Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24

Количество 24

rocky логотип

RLSA-2025:7592

10 месяцев назад

Important: yggdrasil security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7592

около 1 года назад

ELSA-2025-7592: yggdrasil security update (IMPORTANT)

EPSS: Низкий
redhat логотип

CVE-2025-3931

около 1 года назад

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2025-3931

около 1 года назад

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2024-45336

больше 1 года назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-45336

больше 1 года назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-45336

больше 1 года назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2024-45336

больше 1 года назад

Sensitive headers incorrectly sent after cross-domain redirect in net/http

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-45336

больше 1 года назад

The HTTP client drops sensitive headers after following a cross-domain ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-rpg2-jvhp-h354

около 1 года назад

Yggdrasil Vulnerable to Local Privilege Escalation

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-7wrw-r4p8-38rx

больше 1 года назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-02667

больше 1 года назад

Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0281-1

больше 1 года назад

Security update for go1.22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0280-1

больше 1 года назад

Security update for go1.23

EPSS: Низкий
rocky логотип

RLSA-2025:3772

около 1 года назад

Moderate: go-toolset:rhel8 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-3772

больше 1 года назад

ELSA-2025-3772: go-toolset:ol8 security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1555-1

около 1 года назад

Security update for go1.22-openssl

EPSS: Низкий
rocky логотип

RLSA-2025:7466

10 месяцев назад

Moderate: delve and golang security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7466

около 1 года назад

ELSA-2025-7466: delve and golang security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0285-1

больше 1 года назад

Security update for go1.24

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2025:7592

Important: yggdrasil security update

10 месяцев назад
oracle-oval логотип
ELSA-2025-7592

ELSA-2025-7592: yggdrasil security update (IMPORTANT)

около 1 года назад
redhat логотип
CVE-2025-3931

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-3931

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 5.9
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-45336

Sensitive headers incorrectly sent after cross-domain redirect in net/http

CVSS3: 6.1
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain ...

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-rpg2-jvhp-h354

Yggdrasil Vulnerable to Local Privilege Escalation

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-7wrw-r4p8-38rx

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-02667

Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

CVSS3: 6.1
1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0281-1

Security update for go1.22

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0280-1

Security update for go1.23

больше 1 года назад
rocky логотип
RLSA-2025:3772

Moderate: go-toolset:rhel8 security update

около 1 года назад
oracle-oval логотип
ELSA-2025-3772

ELSA-2025-3772: go-toolset:ol8 security update (MODERATE)

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1555-1

Security update for go1.22-openssl

около 1 года назад
rocky логотип
RLSA-2025:7466

Moderate: delve and golang security update

10 месяцев назад
oracle-oval логотип
ELSA-2025-7466

ELSA-2025-7466: delve and golang security update (MODERATE)

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0285-1

Security update for go1.24

больше 1 года назад

Уязвимостей на страницу