Логотип exploitDog
bind:"CVE-2024-6104" OR bind:"CVE-2024-37298" OR bind:"CVE-2024-24783"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-6104" OR bind:"CVE-2024-37298" OR bind:"CVE-2024-24783"

Количество 65

Количество 65

oracle-oval логотип

ELSA-2024-6194

11 месяцев назад

ELSA-2024-6194: podman security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-5258

11 месяцев назад

ELSA-2024-5258: container-tools:ol8 security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2024-6104

около 1 года назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2024-6104

около 1 года назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 6
EPSS: Низкий
nvd логотип

CVE-2024-6104

около 1 года назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 6
EPSS: Низкий
msrc логотип

CVE-2024-6104

10 месяцев назад

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2024-6104

около 1 года назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing the ...

CVSS3: 6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2024:0227-1

12 месяцев назад

Security update for gh

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2024:0226-1

12 месяцев назад

Security update for gh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2286-1

около 1 года назад

Security update for podman

EPSS: Низкий
redos логотип

ROS-20240902-12

11 месяцев назад

Уязвимость python3-pansi

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-v6v8-xj6m-xwqh

около 1 года назад

go-retryablehttp can leak basic auth credentials to log files

CVSS3: 6
EPSS: Низкий
fstec логотип

BDU:2024-06681

около 1 года назад

Уязвимость пакета retryablehttp, связанная с вставкой конфиденциальной информации в файл журнала, позволяющая нарушителю получить конфиденциальные учетные данные базовой аутентификации HTTP

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2024-37298

около 1 года назад

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()` on a struct with arrays of other structs could be vulnerable to this memory exhaustion vulnerability. Version 1.4.1 contains a patch for the issue.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-37298

около 1 года назад

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()` on a struct with arrays of other structs could be vulnerable to this memory exhaustion vulnerability. Version 1.4.1 contains a patch for the issue.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-37298

около 1 года назад

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()` on a struct with arrays of other structs could be vulnerable to this memory exhaustion vulnerability. Version 1.4.1 contains a patch for the issue.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-37298

12 месяцев назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-37298

около 1 года назад

gorilla/schema converts structs to and from form values. Prior to vers ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0458-1

5 месяцев назад

Security update for podman

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0420-1

5 месяцев назад

Security update for skopeo

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2024-6194

ELSA-2024-6194: podman security update (IMPORTANT)

11 месяцев назад
oracle-oval логотип
ELSA-2024-5258

ELSA-2024-5258: container-tools:ol8 security update (IMPORTANT)

11 месяцев назад
ubuntu логотип
CVE-2024-6104

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 6
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-6104

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 6
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-6104

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 6
0%
Низкий
около 1 года назад
msrc логотип
CVSS3: 5.5
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-6104

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing the ...

CVSS3: 6
0%
Низкий
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2024:0227-1

Security update for gh

0%
Низкий
12 месяцев назад
suse-cvrf логотип
openSUSE-SU-2024:0226-1

Security update for gh

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:2286-1

Security update for podman

0%
Низкий
около 1 года назад
redos логотип
ROS-20240902-12

Уязвимость python3-pansi

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-v6v8-xj6m-xwqh

go-retryablehttp can leak basic auth credentials to log files

CVSS3: 6
0%
Низкий
около 1 года назад
fstec логотип
BDU:2024-06681

Уязвимость пакета retryablehttp, связанная с вставкой конфиденциальной информации в файл журнала, позволяющая нарушителю получить конфиденциальные учетные данные базовой аутентификации HTTP

CVSS3: 5.5
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-37298

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()` on a struct with arrays of other structs could be vulnerable to this memory exhaustion vulnerability. Version 1.4.1 contains a patch for the issue.

CVSS3: 7.5
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-37298

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()` on a struct with arrays of other structs could be vulnerable to this memory exhaustion vulnerability. Version 1.4.1 contains a patch for the issue.

CVSS3: 7.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-37298

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()` on a struct with arrays of other structs could be vulnerable to this memory exhaustion vulnerability. Version 1.4.1 contains a patch for the issue.

CVSS3: 7.5
0%
Низкий
около 1 года назад
msrc логотип
CVSS3: 7.5
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-37298

gorilla/schema converts structs to and from form values. Prior to vers ...

CVSS3: 7.5
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0458-1

Security update for podman

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0420-1

Security update for skopeo

5 месяцев назад

Уязвимостей на страницу