l3montree-dev / devguard

DevGuard Backend - Manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy, Compliance to security Frameworks - OWASP Incubating Project
https://flawfix.dev
Other
37 stars 4 forks source link

CVE-2024-24789 #158

Open devguard-app[bot] opened 2 weeks ago

devguard-app[bot] commented 2 weeks ago

CVE-2024-24789

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

Affected component

The vulnerability is in pkg:golang/stdlib@1.22.3, detected by the container-scanning scan.

Recommended fix

Upgrade to version 1.22.4 or later.

Risk: 3.35 (Low)

EPSS: 0.04 %

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit: Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database. There are no script kiddies exploiting this vulnerability.

Vulnerability Depth: 1

The vulnerability is in a direct dependency of your project.

CVSS-BE: 7.3

CVSS-B: 5.5

More details can be found in DevGuard


Same - just update