Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multiple CVEs are reported by Trivy scan tool. Looks like this is because of the go version. #1218

Open
KisanK79 opened this issue Jan 13, 2025 · 1 comment

Comments

@KisanK79
Copy link

Library Vulnerability Severity Status Installed Version Fixed Version Title
github.com/golang-jwt/jwt/v4 CVE-2024-51744 LOW fixed v4.4.2 4.5.1 golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially... Details
golang.org/x/crypto CVE-2024-45337 CRITICAL v0.27.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto. Details
golang.org/x/net CVE-2024-45338 HIGH v0.29.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html. Details
@nablaux
Copy link

nablaux commented Jan 20, 2025

I am having the same golang.org/x/crypto related CVE issue reported by Aikido.
It would be great if this can be addressed.

It seems there is already a PR for that but it is failing: #1210

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants