Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multiple CVEs are reported by Trivy scan tool. Looks like this is because of the go version. #1218

Open
KisanK79 opened this issue Jan 13, 2025 · 0 comments

Comments

@KisanK79
Copy link

Library Vulnerability Severity Status Installed Version Fixed Version Title
github.com/golang-jwt/jwt/v4 CVE-2024-51744 LOW fixed v4.4.2 4.5.1 golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially... Details
golang.org/x/crypto CVE-2024-45337 CRITICAL v0.27.0 0.31.0 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto. Details
golang.org/x/net CVE-2024-45338 HIGH v0.29.0 0.33.0 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html. Details
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant