Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade go-retryablehttp to 0.7.7 to address Security vulnerability #3700

Open
Rizwana777 opened this issue Jul 4, 2024 · 2 comments · May be fixed by #3743
Open

Upgrade go-retryablehttp to 0.7.7 to address Security vulnerability #3700

Rizwana777 opened this issue Jul 4, 2024 · 2 comments · May be fixed by #3743
Assignees
Labels
bug Something isn't working

Comments

@Rizwana777
Copy link

Summary

The outdated versions of go-retryablehttp are vulnerable to CVE-2024-6104, which has been categorised as Moderate.

Motivation

The issue affects the url which might write sensitive information to log file

Proposal

The recommended solution is to upgrade the version of go-retryablehttp to 0.7.7 for versions v1.6.0, master branches.

@itsmurugappan
Copy link

itsmurugappan commented Jul 8, 2024

@Rizwana777 why is this closed ? i still see the vulnerable version

@Rizwana777
Copy link
Author

@Rizwana777 why is this closed ? i still see the vulnerable version

I have raised PR against release branch and the release branch have some problem in packages and I couldn't push my changes to the closed PR above, and also as per the comments on other PRs , we need to raise a PR against release branch which will be cherry picked to release brach, I have raised a new PR against branch

@Rizwana777 Rizwana777 linked a pull request Jul 24, 2024 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants