nsmithuk / local-kms

A mock version of AWS' Key Management Service, for local development and testing.
MIT License
198 stars 34 forks source link

[Vulnerability] btcsuite/btcd 0.22.0-beta #51

Open ecerdeira opened 1 year ago

ecerdeira commented 1 year ago
pkg:golang/github.com/btcsuite/btcd@v0.22.0-beta  [Vulnerable]    
1 known vulnerabilities affecting installed version

(...) Improper Restriction of Operations within the Bounds of a Memory Buffer
btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other 
Bitcoin-related products, mishandles witness size checking.

You should update the github.com/btcsuite/btcd version to fix the issue

Link: https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMBTCSUITEBTCDWIRE-3105848