Логотип exploitDog
bind:"CVE-2024-45336" OR bind:"CVE-2025-3931"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-45336" OR bind:"CVE-2025-3931"

Количество 21

Количество 21

oracle-oval логотип

ELSA-2025-7592

около 1 месяца назад

ELSA-2025-7592: yggdrasil security update (IMPORTANT)

EPSS: Низкий
redhat логотип

CVE-2025-3931

3 месяца назад

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2025-3931

3 месяца назад

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2024-45336

6 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-45336

7 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-45336

6 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2024-45336

6 месяцев назад

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-45336

6 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-rpg2-jvhp-h354

3 месяца назад

Yggdrasil Vulnerable to Local Privilege Escalation

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-7wrw-r4p8-38rx

6 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-02667

6 месяцев назад

Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0281-1

6 месяцев назад

Security update for go1.22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0280-1

6 месяцев назад

Security update for go1.23

EPSS: Низкий
redos логотип

ROS-20250212-16

6 месяцев назад

Множественные уязвимости golang

CVSS3: 6.1
EPSS: Низкий
oracle-oval логотип

ELSA-2025-3772

4 месяца назад

ELSA-2025-3772: go-toolset:ol8 security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1555-1

3 месяца назад

Security update for go1.22-openssl

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7466

около 1 месяца назад

ELSA-2025-7466: delve and golang security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0285-1

6 месяцев назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01731-1

2 месяца назад

Security update for go1.23-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0429-1

6 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2025-7592

ELSA-2025-7592: yggdrasil security update (IMPORTANT)

около 1 месяца назад
redhat логотип
CVE-2025-3931

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-3931

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

CVSS3: 7.8
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 5.9
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
msrc логотип
CVSS3: 6.1
0%
Низкий
6 месяцев назад
debian логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain ...

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-rpg2-jvhp-h354

Yggdrasil Vulnerable to Local Privilege Escalation

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-7wrw-r4p8-38rx

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2025-02667

Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

CVSS3: 6.1
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0281-1

Security update for go1.22

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0280-1

Security update for go1.23

6 месяцев назад
redos логотип
ROS-20250212-16

Множественные уязвимости golang

CVSS3: 6.1
6 месяцев назад
oracle-oval логотип
ELSA-2025-3772

ELSA-2025-3772: go-toolset:ol8 security update (MODERATE)

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:1555-1

Security update for go1.22-openssl

3 месяца назад
oracle-oval логотип
ELSA-2025-7466

ELSA-2025-7466: delve and golang security update (MODERATE)

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0285-1

Security update for go1.24

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01731-1

Security update for go1.23-openssl

2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0429-1

Security update for govulncheck-vulndb

6 месяцев назад

Уязвимостей на страницу