Closed GoVulnBot closed 3 months ago
In GitHub Security Advisory GHSA-9c5w-9q3f-3hv7, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
modules: - module: github.com/stacklok/minder versions: - introduced: TODO (earliest fixed "0.20240507.2069", vuln range "< 0.20240507.2061") packages: - package: github.com/stacklok/minder summary: Minder's GitHub Webhook Handler vulnerable to DoS from un-validated requests in github.com/stacklok/minder ghsas: - GHSA-9c5w-9q3f-3hv7 references: - advisory: https://github.com/stacklok/minder/security/advisories/GHSA-9c5w-9q3f-3hv7 - fix: https://github.com/stacklok/minder/commit/3e5a527d2f1b535159206161d1d519602c75bd0d - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks.go#L213-L218 - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks.go#L337-L342 - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks.go#L367-L377 - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks_test.go#L278-L283 - advisory: https://github.com/advisories/GHSA-9c5w-9q3f-3hv7 source: id: GHSA-9c5w-9q3f-3hv7
Change https://go.dev/cl/584256 mentions this issue: data/reports: add GO-2024-2821.yaml
data/reports: add GO-2024-2821.yaml
In GitHub Security Advisory GHSA-9c5w-9q3f-3hv7, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.