Логотип exploitDog
bind:CVE-2024-28110
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-28110

Количество 5

Количество 5

redhat логотип

CVE-2024-28110

почти 2 года назад

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-28110

почти 2 года назад

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-28110

больше 1 года назад

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5pf6-2qwx-pxm2

почти 2 года назад

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

EPSS: Низкий
fstec логотип

BDU:2024-02146

почти 2 года назад

Уязвимость функции WithRoundTripper() библиотеки для интеграции приложений с облачной инфраструктурой CloudEvents sdk-go, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-28110

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-28110

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2024-28110

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-5pf6-2qwx-pxm2

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-02146

Уязвимость функции WithRoundTripper() библиотеки для интеграции приложений с облачной инфраструктурой CloudEvents sdk-go, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу