Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address CVE-2023-45288 #906

Closed
1 of 3 tasks
ojcm opened this issue Apr 4, 2024 · 1 comment
Closed
1 of 3 tasks

Address CVE-2023-45288 #906

ojcm opened this issue Apr 4, 2024 · 1 comment
Labels

Comments

@ojcm
Copy link

ojcm commented Apr 4, 2024

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

CVE-2023-45288 / GO-2024-2687 was recently published and govuln flags this repository as vulnerable. I believe the changes required to resolve this are:

  • Upgrade Go version to 1.21.9 or 1.22.2
  • Upgrade golang.org/x/net to v0.23.0

Expected Behavior

govuln does not detect any vulnerabilities

Steps To Reproduce

govulncheck ./...

Anything else?

https://pkg.go.dev/vuln/GO-2024-2687

@ojcm ojcm added the bug label Apr 4, 2024
@ojcm ojcm mentioned this issue Apr 4, 2024
12 tasks
@ojcm
Copy link
Author

ojcm commented Apr 5, 2024

govulncheck is no longer flagging this repo as vulnerable.

@ojcm ojcm closed this as completed Apr 5, 2024
@ojcm ojcm closed this as not planned Won't fix, can't repro, duplicate, stale Apr 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant