Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/stacklok/minder: CVE-2024-34084 #2823

Closed
GoVulnBot opened this issue May 7, 2024 · 2 comments
Assignees

Comments

@GoVulnBot
Copy link

CVE-2024-34084 references github.com/stacklok/minder, which may be a Go module.

Description:
Minder's HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerability exists before the request has been validated, and as such the request is still untrusted at the point of failure. This allows an attacker with the ability to send requests to HandleGithubWebhook to crash the Minder controlplane and deny other users from using it. This vulnerability is fixed in 0.0.48.

References:

Cross references:

See doc/triage.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/stacklok/minder
      vulnerable_at: 0.0.48
      packages:
        - package: minder
summary: CVE-2024-34084 in github.com/stacklok/minder
cves:
    - CVE-2024-34084
references:
    - advisory: https://github.com/stacklok/minder/security/advisories/GHSA-9c5w-9q3f-3hv7
    - fix: https://github.com/stacklok/minder/commit/3e5a527d2f1b535159206161d1d519602c75bd0d
source:
    id: CVE-2024-34084

@timothy-king timothy-king self-assigned this May 8, 2024
@timothy-king
Copy link
Contributor

Duplicate of #2821

@timothy-king timothy-king marked this as a duplicate of #2821 May 8, 2024
@gopherbot
Copy link
Contributor

Change https://go.dev/cl/584256 mentions this issue: data/reports: add GO-2024-2821.yaml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants