Skip to content
This repository has been archived by the owner on May 8, 2024. It is now read-only.

CVE-2022-31091 and CVE-2022-31090 #337

Open
oleg-andreyev opened this issue Aug 31, 2022 · 2 comments
Open

CVE-2022-31091 and CVE-2022-31090 #337

oleg-andreyev opened this issue Aug 31, 2022 · 2 comments

Comments

@oleg-andreyev
Copy link

+-------------------+----------------------------------------------------------------------------------+
| Package           | guzzlehttp/guzzle                                                                |
| CVE               | CVE-2022-31091                                                                   |
| Title             | Change in port should be considered a change in origin                           |
| URL               | https://github.com/guzzle/guzzle/security/advisories/GHSA-q559-8m2m-g699         |
| Affected versions | >=7,<7.4.5|>=4,<6.5.8                                                            |
| Reported at       | 2022-06-20T22:24:00+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+
+-------------------+----------------------------------------------------------------------------------+
| Package           | guzzlehttp/guzzle                                                                |
| CVE               | CVE-2022-31090                                                                   |
| Title             | CURLOPT_HTTPAUTH option not cleared on change of origin                          |
| URL               | https://github.com/guzzle/guzzle/security/advisories/GHSA-25mq-v84q-4j7r         |
| Affected versions | >=7,<7.4.5|>=4,<6.5.8                                                            |
| Reported at       | 2022-06-20T22:24:00+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+

@spaze
Copy link
Contributor

spaze commented Aug 31, 2022

You can (and should) update your guzzlehttp/guzzle package. This lib works with 7.4.5 just fine.

@gabema
Copy link

gabema commented Sep 1, 2022

Guzzle 7.5.0 just released as well. Haven't seen any azure storage blob related issues working with it as well.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants