Home/Product/sourcegraph
Product

sourcegraph

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-46248
>= 0.10.0 and <= 0.14.0
Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 are vulnerab
9.0CRITICAL
CVE-2022-41943
< 4.1.0
sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the e
9.0CRITICAL
CVE-2022-41942
< 4.1.0
Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver
7.9HIGH
CVE-2022-31155
< 3.41.0
Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attac
4.3MEDIUM
CVE-2022-31154
< 3.42.0
Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the C
6.4MEDIUM
CVE-2022-29171
< 3.38.0
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execu
6.6MEDIUM
CVE-2022-23642
< 3.37
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in th
8.8HIGH
CVE-2022-23643
>= 3.35.0 and < 3.35.2
Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed side-channe
6.5MEDIUM
CVE-2021-43823
< 3.33.2
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack whe
6.5MEDIUM
CVE-2021-32787
< 3.30.0
Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leaks. The sit
3.1LOW
CVE-2020-12283
< 3.15.1
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in
6.1MEDIUM
threatengine.sh