Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical & High Vulnerabilities please check this.. #195

Open
Rajsharan123 opened this issue Feb 5, 2025 · 0 comments
Open

Critical & High Vulnerabilities please check this.. #195

Rajsharan123 opened this issue Feb 5, 2025 · 0 comments

Comments

@Rajsharan123
Copy link

I want to report the below Critical CVE's for the packages in current latest container image for this code.

  1. CVE-2024-45337 API misuse in Golang x/crypto/ssh may lead to authorization bypass when using public key authentication.
    golang.org/x/crypto Version0.23.0 --CVE Reported Fix version package 0.31.0
    sha256__374df9521245cd4d4fb10214a418b54c41ca0aab3f91acac5dbba6cb4bae04be.tar.gz/opt/kafka-proxy/bin/auth-ldap/golang.org/x/crypto

  2. CVE-2024-45338 golang.org/x/net:0.23.0 fixed version package 0.33.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant