Количество 46
Количество 46
SUSE-SU-2024:3288-1
Security update for golang-github-prometheus-prometheus
SUSE-SU-2023:2183-1
Security update for SUSE Manager Client Tools
GHSA-fqpx-62jv-7r6r
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.
GHSA-m3hq-grv6-h853
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparseable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparseable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.
SUSE-SU-2024:0487-1
Security update for SUSE Manager Client Tools
SUSE-SU-2023:2578-1
Security update for SUSE Manager Client Tools
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
SUSE-SU-2024:3288-1 Security update for golang-github-prometheus-prometheus | около 1 года назад | |||
SUSE-SU-2023:2183-1 Security update for SUSE Manager Client Tools | больше 2 лет назад | |||
GHSA-fqpx-62jv-7r6r Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-m3hq-grv6-h853 Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparseable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparseable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
SUSE-SU-2024:0487-1 Security update for SUSE Manager Client Tools | почти 2 года назад | |||
SUSE-SU-2023:2578-1 Security update for SUSE Manager Client Tools | больше 2 лет назад |
Уязвимостей на страницу