sonatype-nexus-community / ahab

ahab is a tool to check for vulnerabilities in your apt, apk, or yum powered operating systems, powered by Sonatype OSS Index.
Apache License 2.0
68 stars 18 forks source link

[DepShield] (CVSS 7.5) Vulnerability due to usage of golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c #59

Closed sonatype-depshield[bot] closed 4 years ago

sonatype-depshield[bot] commented 4 years ago

Vulnerabilities

DepShield reports that this application's usage of golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c results in the following vulnerability(s):


Occurrences

golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c is a transitive dependency introduced by the following direct dependency(s):

github.com/spf13:viper:1.7.1         └─ github.com/bketelsen:crypt:0.0.3-0.20200106085610-5cbc8cc4026c               └─ google.golang.org:api:0.13.0                     └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c               └─ cloud.google.com/go:firestore:1.1.0                     └─ cloud.google.com:go:0.46.3                           └─ cloud.google.com/go:bigquery:1.0.1                                 └─ google.golang.org:api:0.8.0                                       └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                 └─ cloud.google.com:go:0.44.2                                       └─ google.golang.org:api:0.8.0                                             └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                       └─ cloud.google.com/go:datastore:1.0.0                                             └─ cloud.google.com:go:0.44.1                                                   └─ google.golang.org:api:0.8.0                                                         └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                             └─ google.golang.org:api:0.7.0                                                   └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                           └─ cloud.google.com/go:datastore:1.0.0                                 └─ cloud.google.com:go:0.44.1                                       └─ google.golang.org:api:0.8.0                                             └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                 └─ google.golang.org:api:0.7.0                                       └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                           └─ cloud.google.com/go:pubsub:1.0.1                                 └─ google.golang.org:api:0.9.0                                       └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                 └─ cloud.google.com:go:0.45.1                                       └─ cloud.google.com/go:datastore:1.0.0                                             └─ cloud.google.com:go:0.44.1                                                   └─ google.golang.org:api:0.8.0                                                         └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                             └─ google.golang.org:api:0.7.0                                                   └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                       └─ cloud.google.com/go:bigquery:1.0.1                                             └─ google.golang.org:api:0.8.0                                                   └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                             └─ cloud.google.com:go:0.44.2                                                   └─ google.golang.org:api:0.8.0                                                         └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                                   └─ cloud.google.com/go:datastore:1.0.0                                                         └─ cloud.google.com:go:0.44.1                                                               └─ google.golang.org:api:0.8.0                                                                     └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                                         └─ google.golang.org:api:0.7.0                                                               └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                       └─ google.golang.org:api:0.9.0                                             └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                           └─ google.golang.org:api:0.9.0                                 └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                     └─ cloud.google.com/go:storage:1.0.0                           └─ cloud.google.com:go:0.46.3                                 └─ cloud.google.com/go:bigquery:1.0.1                                       └─ google.golang.org:api:0.8.0                                             └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                       └─ cloud.google.com:go:0.44.2                                             └─ google.golang.org:api:0.8.0                                                   └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                             └─ cloud.google.com/go:datastore:1.0.0                                                   └─ cloud.google.com:go:0.44.1                                                         └─ google.golang.org:api:0.8.0                                                               └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                                   └─ google.golang.org:api:0.7.0                                                         └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                 └─ cloud.google.com/go:datastore:1.0.0                                       └─ cloud.google.com:go:0.44.1                                             └─ google.golang.org:api:0.8.0                                                   └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                       └─ google.golang.org:api:0.7.0                                             └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                 └─ cloud.google.com/go:pubsub:1.0.1                                       └─ google.golang.org:api:0.9.0                                             └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                       └─ cloud.google.com:go:0.45.1                                             └─ cloud.google.com/go:datastore:1.0.0                                                   └─ cloud.google.com:go:0.44.1                                                         └─ google.golang.org:api:0.8.0                                                               └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                                   └─ google.golang.org:api:0.7.0                                                         └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                             └─ cloud.google.com/go:bigquery:1.0.1                                                   └─ google.golang.org:api:0.8.0                                                         └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                                   └─ cloud.google.com:go:0.44.2                                                         └─ google.golang.org:api:0.8.0                                                               └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                                         └─ cloud.google.com/go:datastore:1.0.0                                                               └─ cloud.google.com:go:0.44.1                                                                     └─ google.golang.org:api:0.8.0                                                                           └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                                               └─ google.golang.org:api:0.7.0                                                                     └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                             └─ google.golang.org:api:0.9.0                                                   └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                                 └─ google.golang.org:api:0.9.0                                       └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                           └─ google.golang.org:api:0.9.0                                 └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c                     └─ google.golang.org:api:0.13.0                           └─ golang.org/x:net:0.0.0-20190503192946-f4e77d36d62c

This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.

bhamail commented 4 years ago

False positive. We actually use a newer version of x/net (0.0.0-20190620200207-3b0461eec859), not 0.0.0-20190503192946-f4e77d36d62c

$ go list -m all | grep 'x/net'
golang.org/x/net v0.0.0-20190620200207-3b0461eec859