Search CVE reports


Toggle filters

701 – 710 of 1635 results


CVE-2021-4239

Medium priority
Needs evaluation

The Noise protocol implementation suffers from weakened cryptographic security after encrypting 2^64 messages, and a potential denial of service attack. After 2^64 (~18.4 quintillion) messages are encrypted with the Encrypt...

1 affected package

golang-github-flynn-noise

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-flynn-noise Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-4238

Medium priority
Needs evaluation

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This...

1 affected package

golang-github-masterminds-goutils

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-masterminds-goutils Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-4235

Medium priority

Some fixes available 3 of 36

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

6 affected packages

golang-github-coreos-discovery-etcd-io, golang-gopkg-yaml.v3, kubernetes, singularity-container, webhook, golang-yaml.v2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-coreos-discovery-etcd-io Vulnerable Vulnerable Vulnerable Vulnerable Not in release
golang-gopkg-yaml.v3 Not affected Not affected Not affected Not in release Not in release
kubernetes Not in release Not affected Not affected Not affected Not in release
singularity-container Needs evaluation Needs evaluation Not in release Not in release Needs evaluation
webhook Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golang-yaml.v2 Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-36568

Medium priority
Needs evaluation

Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocation.

1 affected package

golang-github-revel-revel

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-revel-revel Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2017-20146

Medium priority
Vulnerable

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

2 affected packages

golang-github-coreos-discovery-etcd-io, golang-github-gorilla-handlers

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-coreos-discovery-etcd-io Not affected Not affected Not affected Not affected Not in release
golang-github-gorilla-handlers Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-36567

Medium priority
Needs evaluation

Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines.

1 affected package

golang-github-gin-gonic-gin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-gin-gonic-gin Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-36627

Medium priority
Vulnerable

A vulnerability was found in Macaron i18n. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file i18n.go. The manipulation leads to open redirect. The attack can be launched...

1 affected package

golang-github-go-macaron-i18n

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-macaron-i18n Not in release Not in release Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2022-4123

Medium priority
Needs evaluation

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

1 affected package

golang-github-containers-buildah

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containers-buildah Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2022-4122

Medium priority
Needs evaluation

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

1 affected package

golang-github-containers-buildah

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containers-buildah Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2020-36565

Negligible priority
Needs evaluation

Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

1 affected package

golang-github-labstack-echo

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-labstack-echo Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
Show less packages