Closed GoVulnBot closed 4 months ago
In GitHub Security Advisory GHSA-mg2c-rc36-p594, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
modules: - module: github.com/apache/trafficcontrol versions: - introduced: 5.1.0 fixed: 5.1.4 packages: - package: github.com/apache/trafficcontrol - module: github.com/apache/trafficcontrol versions: - introduced: 6.0.0 fixed: 6.0.1 packages: - package: github.com/apache/trafficcontrol summary: Apache Traffic Control Traffic Ops Vulnerable to LDAP Injection in github.com/apache/trafficcontrol cves: - CVE-2021-43350 ghsas: - GHSA-mg2c-rc36-p594 references: - web: https://nvd.nist.gov/vuln/detail/CVE-2021-43350 - web: http://www.openwall.com/lists/oss-security/2021/11/11/3 - web: http://www.openwall.com/lists/oss-security/2021/11/11/4 - web: http://www.openwall.com/lists/oss-security/2021/11/17/1 - web: https://trafficcontrol.apache.org/security - advisory: https://github.com/advisories/GHSA-mg2c-rc36-p594 source: id: GHSA-mg2c-rc36-p594
Change https://go.dev/cl/582535 mentions this issue: data/reports: batch add unreviewed reports
data/reports: batch add unreviewed reports
Change https://go.dev/cl/591199 mentions this issue: data/reports: add 5 unreviewed reports
data/reports: add 5 unreviewed reports
In GitHub Security Advisory GHSA-mg2c-rc36-p594, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.