Количество 28
Количество 28
RLSA-2025:0401
Important: grafana security update
ELSA-2025-0401
ELSA-2025-0401: grafana security update (IMPORTANT)
ROS-20250214-02
Множественные уязвимости grafana
ROS-20250219-03
Множественные уязвимости trivy
openSUSE-SU-2025:20177-1
Security update for cheat
openSUSE-SU-2025:0056-1
Security update for trivy
CVE-2025-21614
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.
CVE-2025-21614
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.
CVE-2025-21614
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.
CVE-2025-21614
go-git clients vulnerable to DoS via maliciously crafted Git server replies
CVE-2025-21614
go-git is a highly extensible git implementation library written in pu ...
CVE-2025-21613
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.
CVE-2025-21613
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.
CVE-2025-21613
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.
CVE-2025-21613
go-git has an Argument Injection via the URL field
CVE-2025-21613
go-git is a highly extensible git implementation library written in pu ...
openSUSE-SU-2025:20117-1
Security update for trivy
openSUSE-SU-2026:20798-1
Security update for trivy
GHSA-r9px-m959-cxf4
go-git clients vulnerable to DoS via maliciously crafted Git server replies
BDU:2025-00211
Уязвимость библиотеки go-git, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2025:0401 Important: grafana security update | больше 1 года назад | |||
ELSA-2025-0401 ELSA-2025-0401: grafana security update (IMPORTANT) | больше 1 года назад | |||
ROS-20250214-02 Множественные уязвимости grafana | CVSS3: 9.8 | больше 1 года назад | ||
ROS-20250219-03 Множественные уязвимости trivy | CVSS3: 9.8 | больше 1 года назад | ||
openSUSE-SU-2025:20177-1 Security update for cheat | 8 месяцев назад | |||
openSUSE-SU-2025:0056-1 Security update for trivy | больше 1 года назад | |||
CVE-2025-21614 go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-21614 go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-21614 go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-21614 go-git clients vulnerable to DoS via maliciously crafted Git server replies | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-21614 go-git is a highly extensible git implementation library written in pu ... | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-21613 go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-21613 go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0. | CVSS3: 8.1 | 1% Низкий | больше 1 года назад | |
CVE-2025-21613 go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-21613 go-git has an Argument Injection via the URL field | CVSS3: 8.1 | 1% Низкий | больше 1 года назад | |
CVE-2025-21613 go-git is a highly extensible git implementation library written in pu ... | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
openSUSE-SU-2025:20117-1 Security update for trivy | 8 месяцев назад | |||
openSUSE-SU-2026:20798-1 Security update for trivy | 6 месяцев назад | |||
GHSA-r9px-m959-cxf4 go-git clients vulnerable to DoS via maliciously crafted Git server replies | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
BDU:2025-00211 Уязвимость библиотеки go-git, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу