-
Notifications
You must be signed in to change notification settings - Fork 20
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerabilities: CVE-2020-11022, CVE-2015-9251, CVE-2012-6708 #8
Comments
Hi @mkrakow Going through the reported CVE, the impact area in the jQuery package which has the vulnerability. |
With respect to the vulnerability reported in the issue and the PR suggested, Go sdk does not consume the package reported as part of the CVE. The file ( as pointed in the PR) has a comment section which has a jquery version in it. Hence we can treat this as a FALSE POSITIVE. |
We have raised an internal ticket for this issue. Thanks |
Any update on this? |
we will merge the fix along with the next release in the early first quarter next year. |
Hi @arnabm28 , with the release of https://github.com/IBM/ibm-cos-sdk-go/releases/tag/v1.9.3 on Dec 8, 2022, we should be good to close this issue, right? |
@azieseme Yes this new release has the required upgrade. We are good to close this issue. Thank you for the following up. |
It has already been resolved, so I am closing the ticket. |
Cloud you please fix vulnerabilities reported by security scans?
CVE-2020-11022 (Medium) detected in github.com/IBM/ibm-cos-sdk-go-v1.9.2
CVE-2015-9251 (Medium) detected in github.com/IBM/ibm-cos-sdk-go-v1.9.2
CVE-2012-6708 (Low) detected in github.com/IBM/ibm-cos-sdk-go-v1.9.2
The text was updated successfully, but these errors were encountered: