vipinsun / fabric-sdk-go

https://wiki.hyperledger.org/display/fabric
Apache License 2.0
0 stars 0 forks source link

CVE-2018-17847 (High) detected in github.com/hyperledger/fabric-lib-go-v1.0.0 #21

Open mend-bolt-for-github[bot] opened 3 years ago

mend-bolt-for-github[bot] commented 3 years ago

CVE-2018-17847 - High Severity Vulnerability

Vulnerable Library - github.com/hyperledger/fabric-lib-go-v1.0.0

null

Library home page: https://proxy.golang.org/github.com/hyperledger/fabric-lib-go/@v/v1.0.0.zip

Path to dependency file: /go.mod

Path to vulnerable library: /go.mod

Dependency Hierarchy: - :x: **github.com/hyperledger/fabric-lib-go-v1.0.0** (Vulnerable Library)

Found in HEAD commit: 432a85aa9d4094d52823bdb4be9cf19758df85e1

Found in base branch: main

Vulnerability Details

The html package (aka x/net/html) through 2018-09-25 in Go mishandles