Логотип exploitDog
bind:"CVE-2024-45336" OR bind:"CVE-2025-3931"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-45336" OR bind:"CVE-2025-3931"

Количество 24

Количество 24

rocky логотип

RLSA-2025:7592

около 1 месяца назад

Important: yggdrasil security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7592

4 месяца назад

ELSA-2025-7592: yggdrasil security update (IMPORTANT)

EPSS: Низкий
redhat логотип

CVE-2025-3931

6 месяцев назад

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2025-3931

6 месяцев назад

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2024-45336

9 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-45336

10 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-45336

9 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2024-45336

9 месяцев назад

Sensitive headers incorrectly sent after cross-domain redirect in net/http

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-45336

9 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-rpg2-jvhp-h354

6 месяцев назад

Yggdrasil Vulnerable to Local Privilege Escalation

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-7wrw-r4p8-38rx

9 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-02667

9 месяцев назад

Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0281-1

9 месяцев назад

Security update for go1.22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0280-1

9 месяцев назад

Security update for go1.23

EPSS: Низкий
redos логотип

ROS-20250212-16

9 месяцев назад

Множественные уязвимости golang

CVSS3: 6.1
EPSS: Низкий
oracle-oval логотип

ELSA-2025-3772

7 месяцев назад

ELSA-2025-3772: go-toolset:ol8 security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1555-1

6 месяцев назад

Security update for go1.22-openssl

EPSS: Низкий
rocky логотип

RLSA-2025:7466

около 1 месяца назад

Moderate: delve and golang security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7466

4 месяца назад

ELSA-2025-7466: delve and golang security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0285-1

9 месяцев назад

Security update for go1.24

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2025:7592

Important: yggdrasil security update

около 1 месяца назад
oracle-oval логотип
ELSA-2025-7592

ELSA-2025-7592: yggdrasil security update (IMPORTANT)

4 месяца назад
redhat логотип
CVE-2025-3931

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-3931

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
redhat логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 5.9
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
msrc логотип
CVE-2024-45336

Sensitive headers incorrectly sent after cross-domain redirect in net/http

CVSS3: 6.1
0%
Низкий
9 месяцев назад
debian логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain ...

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-rpg2-jvhp-h354

Yggdrasil Vulnerable to Local Privilege Escalation

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-7wrw-r4p8-38rx

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
fstec логотип
BDU:2025-02667

Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

CVSS3: 6.1
0%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0281-1

Security update for go1.22

9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0280-1

Security update for go1.23

9 месяцев назад
redos логотип
ROS-20250212-16

Множественные уязвимости golang

CVSS3: 6.1
9 месяцев назад
oracle-oval логотип
ELSA-2025-3772

ELSA-2025-3772: go-toolset:ol8 security update (MODERATE)

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:1555-1

Security update for go1.22-openssl

6 месяцев назад
rocky логотип
RLSA-2025:7466

Moderate: delve and golang security update

около 1 месяца назад
oracle-oval логотип
ELSA-2025-7466

ELSA-2025-7466: delve and golang security update (MODERATE)

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0285-1

Security update for go1.24

9 месяцев назад

Уязвимостей на страницу