CVE-2021-25742
- EPSS 0.63%
- Published 29.10.2021 04:15:08
- Last modified 21.11.2024 05:55:19
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
CVE-2021-34558
- EPSS 1.48%
- Published 15.07.2021 14:15:19
- Last modified 21.11.2024 06:10:40
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.
CVE-2020-29509
- EPSS 0.19%
- Published 14.12.2020 20:15:13
- Last modified 21.11.2024 05:24:08
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages ...
CVE-2020-29510
- EPSS 0.12%
- Published 14.12.2020 20:15:13
- Last modified 21.11.2024 05:24:09
The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of proc...
CVE-2020-29511
- EPSS 0.19%
- Published 14.12.2020 20:15:13
- Last modified 21.11.2024 05:24:09
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of...
CVE-2020-28362
- EPSS 0.15%
- Published 18.11.2020 17:15:11
- Last modified 21.11.2024 05:22:39
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
CVE-2020-28366
- EPSS 0.22%
- Published 18.11.2020 17:15:11
- Last modified 21.11.2024 05:22:40
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.
CVE-2019-9514
- EPSS 9.48%
- Published 13.08.2019 21:15:12
- Last modified 14.01.2025 19:29:55
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the p...
CVE-2019-11243
- EPSS 0.25%
- Published 22.04.2019 15:29:00
- Last modified 21.11.2024 04:20:47
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.Anon...
- EPSS 0.11%
- Published 22.04.2019 15:29:00
- Last modified 21.11.2024 04:20:47
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a differe...