Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-jjjj-jwhf-8rgr
  • Go/github.com/minio/minio
MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS 15 hours ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-9m49-p2j3-c6xm
  • Go/github.com/apache/trafficcontrol/v8
Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerability yesterday
  • No fix available
  • Severity - 1.3 (Low)
GHSA-3q4q-wqm6-hvf3
  • Go/github.com/mattermost/mattermost/server/v8
  • Go/github.com/mattermost/mattermost-server
Mattermost has a Missing Authorization vulnerability yesterday
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-424h-xj87-m937
  • Go/github.com/mattermost/mattermost/server/v8
  • Go/github.com/mattermost/mattermost-server
Mattermost has an Incorrect Authorization vulnerability yesterday
  • Fix available
  • Severity - 3.1 (Low)
GHSA-6q7m-p8cc-998r
  • Go/github.com/mattermost/mattermost/server/v8
  • Go/github.com/mattermost/mattermost-server
Mattermost has a Missing Authorization vulnerability yesterday
  • Fix available
  • Severity - 8.1 (High)
GHSA-7cr3-38jm-6p45
  • Go/github.com/mattermost/mattermost/server/v8
  • Go/github.com/mattermost/mattermost-server
Mattermost has a Missing Authorization vulnerability yesterday
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-r6qj-894f-5hr2
  • Go/github.com/mattermost/mattermost/server/v8
  • Go/github.com/mattermost/mattermost-server
Mattermost has a Missing Authorization vulnerability yesterday
  • Fix available
  • Severity - 8.1 (High)
GHSA-xr3w-rmvj-f6m7
  • Go/github.com/mattermost/mattermost/server/v8
  • Go/github.com/mattermost/mattermost-server
Mattermost has an Observable Timing Discrepancy vulnerability yesterday
  • Fix available
  • Severity - 3.1 (Low)
GHSA-72c7-4g63-hpw5
  • Go/github.com/in-toto/go-witness
go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents yesterday
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-fr8m-434r-g3xp
  • Go/github.com/consensys/gnark-crypto
gnark-crypto doesn't range check input values during ECDSA and EdDSA signature deserialization yesterday
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-hrhf-2vcr-ghch
  • Go/github.com/cometbft/cometbft
CometBFT's invalid BitArray handling can lead to network halt 2 days ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-c2hv-4pfj-mm2r
  • Go/github.com/argoproj/argo-workflows/v3
Argo Workflow may expose artifact repository credentials 2 days ago
  • Fix available
  • Severity - 8.5 (High)
GHSA-p84v-gxvw-73pf
  • Go/github.com/argoproj/argo-workflows/v3
Argo Workflow has a Zipslip Vulnerability 2 days ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-77r9-w39m-9xh5
  • Go/github.com/siderolabs/omni
Omni vulnerable to information leak via API 3 days ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-4p3p-cr38-v5xp
  • Go/github.com/siderolabs/omni
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests 3 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-xc79-566c-j4qx
  • Go/github.com/microstack-tech/parallax
Parallax is vulnerable to DoS via malicious p2p message 6 days ago
  • Fix available
  • Severity - 7.5 (High)