endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2021-3121 | github.com/gogo/protobuf:v1.3.0 (CWE-20) #50

Open cbilgin23 opened 2 years ago

cbilgin23 commented 2 years ago

Due Date: 2022-09-30

A high severity vulnerability has been discovered in your project.

Project Name: test

Scanner Name: dependabot

Cwe ID: 20

Cwe Name: Improper Input Validation

Cwe Link: https://cwe.mitre.org/data/definitions/20.html

File: go.sum

Packages:

References:

Training(Secure Code Warrior):


Tool Description: Summary: Improper Input Validation in GoGo Protobuf. Description: An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.

Kondukto Link: http://80.kondukto.local/projects/6331ad74ef14f4953e572991/vulns/appsec?page=1&perPage=15&id=in:63369976ac49fe7403108cf8