golang / vulndb

[mirror] The Go Vulnerability Database
Other
562 stars 60 forks source link

x/vulndb: potential Go vuln in github.com/apache/trafficcontrol: GHSA-mg2c-rc36-p594 #2776

Closed GoVulnBot closed 4 months ago

GoVulnBot commented 6 months ago

In GitHub Security Advisory GHSA-mg2c-rc36-p594, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/apache/trafficcontrol 5.1.4 >= 5.1.0, < 5.1.4 github.com/apache/trafficcontrol 6.0.1 >= 6.0.0, < 6.0.1

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
    - module: github.com/apache/trafficcontrol
      versions:
        - introduced: 5.1.0
          fixed: 5.1.4
      packages:
        - package: github.com/apache/trafficcontrol
    - module: github.com/apache/trafficcontrol
      versions:
        - introduced: 6.0.0
          fixed: 6.0.1
      packages:
        - package: github.com/apache/trafficcontrol
summary: Apache Traffic Control Traffic Ops Vulnerable to LDAP Injection in github.com/apache/trafficcontrol
cves:
    - CVE-2021-43350
ghsas:
    - GHSA-mg2c-rc36-p594
references:
    - web: https://nvd.nist.gov/vuln/detail/CVE-2021-43350
    - web: http://www.openwall.com/lists/oss-security/2021/11/11/3
    - web: http://www.openwall.com/lists/oss-security/2021/11/11/4
    - web: http://www.openwall.com/lists/oss-security/2021/11/17/1
    - web: https://trafficcontrol.apache.org/security
    - advisory: https://github.com/advisories/GHSA-mg2c-rc36-p594
source:
    id: GHSA-mg2c-rc36-p594
gopherbot commented 6 months ago

Change https://go.dev/cl/582535 mentions this issue: data/reports: batch add unreviewed reports

gopherbot commented 4 months ago

Change https://go.dev/cl/591199 mentions this issue: data/reports: add 5 unreviewed reports