Sitelet https://web.archive.org/web/20210519031222/https://github.com/advisories
Skip to content

GitHub Advisory Database

Cross-site scripting in bluemonday
CVE-2021-29272 (Moderate severity) was published May 18, 2021 • github.com/microcosm-cc/bluemonday (Go)
Denial of service
CVE-2021-23351 (Moderate severity) was published May 18, 2021 • github.com/pires/go-proxyproto (Go)
Origin Validation Error
CVE-2021-20199 (Moderate severity) was published May 18, 2021 • github.com/containers/podman/v3 (Go)
Denial of service
CVE-2020-36066 (Moderate severity) was published May 18, 2021 • github.com/tidwall/gjson (Go)
Integer overflow in github.com/gorilla/websocket
CVE-2020-27813 (High severity) was published May 18, 2021 • github.com/gorilla/websocket (Go)
Authorization bypass in github.com/dgrijalva/jwt-go
CVE-2020-26160 (High severity) was published May 18, 2021 • github.com/dgrijalva/jwt-go (Go)
Path traversal
CVE-2020-7665 (Moderate severity) was published May 18, 2021 • github.com/u-root/u-root (Go)
Open redirect
CVE-2020-12666 (Moderate severity) was published May 18, 2021 • gopkg.in/macaron.v1 (Go)
Insufficient Session Expiration in Kiali
CVE-2020-1762 (High severity) was published May 18, 2021 • github.com/kiali/kiali (Go)
Insecure generation of random numbers
CVE-2019-19794 (Moderate severity) was published May 18, 2021 • github.com/miekg/dns (Go)
Script injection without script or programming rights through Gadget titles
CVE-2021-32621 (High severity) was published May 18, 2021 • org.xwiki.commons:xwiki-commons-core (Maven)
Users registered with email verification can self re-activate their disabled accounts
CVE-2021-32620 (Moderate severity) was published May 18, 2021 • org.xwiki.commons:xwiki-commons-core (Maven)
XStream is vulnerable to a Remote Command Execution attack
CVE-2021-29505 (Low severity) was published May 18, 2021 • com.thoughtworks.xstream:xstream (Maven)
Keepalive Connections Causing Denial Of Service in puma
CVE-2021-29509 (High severity) was published May 18, 2021 • puma (RubyGems)
MSP-Greg wjordan
ioquatix
Improper Verification of Cryptographic Signature
CVE-2020-9283 (Moderate severity) was published May 18, 2021 • golang.org/x/crypto (Go)
Use After Free
CVE-2020-8945 (High severity) was published May 18, 2021 • github.com/proglottis/gpgme (Go)
Symlink Attack
CVE-2019-11251 (Moderate severity) was published May 18, 2021 • github.com/kubernetes/kubernetes/pkg/kubectl/cmd/cp (Go)
Improper Access Control in Lightning Network Daemon
CVE-2019-12999 (High severity) was published May 18, 2021 • github.com/lightningnetwork/lnd (Go)
Cross-site Scripting in Documize
CVE-2019-19619 (Moderate severity) was published May 18, 2021 • github.com/documize/community (Go)
Path Traversal in Docker
CVE-2014-9356 (High severity) was published May 18, 2021 • github.com/fsouza/go-dockerclient (Go)
Denial of Service (DoS) in Cloud Foundry Routing
CVE-2019-11289 (High severity) was published May 18, 2021 • code.cloudfoundry.org/gorouter/common/secure (Go)
Path Traversal in MHolt Archiver
CVE-2019-10743 (Moderate severity) was published May 18, 2021 • github.com/mholt/archiver/cmd/arc (Go)
Out-of-bounds read in Apache Thrift
CVE-2019-0210 (High severity) was published May 18, 2021 • github.com/apache/thrift/lib/go/thrift (Go)
XML Entity Expansion and Improper Input Validation in Kubernetes API server
CVE-2019-11253 (High severity) was published May 18, 2021 • k8s.io/kubernetes/pkg/apiserver (Go)
Exposure of Sensitive Information to an Unauthorized Actor in kube-state-metrics
CVE-2019-17110 (Moderate severity) was published May 18, 2021 • github.com/kubernetes/kube-state-metrics (Go)
ProTip! Advisories are also available from the GraphQL API