go package report

Is github.com/weaveworks/weave-gitops safe?

3 known vulnerabilities, worst severity CRITICAL.

cvss
9.0

how bad it is if exploited, out of 10

epss
1.2%

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-xggc-qprg-x6mw, the advisory selected below

// advisories

GHSA-xggc-qprg-x6mw

CRITICALCVE-2022-31098

A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka KubeConfg, of registered Kubernetes clusters, including the service account tokens in plain text from Weave GitOps's pod logs on the management cluster. An unauthorized remote attacker can also view these sensitive configurations from external log storage if ena

Affected
<= 0.8.1-rc.5
Fixed in
0.8.1-rc.6
Weakness
CWE-200
Published
2022-06-23
Source
github

GHSANVDMITREreferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


Checked 2026-09-22 at 01:38 UTC. The most recent advisory here was published 2023-01-09. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is github.com/weaveworks/weave-gitops safe? go package security report | CyberXYZ