8.6
CVSSv3

CVE-2021-3121

Published: 11/01/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4.7 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in GoGo Protobuf prior to 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang protobuf

hashicorp consul

Vendor Advisories

Synopsis Important: Red Hat AMQ Broker 7101 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 7101 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Moderate: Windows Container Support for Red Hat OpenShift 500 [security update] Type/Severity Security Advisory: Moderate Topic The components for Windows Container Support for Red Hat OpenShift 500 are now available This product release includes bug fixes and a moderate security update for the following packages: windows-machin ...
Synopsis Important: OpenShift Container Platform 41030 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41030 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift ...
Synopsis Moderate: Cryostat 210: new Cryostat on RHEL 8 container images Type/Severity Security Advisory: Moderate Topic New Cryostat 210 on RHEL 8 container images are now available Description New Cryostat 210 on RHEL 8 container images have been released, adding a variety of features and bug fixes and addressing the following secur ...
Synopsis Important: Red Hat OpenShift Service Mesh 209 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Service Mesh 209Red Hat Product Security has rated this update as having a secu ...
Synopsis Moderate: Red Hat Advanced Cluster Management 213 security and bug fix update Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 213 General Availabilityrelease images, which fix several bugs and security issues Red Hat Product Security has rated ...
Synopsis Moderate: OpenShift Container Platform 4742 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4742 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container Platfo ...
Synopsis Moderate: OpenShift Container Platform 4103 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4103 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Moderate: OpenShift Container Platform 4115 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4115 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Cont ...

Github Repositories

OSV-Scanner Use OSV-Scanner to find existing vulnerabilities affecting your project's dependencies OSV-Scanner provides an officially supported frontend to the OSV database that connects a project’s list of dependencies with the vulnerabilities that affect them Since the OSVdev database is open source and distributed, it has several benefits in comparison with clo

Utility helping to trace some dependency sub-graphs for Go projects.

gomodtrace Utility is intended to trace some dependency sub-graphs for Go projects Installation Run go install githubcom/godepsresolve/gomodtrace/cmd/gomodtrace@latest Usage go mod graph | gomodtrace [OPTION] PARENT_PACKAGE DEPENDENT_PACKAGE -v use verbose mode Let's try to trace usages of

Policy Reporter Plugins Monorepo

Policy Reporter Plugins Monorepo Introduction With Policy Reporter UI v2 a new plugin system will be introduced While plugins in v1 were only used for integrating the Policy Reporter Kyverno Plugin, the new system will be more generic and needs to provide a defined set of REST APIs, no actual UI changes are required Plugin information will be included in existing views and pr

OSV-Scanner This repository contains a script to build a container image for the latest release of Google OSV-Scanner tool and push it to Docker Hub The image is available at anmalkov/osv-scanner You can find the official Google OSV-Scanner repository here What is Google OSV-Scanner Use OSV-Scanner to find existing vulnerabilities affecting your project's dependencies