Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Apiiro] 2 risks #133

Open
haimlebo opened this issue Aug 27, 2024 · 0 comments
Open

[Apiiro] 2 risks #133

haimlebo opened this issue Aug 27, 2024 · 0 comments

Comments

@haimlebo
Copy link
Contributor

@@@seperated @@@

Discovered on: Jul 28, 2024 13:41
Due date: Jul 29, 2024 13:41
Dependency: golang.org/x/net
Version: 0.0.0-20190311183353-d8887717615a
Type: Sub dependency
Introduced through:

  • github.com/smartystreets/goconvey: 1.6.4 > golang.org/x/tools: 0.0.0-20190328211700-ab21143f2384 > golang.org/x/net: 0.0.0-20190311183353-d8887717615a

Vulnerabilities

About this package:

External dependency: golang.org/x/net
Latest version: v0.27.0
License: BSD-3-Clause
Insights:

  • Not fixable - This package includes a CVE that has not been fixed by an official release or patch
  • Known exploit - This package has 1 Known Exploited Vulnerabilities.

Source: CISA.gov

  • Historical CVEs - This package had at least two critical or high CVEs in two consecutive years
  • No version 1 - The package releases hasn't reached v1
  • Has vulnerabilities - One or more vulnerabilities have been reported for this package
  • High EPSS - This package has 2 vulnerabilities that are highly likely to be exploited according to the EPSS algorithm

Remediation

Upgrade the top level dependencies (Declared in: go.mod) to change golang.org/x/net 0.0.0-20190311183353-d8887717615a to the minimum required version golang.org/x/net 0.23.0:

golang.org/x/net: 0.0.0-20190311183353-d8887717615a -> 0.23.0
View in Apiiro

Discovered on: Jul 28, 2024 14:50
Due date: Jul 29, 2024 14:50
Detection Method: User Password
Secret type: User password
Exposure: Exposed
File type: Tests
Introduced through: Link to file (2 references)
Code preview: TUSERDATA = [{'username': 'user_1', 'password': '•••••',
Validity: No validator
Source: Apiiro
View in Apiiro

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant