Количество 40
Количество 40
BDU:2025-03456
Уязвимость компонента crypto-elliptic языка программирования Golang, позволяющая нарушителю получить доступ к конфиденциальной информации
SUSE-SU-2025:0431-1
Security update for go1.24
CVE-2024-45341
A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.
CVE-2024-45341
A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.
CVE-2024-45341
A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.
CVE-2024-45341
Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509
CVE-2024-45341
A certificate with a URI which has a IPv6 address with a zone ID may i ...
CVE-2024-45336
The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
CVE-2024-45336
The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
CVE-2024-45336
The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
CVE-2024-45336
Sensitive headers incorrectly sent after cross-domain redirect in net/http
CVE-2024-45336
The HTTP client drops sensitive headers after following a cross-domain ...
GHSA-3f6r-qh9c-x6mm
A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.
BDU:2025-03335
Уязвимость языка программирования Golang, связанная с неправильной проверкой входных данных, позволяющая нарушителю обойти внедренные ограничения безопасности
GHSA-7wrw-r4p8-38rx
The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
BDU:2025-02667
Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным
SUSE-SU-2025:0297-1
Security update for govulncheck-vulndb
RLSA-2025:7592
Important: yggdrasil security update
ELSA-2025-7592
ELSA-2025-7592: yggdrasil security update (IMPORTANT)
ROS-20250806-13
Множественные уязвимости portainer-ce
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
BDU:2025-03456 Уязвимость компонента crypto-elliptic языка программирования Golang, позволяющая нарушителю получить доступ к конфиденциальной информации  | CVSS3: 4  | 0% Низкий | 9 месяцев назад | |
SUSE-SU-2025:0431-1 Security update for go1.24  | 9 месяцев назад | |||
CVE-2024-45341 A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
CVE-2024-45341 A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.  | CVSS3: 4.2  | 0% Низкий | 10 месяцев назад | |
CVE-2024-45341 A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
CVE-2024-45341 Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
CVE-2024-45341 A certificate with a URI which has a IPv6 address with a zone ID may i ...  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
CVE-2024-45336 The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
CVE-2024-45336 The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.  | CVSS3: 5.9  | 0% Низкий | 10 месяцев назад | |
CVE-2024-45336 The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
CVE-2024-45336 Sensitive headers incorrectly sent after cross-domain redirect in net/http  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
CVE-2024-45336 The HTTP client drops sensitive headers after following a cross-domain ...  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
GHSA-3f6r-qh9c-x6mm A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
BDU:2025-03335 Уязвимость языка программирования Golang, связанная с неправильной проверкой входных данных, позволяющая нарушителю обойти внедренные ограничения безопасности  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
GHSA-7wrw-r4p8-38rx The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
BDU:2025-02667 Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным  | CVSS3: 6.1  | 0% Низкий | 9 месяцев назад | |
SUSE-SU-2025:0297-1 Security update for govulncheck-vulndb  | 9 месяцев назад | |||
RLSA-2025:7592 Important: yggdrasil security update  | около 1 месяца назад | |||
ELSA-2025-7592 ELSA-2025-7592: yggdrasil security update (IMPORTANT)  | 4 месяца назад | |||
ROS-20250806-13 Множественные уязвимости portainer-ce  | CVSS3: 9.1  | 3 месяца назад | 
Уязвимостей на страницу