github.com/codenotary/immudb
immudb - immutable database based on zero trust, SQL/Key-Value/Document model, tamperproof, data change history
Activity
- Latest release
- 1w ago
- Total releases
- 48
- Cadence
- ~32 days
- Last 12 months
- 5
Reach
- Stars
- 9.0k
Details
- First release
- May 11, 2020
| Version | Released | |
|---|---|---|
v1.11.2
patch
|
v1.11.2
patch
Dependencies (42)
+ 34 more |
|
v1.11.1
patch
|
v1.11.1
patch
Dependencies (42)
+ 34 more |
|
v1.11.0
minor
|
v1.11.0
minor
Dependencies (41)
+ 33 more |
|
v1.11.0-RC1
pre
|
v1.11.0-RC1
pre
Dependencies (39)
+ 31 more |
|
v1.10.0
minor
|
v1.10.0
minor
Dependencies (39)
+ 31 more |
|
v1.9.7
patch
|
v1.9.7
patch
Dependencies (39)
+ 31 more |
|
v1.9.6
patch
|
v1.9.6
patch
Dependencies (39)
+ 31 more |
|
v1.9.5
patch
|
v1.9.5
patch
Dependencies (39)
+ 31 more |
|
v1.9.4
minor
|
v1.9.4
minor
Dependencies (39)
+ 31 more |
|
v1.9.0-RC2
pre
|
v1.9.0-RC2
pre
Dependencies (39)
+ 31 more |
|
v1.9.0-RC1
pre
|
v1.9.0-RC1
pre
Dependencies (39)
+ 31 more |
|
v1.5.0
minor
|
v1.5.0
minor
Dependencies (38)
+ 30 more |
|
v1.5.0-RC1
pre
|
v1.5.0-RC1
pre
Dependencies (38)
+ 30 more |
|
v1.4.1
patch
|
v1.4.1
patch
Dependencies (37)
+ 29 more |
|
v1.4.1-RC1
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.4.1-RC1
pre
Dependencies (37)
+ 29 more |
|
v1.4.0
minor
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.4.0
minor
Dependencies (37)
+ 29 more |
|
v1.4.0-RC2
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.4.0-RC2
pre
Dependencies (37)
+ 29 more |
|
v1.4.0-RC1
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.4.0-RC1
pre
Dependencies (37)
+ 29 more |
|
v1.3.2
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.2
patch
Dependencies (35)
+ 27 more |
|
v1.3.2-RC1
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.2-RC1
pre
Dependencies (35)
+ 27 more |
|
v1.3.1
minor
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.1
minor
Dependencies (31)
+ 23 more |
|
v1.3.1-RC1
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.1-RC1
pre
Dependencies (31)
+ 23 more |
|
v1.3.0-RC1
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.0-RC1
pre
Dependencies (31)
+ 23 more |
|
v1.2.4
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.4
patch
Dependencies (31)
+ 23 more |
|
v1.2.4-RC1
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.4-RC1
pre
Dependencies (31)
+ 23 more |
|
v1.2.3-RC1
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.3-RC1
pre
Dependencies (31)
+ 23 more |
|
v1.2.2
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.2
patch
Dependencies (31)
+ 23 more |
|
v1.2.1
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.1
patch
Dependencies (30)
+ 22 more |
|
v1.2.0
minor
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.0
minor
Dependencies (30)
+ 22 more |
|
v1.2.0-RC1
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.0-RC1
pre
Dependencies (30)
+ 22 more |
|
v1.1.0
minor
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.1.0
minor
Dependencies (29)
+ 21 more |
|
v1.0.5
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.5
patch
Dependencies (29)
+ 21 more |
|
v1.0.1
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.1
patch
Dependencies (28)
+ 20 more |
|
v1.0.0
major
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.0
major
Dependencies (28)
+ 20 more |
|
v0.9.2
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.9.2
patch
Dependencies (23)
+ 15 more |
|
v0.9.1
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.9.1
patch
Dependencies (24)
+ 16 more |
|
v0.9.0
minor
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.9.0
minor
Dependencies (24)
+ 16 more |
|
v0.9.0-RC2
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.9.0-RC2
pre
Dependencies (24)
+ 16 more |
|
v0.9.0-RC1
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.9.0-RC1
pre
Dependencies (24)
+ 16 more |
|
v0.8.1
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.1
patch
Dependencies (26)
+ 18 more |
|
v0.8.0
minor
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.0
minor
Dependencies (25)
+ 17 more |
|
v0.7.1
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.7.1
patch
Dependencies (26)
+ 18 more |
|
v0.7.0
minor
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.7.0
minor
Dependencies (27)
+ 19 more |
|
v0.6.2
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.2
patch
Dependencies (27)
+ 19 more |
|
v0.6.1
patch
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.1
patch
Dependencies (27)
+ 19 more |
|
v0.6.0
initial
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.0
initial
Dependencies (26)
+ 18 more |
|
v0.6.0-RC2
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.0-RC2
pre
Dependencies (26)
+ 18 more |
|
v0.6.0-RC1
pre
2 CVEs
CVE-2022-36111
GO-2022-1117
GHSA-672p-m5jq-mrh8
Dec 22, 2022
Insufficient verification of proofs in github.com/codenotary/immudb In certain scenarios, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. Fixed in
1.4.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-39199
GO-2022-1118
GHSA-6cqj-6969-p57x
Dec 22, 2022
Improper validation of UUIDs in github.com/codenotary/immudb A malicious server can trick a client into treating it as a different server by changing the reported UUID. immudb client SDKs use the server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. The SDK does not validate this UUID and accepts any value reported by the server. A malicious server can therefore change the reported UUID and trick the client into treating it as a different server. Fixed in
1.4.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.0-RC1
pre
Dependencies (24)
+ 16 more |