Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

redhat логотип

CVE-2024-28110

больше 2 лет назад

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-28110

больше 2 лет назад

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-28110

около 2 лет назад

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5pf6-2qwx-pxm2

больше 2 лет назад

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-02146

больше 2 лет назад

Уязвимость функции WithRoundTripper() библиотеки для интеграции приложений с облачной инфраструктурой CloudEvents sdk-go, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-28110

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-28110

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2024-28110

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-5pf6-2qwx-pxm2

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-02146

Уязвимость функции WithRoundTripper() библиотеки для интеграции приложений с облачной инфраструктурой CloudEvents sdk-go, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу