golang / vulndb

[mirror] The Go Vulnerability Database
Other
559 stars 56 forks source link

x/vulndb: potential Go vuln in atomys.codes/stud42: GHSA-3hwm-922r-47hw #1688

Closed GoVulnBot closed 1 year ago

GoVulnBot commented 1 year ago

In GitHub Security Advisory GHSA-3hwm-922r-47hw, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
atomys.codes/stud42 <= 0.22.3

Cross references: No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: atomys.codes/stud42
    versions:
      - {}
    packages:
      - package: atomys.codes/stud42
summary: Stud42 vulnerable to denial of service
description: Stud42's API is vulnerable to a denial of service because the API pod
    can be overloaded by the GraphQL parser.
ghsas:
  - GHSA-3hwm-922r-47hw
references:
  - advisory: https://github.com/42Atomys/stud42/security/advisories/GHSA-3hwm-922r-47hw
  - report: https://github.com/42Atomys/stud42/issues/412
  - advisory: https://github.com/advisories/GHSA-3hwm-922r-47hw
gopherbot commented 1 year ago

Change https://go.dev/cl/482836 mentions this issue: data/excluded: batch add GO-2023-1706, GO-2023-1689, GO-2023-1688, GO-2023-1686

gopherbot commented 3 months ago

Change https://go.dev/cl/592760 mentions this issue: data/reports: unexclude 75 reports