From 51e27f9e3b9aced86c497429a94ef25f036cb716 Mon Sep 17 00:00:00 2001 From: zzzckck <152148891+zzzckck@users.noreply.github.com> Date: Tue, 2 Jul 2024 15:00:14 +0800 Subject: [PATCH] nancy: ignore go-retryablehttp@v0.7.4 in .nancy-ignore (#2559) --- .nancy-ignore | 1 + 1 file changed, 1 insertion(+) diff --git a/.nancy-ignore b/.nancy-ignore index 062a7015a1..0b64e763db 100644 --- a/.nancy-ignore +++ b/.nancy-ignore @@ -1 +1,2 @@ CVE-2024-34478 # "CWE-754: Improper Check for Unusual or Exceptional Conditions." This vulnerability is BTC only, BSC does not have the issue. +CVE-2024-6104 # "CWE-532: Information Exposure Through Log Files" This is caused by the vulnerabilities go-retryablehttp@v0.7.4, it is only used in cmd devp2p, impact is limited. will upgrade to v0.7.7 later