Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: suggestion regarding GO-2024-2527 #2953

Closed
rikatz opened this issue Jun 28, 2024 · 1 comment
Closed

x/vulndb: suggestion regarding GO-2024-2527 #2953

rikatz opened this issue Jun 28, 2024 · 1 comment

Comments

@rikatz
Copy link

rikatz commented Jun 28, 2024

Report ID

GO-2024-2527

Suggestion/Comment

This report is not about a vulnerability, but on a configuration state.

For instance, the mentioned advisory at GHSA-5x4g-q5rc-36jp reports that the correction is to set the right cipher suite.

Govulncheck is detecting it on a version that, per this report is supposed to be fixed:

Vulnerability #1: GO-2024-2527
    Etcd pkg Insecure ciphers are allowed by default in
    go.etcd.io/etcd/client/pkg/v3
  More info: https://pkg.go.dev/vuln/GO-2024-2527
  Module: go.etcd.io/etcd/client/pkg/v3
    Found in: go.etcd.io/etcd/client/pkg/v3@v3.5.10

Thanks!!

@rikatz
Copy link
Author

rikatz commented Jun 28, 2024

Oooops just saw @dims being faster than me on #2952
Closing and will follow from this other report.

Thanks

@rikatz rikatz closed this as completed Jun 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant