vulndb/data/osv/GO-2023-1901.json

53 строки
1.4 KiB
JSON
Исходник Обычный вид История

data/reports: unexclude 20 reports (7) - data/reports/GO-2023-1862.yaml - data/reports/GO-2023-1863.yaml - data/reports/GO-2023-1864.yaml - data/reports/GO-2023-1865.yaml - data/reports/GO-2023-1866.yaml - data/reports/GO-2023-1871.yaml - data/reports/GO-2023-1879.yaml - data/reports/GO-2023-1887.yaml - data/reports/GO-2023-1888.yaml - data/reports/GO-2023-1891.yaml - data/reports/GO-2023-1892.yaml - data/reports/GO-2023-1894.yaml - data/reports/GO-2023-1895.yaml - data/reports/GO-2023-1896.yaml - data/reports/GO-2023-1897.yaml - data/reports/GO-2023-1898.yaml - data/reports/GO-2023-1899.yaml - data/reports/GO-2023-1900.yaml - data/reports/GO-2023-1901.yaml - data/reports/GO-2023-1911.yaml Updates golang/vulndb#1862 Updates golang/vulndb#1863 Updates golang/vulndb#1864 Updates golang/vulndb#1865 Updates golang/vulndb#1866 Updates golang/vulndb#1871 Updates golang/vulndb#1879 Updates golang/vulndb#1887 Updates golang/vulndb#1888 Updates golang/vulndb#1891 Updates golang/vulndb#1892 Updates golang/vulndb#1894 Updates golang/vulndb#1895 Updates golang/vulndb#1896 Updates golang/vulndb#1897 Updates golang/vulndb#1898 Updates golang/vulndb#1899 Updates golang/vulndb#1900 Updates golang/vulndb#1901 Updates golang/vulndb#1911 Change-Id: Iffcbe8e6325ef654a17298cd4c7072192626ad21 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/606787 Auto-Submit: Tatiana Bradley <tatianabradley@google.com> Reviewed-by: Damien Neil <dneil@google.com> LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
2024-08-20 19:49:35 +03:00
{
"schema_version": "1.3.1",
"id": "GO-2023-1901",
"modified": "0001-01-01T00:00:00Z",
"published": "0001-01-01T00:00:00Z",
"aliases": [
"CVE-2023-37264",
"GHSA-w2h3-vvvq-3m53"
],
"summary": "Pipelines do not validate child UIDs in github.com/tektoncd/pipeline",
"details": "Pipelines do not validate child UIDs in github.com/tektoncd/pipeline",
"affected": [
{
"package": {
"name": "github.com/tektoncd/pipeline",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0.35.0"
}
]
}
],
"ecosystem_specific": {}
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/tektoncd/pipeline/security/advisories/GHSA-w2h3-vvvq-3m53"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37264"
},
{
"type": "WEB",
"url": "https://github.com/tektoncd/pipeline/blob/2d38f5fa840291395178422d34b36b1bc739e2a2/pkg/reconciler/pipelinerun/pipelinerun.go#L1358-L1372"
},
{
"type": "WEB",
"url": "https://pkg.go.dev/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1#ChildStatusReference"
}
],
"database_specific": {
"url": "https://pkg.go.dev/vuln/GO-2023-1901",
"review_status": "UNREVIEWED"
}
}