We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
In GitHub Security Advisory GHSA-9c5w-9q3f-3hv7, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
modules: - module: github.com/stacklok/minder versions: - introduced: TODO (earliest fixed "0.20240507.2069", vuln range "< 0.20240507.2061") packages: - package: github.com/stacklok/minder summary: Minder's GitHub Webhook Handler vulnerable to DoS from un-validated requests in github.com/stacklok/minder ghsas: - GHSA-9c5w-9q3f-3hv7 references: - advisory: https://github.com/stacklok/minder/security/advisories/GHSA-9c5w-9q3f-3hv7 - fix: https://github.com/stacklok/minder/commit/3e5a527d2f1b535159206161d1d519602c75bd0d - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks.go#L213-L218 - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks.go#L337-L342 - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks.go#L367-L377 - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks_test.go#L278-L283 - advisory: https://github.com/advisories/GHSA-9c5w-9q3f-3hv7 source: id: GHSA-9c5w-9q3f-3hv7
The text was updated successfully, but these errors were encountered:
Change https://go.dev/cl/584256 mentions this issue: data/reports: add GO-2024-2821.yaml
data/reports: add GO-2024-2821.yaml
Sorry, something went wrong.
8e27223
timothy-king
No branches or pull requests
In GitHub Security Advisory GHSA-9c5w-9q3f-3hv7, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: