Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade gopkg.in/macaron.v1 to v1.3.7 (or above) #25856

Closed
simonpasquier opened this issue Jun 26, 2020 · 2 comments · Fixed by #25869
Closed

Upgrade gopkg.in/macaron.v1 to v1.3.7 (or above) #25856

simonpasquier opened this issue Jun 26, 2020 · 2 comments · Fixed by #25869
Assignees
Milestone

Comments

@simonpasquier
Copy link

gopkg.in/macaron.v1 prior v1.3.7 is affected by CVE-2020-12666:

go-macaron/macaron#199
go-macaron/macaron#198

Though Grafana doesn't use the macaron.StaticHandler method currently, it would be nice to bump to a version including the fix in case future versions of Grafana make use of the method.

@aknuds1
Copy link
Contributor

aknuds1 commented Jun 26, 2020

Thanks for the report, will look into this.

@aknuds1 aknuds1 self-assigned this Jun 26, 2020
@aknuds1 aknuds1 moved this from To do to Under review in Backend Platform Squad Jun 29, 2020
@aknuds1
Copy link
Contributor

aknuds1 commented Jul 8, 2020

This is fixed!

@aknuds1 aknuds1 closed this as completed Jul 8, 2020
Backend Platform Squad automation moved this from Under review to Done Jul 8, 2020
@marefr marefr added this to the 7.1-beta1 milestone Sep 10, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
No open projects
Development

Successfully merging a pull request may close this issue.

3 participants