VYPR

Bitnami package

golang

pkg:bitnami/golang

Vulnerabilities (183)

  • CVE-2022-1962MedAug 10, 2022
    affected < 1.17.12fixed 1.17.12

    Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

  • CVE-2022-1705MedAug 10, 2022
    affected < 1.17.12fixed 1.17.12

    Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.

  • CVE-2022-30634HigJul 15, 2022
    affected < 1.17.11fixed 1.17.11

    Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

  • CVE-2022-29526MedJun 23, 2022
    affected < 1.17.10fixed 1.17.10

    Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

  • CVE-2022-28327HigApr 20, 2022
    affected < 1.17.9fixed 1.17.9

    The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.

  • CVE-2022-27536HigApr 20, 2022
    affected >= 1.18.0, < 1.18.1fixed 1.18.1

    Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.

  • CVE-2022-24675HigApr 20, 2022
    affected < 1.17.9fixed 1.17.9

    encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.

  • CVE-2022-24921HigMar 5, 2022
    affected < 1.16.15fixed 1.16.15

    regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.

  • CVE-2022-23806CriFeb 11, 2022
    affected < 1.16.14fixed 1.16.14

    Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

  • CVE-2022-23773HigFeb 11, 2022
    affected < 1.16.14fixed 1.16.14

    cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

  • CVE-2022-23772HigFeb 11, 2022
    affected < 1.16.14fixed 1.16.14

    Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.

  • CVE-2021-39293HigJan 24, 2022
    affected < 1.16.8fixed 1.16.8

    In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.

  • CVE-2021-44717MedJan 1, 2022
    affected < 1.16.12fixed 1.16.12

    Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustion.

  • CVE-2021-44716HigJan 1, 2022
    affected < 1.16.12fixed 1.16.12

    net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

  • CVE-2021-41772HigNov 8, 2021
    affected < 1.16.10fixed 1.16.10

    Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.

  • CVE-2021-41771HigNov 8, 2021
    affected < 1.16.10fixed 1.16.10

    ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.

  • CVE-2021-38297CriOct 18, 2021
    affected < 1.16.9fixed 1.16.9

    Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.

  • CVE-2021-36221MedAug 8, 2021
    affected < 1.15.15fixed 1.15.15

    Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

  • CVE-2021-29923HigAug 7, 2021
    affected < 1.17.0fixed 1.17.0

    Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP a

  • CVE-2021-33198HigAug 2, 2021
    affected < 1.15.13fixed 1.15.13

    In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

Page 8 of 10