Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

golang.org/x/crypto version has CVE vulnerability #1344

Open
2 tasks done
ElenaForester opened this issue Dec 12, 2024 · 1 comment
Open
2 tasks done

golang.org/x/crypto version has CVE vulnerability #1344

ElenaForester opened this issue Dec 12, 2024 · 1 comment

Comments

@ElenaForester
Copy link

  • I have looked at the documentation here first?
  • I have looked at the examples provided that may showcase my question here?

Package version eg. v9, v10:

v10.23.0

Issue, Question or Enhancement:

The latest version requires golang.org/x/crypto v0.19.0 which has a CVE vulnerability https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45337.
When is it going to be updated to 0.31.0?

Code sample, to showcase or reproduce:

@nodivbyzero
Copy link
Contributor

This PR #1345 updates dependencies to the latest.
cc: @deankarn

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants