GO-2024-3119
  • Go/github.com/stripe/stripe-cli
Path traversal vulnerability in stripe-cli in github.com/stripe/stripe-cli 5 days ago
  • Fix available
GO-2024-3121
  • Go/github.com/cosmos/interchain-security
  • Go/github.com/cosmos/interchain-security/v2
  • Go/github.com/cosmos/interchain-security/v3
  • Go/github.com/cosmos/interchain-security/v4
  • Go/github.com/cosmos/interchain-security/v5
Interchain Security: The signers of ICS messages do not need to match the provider address in github.com/cosmos/interchain-security 5 days ago
  • Fix available
GHSA-q3hw-3gm4-w5cr
  • Go/github.com/consensys/gnark
gnark's Groth16 commitment extension unsound for more than one commitment 5 days ago
  • Fix available
  • Severity - 6.2 (Medium)
GHSA-9xcg-3q8v-7fq6
  • Go/github.com/consensys/gnark
gnark commitments to private witnesses in Groth16 as implemented break zero-knowledge property 5 days ago
  • Fix available
  • Severity - 8.2 (High)
GO-2024-3105
  • Go/stdlib
Stack exhaustion in all Parse functions in go/parser 5 days ago
  • Fix available
GO-2024-3106
  • Go/stdlib
Stack exhaustion in Decoder.Decode in encoding/gob 5 days ago
  • Fix available