spf13 / afero

A FileSystem Abstraction System for Go
Apache License 2.0
5.99k stars 514 forks source link

fix: fixed vulnerable protobuf version 1.31.0. See CVE-2024-24786 #425

Open manuelkasiske4idealo opened 6 months ago

manuelkasiske4idealo commented 6 months ago

CVE-2024-24786, Score: 7.5

In the package google.golang.org/protobuf versions prior to 1.33.0, the "protojson.Unmarshal" function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a "google.protobuf.Any" value, or when the "UnmarshalOptions.DiscardUnknown" option is set.

https://devhub.checkmarx.com/cve-details/CVE-2024-24786/

CLAassistant commented 6 months ago

CLA assistant check
All committers have signed the CLA.

melekes commented 3 months ago

👀 anyone?