github.com/rancher/wrangler
Write controllers like a boss
Activity
- Latest release
- 2y ago
- Total releases
- 43
- Cadence
- ~7 days
- Last 12 months
- 0
Reach
- Stars
- 295
Details
- First release
- May 16, 2019
| Version | Released | |
|---|---|---|
v1.1.2
patch
|
v1.1.2
patch
Dependencies (20)
+ 12 more |
|
v1.1.1
patch
|
v1.1.1
patch
Dependencies (18)
+ 10 more |
|
v1.1.0
minor
|
v1.1.0
minor
Dependencies (18)
+ 10 more |
|
v0.7.5
patch
|
v0.7.5
patch
Dependencies (16)
+ 8 more |
|
v1.0.2
patch
|
v1.0.2
patch
Dependencies (18)
+ 10 more |
|
v0.8.5-security1
pre
|
v0.8.5-security1
pre
Dependencies (17)
+ 9 more |
|
v1.0.1
patch
|
v1.0.1
patch
Dependencies (18)
+ 10 more |
|
v0.7.4-security1
pre
|
v0.7.4-security1
pre
Dependencies (16)
+ 8 more |
|
v0.8.11
patch
|
v0.8.11
patch
Dependencies (17)
+ 9 more |
|
v1.0.0
major
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.0
major
Dependencies (18)
+ 10 more |
|
v0.8.10
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.10
patch
Dependencies (17)
+ 9 more |
|
v0.8.9
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.9
patch
Dependencies (17)
+ 9 more |
|
v0.8.8
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.8
patch
Dependencies (17)
+ 9 more |
|
v0.8.7
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.7
patch
Dependencies (17)
+ 9 more |
|
v0.8.6
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.6
patch
Dependencies (17)
+ 9 more |
|
v0.8.5
patch
|
v0.8.5
patch
Dependencies (17)
+ 9 more |
|
v0.8.4
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.4
patch
Dependencies (17)
+ 9 more |
|
v0.8.3
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.3
patch
Dependencies (17)
+ 9 more |
|
v0.8.2
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.2
patch
Dependencies (17)
+ 9 more |
|
v0.8.1
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.1
patch
Dependencies (17)
+ 9 more |
|
v0.8.0
minor
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.0
minor
Dependencies (17)
+ 9 more |
|
v0.6.2
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.2
patch
Dependencies (12)
+ 4 more |
|
v0.7.2
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.7.2
patch
Dependencies (16)
+ 8 more |
|
v0.7.1
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.7.1
patch
Dependencies (16)
+ 8 more |
|
v0.7.0
minor
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.7.0
minor
Dependencies (16)
+ 8 more |
|
v0.6.1
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.1
patch
Dependencies (12)
+ 4 more |
|
v0.6.0
minor
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.0
minor
Dependencies (12)
+ 4 more |
|
v0.5.3
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.5.3
patch
Dependencies (12)
+ 4 more |
|
v0.5.2
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.5.2
patch
Dependencies (12)
+ 4 more |
|
v0.5.1
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.5.1
patch
Dependencies (12)
+ 4 more |
|
v0.5.0
minor
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.5.0
minor
Dependencies (12)
+ 4 more |
|
v0.4.1
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.4.1
patch
Dependencies (11)
+ 3 more |
|
v0.4.0
minor
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.4.0
minor
Dependencies (11)
+ 3 more |
|
v0.3.1
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.1
patch
Dependencies (11)
+ 3 more |
|
v0.3.0
minor
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.0
minor
Dependencies (11)
+ 3 more |
|
v0.2.0
minor
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.2.0
minor
Dependencies (12)
+ 4 more |
|
v0.1.6
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.6
patch
Dependencies (12)
+ 4 more |
|
v0.1.5
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.5
patch
Dependencies (13)
+ 5 more |
|
v0.1.4
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.4
patch
Dependencies (13)
+ 5 more |
|
v0.1.3
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.3
patch
Dependencies (13)
+ 5 more |
|
v0.1.2
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.2
patch
Dependencies (13)
+ 5 more |
|
v0.1.1
patch
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.1
patch
Dependencies (13)
+ 5 more |
|
v0.1.0
initial
2 CVEs
CVE-2022-31249
GO-2023-1519
GHSA-qrg7-hfx7-95c5
Feb 14, 2023
Command injection in github.com/rancher/wrangler A command injection vulnerability exists in the Wrangler Git package. Specially crafted commands can be passed to Wrangler that will change their behavior and cause confusion when executed through Git, resulting in command injection in the underlying host. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
Updated May 20, 2024 · Source: OSV.dev
CVE-2022-43756
GO-2023-1515
GHSA-8fcj-gf77-47mg
Feb 14, 2023
Denial of service when processing Git credentials in github.com/rancher/wrangler A denial of service (DoS) vulnerability exists in the Wrangler Git package. Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories. A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version. Fixed in
0.7.4-security1
0.8.5-security1
0.8.11
1.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.0
initial
Dependencies (13)
+ 5 more |