Open ghost opened 2 years ago
@spf13,同学,您好,上面的漏洞报告是我IDE运行时,安全插件提示您这个项目存在的几个漏洞的报告,辛苦您修复一下哈,担心其他人也会用到你这个项目,从而引入这些漏洞。:)
English pls. Also this library should not have anything to do with Kubernetes.
@jxsl13 Doing some research seems to be a vulnerability reported by kubernetes, is related to the library
gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
which is in the go.sum
.
Translation: (no guarantee on correctness)
Package spf13/afero imported 77 open-source packages and 2 vulnerabilities is detected.
Title: Google Kubernetes API Server Resource Management Error
Package: gopkg.in/yaml.v2@v2.2.2
CVE: CVE-2019-11254
CNVD: CNVD-2020-35519
Affected: (∞, 2.2.8)
Fixed: 2.2.8
Import path: github.com/spf13/afero@->gopkg.in/yaml.v2@v2.2.2
检测到 spf13/afero 一共引入了77个开源组件,存在2个漏洞
另外还有2个漏洞,详细报告:https://mofeisec.com/jr?p=a0bfd4