Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Bump golang.org/x{net,sys,term} to address CVE-2023-45288 #149

Merged
merged 1 commit into from
Apr 23, 2024

Conversation

a-hilaly
Copy link
Member

@a-hilaly a-hilaly commented Apr 23, 2024

Bumping the golang.org/x/{net,set,term} to address a newly reported CVE.

CVE Details: https://nvd.nist.gov/vuln/detail/CVE-2023-45288

Severity: Moderate (5.3/10)
Attack vector: Network
Attack complexity: Low
Privileges required: None
User interaction: None

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Signed-off-by: Amine Hilaly <hilalyamine@gmail.com>
@ack-prow ack-prow bot requested review from jlbutler and jljaco April 23, 2024 12:00
@ack-prow ack-prow bot added the approved label Apr 23, 2024
@jlbutler
Copy link

/lgtm

@ack-prow ack-prow bot added the lgtm Indicates that a PR is ready to be merged. label Apr 23, 2024
Copy link

ack-prow bot commented Apr 23, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: a-hilaly, jlbutler

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ack-prow ack-prow bot merged commit b6876b5 into aws-controllers-k8s:main Apr 23, 2024
5 checks passed
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
approved lgtm Indicates that a PR is ready to be merged.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants