golang / vulndb

[mirror] The Go Vulnerability Database
Other
557 stars 56 forks source link

x/vulndb: potential Go vuln in github.com/stacklok/minder: GHSA-9c5w-9q3f-3hv7 #2821

Closed GoVulnBot closed 3 months ago

GoVulnBot commented 4 months ago

In GitHub Security Advisory GHSA-9c5w-9q3f-3hv7, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/stacklok/minder 0.20240507.2069 < 0.20240507.2061

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
    - module: github.com/stacklok/minder
      versions:
        - introduced: TODO (earliest fixed "0.20240507.2069", vuln range "< 0.20240507.2061")
      packages:
        - package: github.com/stacklok/minder
summary: Minder's GitHub Webhook Handler vulnerable to DoS from un-validated requests in github.com/stacklok/minder
ghsas:
    - GHSA-9c5w-9q3f-3hv7
references:
    - advisory: https://github.com/stacklok/minder/security/advisories/GHSA-9c5w-9q3f-3hv7
    - fix: https://github.com/stacklok/minder/commit/3e5a527d2f1b535159206161d1d519602c75bd0d
    - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks.go#L213-L218
    - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks.go#L337-L342
    - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks.go#L367-L377
    - web: https://github.com/stacklok/minder/blob/ee66f6c0763212503c898cfefb65ce1450c7f5ac/internal/controlplane/handlers_githubwebhooks_test.go#L278-L283
    - advisory: https://github.com/advisories/GHSA-9c5w-9q3f-3hv7
source:
    id: GHSA-9c5w-9q3f-3hv7
gopherbot commented 4 months ago

Change https://go.dev/cl/584256 mentions this issue: data/reports: add GO-2024-2821.yaml