nlamirault / alan

Bridge between Vault and password managers
Apache License 2.0
8 stars 2 forks source link

CVE-2018-17075 (High) detected in net500e7a4f953ddaf55d316b4d3adc516aa0379622 - autoclosed #194

Closed mend-bolt-for-github[bot] closed 5 months ago

mend-bolt-for-github[bot] commented 1 year ago

CVE-2018-17075 - High Severity Vulnerability

Vulnerable Library - net500e7a4f953ddaf55d316b4d3adc516aa0379622

[mirror] Go supplementary network libraries

Library home page: https://github.com/golang/net.git

Found in base branch: master

Vulnerable Source Files (1)

Vulnerability Details

The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of