зеркало из https://github.com/golang/vulndb.git
data/reports: update GO-2024-3166
- data/reports/GO-2024-3166.yaml Updates golang/vulndb#3166 Change-Id: If53fa8292b261b3a0867d15f7a52fed22097eca6 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/620155 Auto-Submit: Maceo Thompson <maceothompson@google.com> Reviewed-by: Tatiana Bradley <tatianabradley@google.com> LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
This commit is contained in:
Родитель
1ac23c52cd
Коммит
5691b9d500
|
@ -10,23 +10,6 @@
|
||||||
"summary": "Incorrect delegation lookups can make go-tuf download the wrong artifact in github.com/theupdateframework/go-tuf",
|
"summary": "Incorrect delegation lookups can make go-tuf download the wrong artifact in github.com/theupdateframework/go-tuf",
|
||||||
"details": "Incorrect delegation lookups can make go-tuf download the wrong artifact in github.com/theupdateframework/go-tuf",
|
"details": "Incorrect delegation lookups can make go-tuf download the wrong artifact in github.com/theupdateframework/go-tuf",
|
||||||
"affected": [
|
"affected": [
|
||||||
{
|
|
||||||
"package": {
|
|
||||||
"name": "github.com/theupdateframework/go-tuf",
|
|
||||||
"ecosystem": "Go"
|
|
||||||
},
|
|
||||||
"ranges": [
|
|
||||||
{
|
|
||||||
"type": "SEMVER",
|
|
||||||
"events": [
|
|
||||||
{
|
|
||||||
"introduced": "0"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"ecosystem_specific": {}
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"package": {
|
"package": {
|
||||||
"name": "github.com/theupdateframework/go-tuf/v2",
|
"name": "github.com/theupdateframework/go-tuf/v2",
|
||||||
|
|
|
@ -1,7 +1,5 @@
|
||||||
id: GO-2024-3166
|
id: GO-2024-3166
|
||||||
modules:
|
modules:
|
||||||
- module: github.com/theupdateframework/go-tuf
|
|
||||||
vulnerable_at: 0.7.0
|
|
||||||
- module: github.com/theupdateframework/go-tuf/v2
|
- module: github.com/theupdateframework/go-tuf/v2
|
||||||
versions:
|
versions:
|
||||||
- fixed: 2.0.1
|
- fixed: 2.0.1
|
||||||
|
|
Загрузка…
Ссылка в новой задаче