Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue with gogo/protobuf while importing go.etcd.io/etcd #1090

Closed
dochri opened this issue May 19, 2021 · 1 comment
Closed

Security Issue with gogo/protobuf while importing go.etcd.io/etcd #1090

dochri opened this issue May 19, 2021 · 1 comment

Comments

@dochri
Copy link

dochri commented May 19, 2021

An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue. go-kit/kit is using go.etcd.io/etcd v0.0.0-20191023171146-3cf2f69b5738 which import gogo/protobuf v.1.1.1. The go.etcd.io/etcd package is now in version v3.4.16 which now uses version 1.3.2 of gogo/protobuf. Is it possible to update the version to eliminate the security issue.

@peterbourgon
Copy link
Member

#1067

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants