Логотип exploitDog
bind:"CVE-2025-21613" OR bind:"CVE-2025-21614"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-21613" OR bind:"CVE-2025-21614"

Количество 27

Количество 27

rocky логотип

RLSA-2025:0401

12 месяцев назад

Important: grafana security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-0401

около 1 года назад

ELSA-2025-0401: grafana security update (IMPORTANT)

EPSS: Низкий
redos логотип

ROS-20250214-02

12 месяцев назад

Множественные уязвимости grafana

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20250219-03

12 месяцев назад

Множественные уязвимости trivy

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20177-1

около 2 месяцев назад

Security update for cheat

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:0056-1

12 месяцев назад

Security update for trivy

EPSS: Низкий
ubuntu логотип

CVE-2025-21614

около 1 года назад

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-21614

около 1 года назад

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-21614

около 1 года назад

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-21614

около 1 года назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-21614

около 1 года назад

go-git is a highly extensible git implementation library written in pu ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-21613

около 1 года назад

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2025-21613

около 1 года назад

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2025-21613

около 1 года назад

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2025-21613

около 1 года назад

go-git has an Argument Injection via the URL field

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2025-21613

около 1 года назад

go-git is a highly extensible git implementation library written in pu ...

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20117-1

2 месяца назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0060-1

около 1 года назад

Security update for govulncheck-vulndb

EPSS: Низкий
github логотип

GHSA-r9px-m959-cxf4

около 1 года назад

go-git clients vulnerable to DoS via maliciously crafted Git server replies

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-00211

около 1 года назад

Уязвимость библиотеки go-git, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2025:0401

Important: grafana security update

12 месяцев назад
oracle-oval логотип
ELSA-2025-0401

ELSA-2025-0401: grafana security update (IMPORTANT)

около 1 года назад
redos логотип
ROS-20250214-02

Множественные уязвимости grafana

CVSS3: 9.8
12 месяцев назад
redos логотип
ROS-20250219-03

Множественные уязвимости trivy

CVSS3: 9.8
12 месяцев назад
suse-cvrf логотип
openSUSE-SU-2025:20177-1

Security update for cheat

около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2025:0056-1

Security update for trivy

12 месяцев назад
ubuntu логотип
CVE-2025-21614

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.

CVSS3: 7.5
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-21614

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.

CVSS3: 7.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-21614

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.

CVSS3: 7.5
0%
Низкий
около 1 года назад
msrc логотип
CVSS3: 7.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-21614

go-git is a highly extensible git implementation library written in pu ...

CVSS3: 7.5
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-21613

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.

CVSS3: 9.8
1%
Низкий
около 1 года назад
redhat логотип
CVE-2025-21613

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.

CVSS3: 8.1
1%
Низкий
около 1 года назад
nvd логотип
CVE-2025-21613

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.

CVSS3: 9.8
1%
Низкий
около 1 года назад
msrc логотип
CVE-2025-21613

go-git has an Argument Injection via the URL field

CVSS3: 8.1
1%
Низкий
около 1 года назад
debian логотип
CVE-2025-21613

go-git is a highly extensible git implementation library written in pu ...

CVSS3: 9.8
1%
Низкий
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2025:20117-1

Security update for trivy

2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0060-1

Security update for govulncheck-vulndb

около 1 года назад
github логотип
GHSA-r9px-m959-cxf4

go-git clients vulnerable to DoS via maliciously crafted Git server replies

CVSS3: 7.5
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-00211

Уязвимость библиотеки go-git, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу