File tree 2 files changed +9
-16
lines changed
2 files changed +9
-16
lines changed Original file line number Diff line number Diff line change 21
21
"events" : [
22
22
{
23
23
"introduced" : " 0"
24
+ },
25
+ {
26
+ "fixed" : " 0.3.6"
24
27
}
25
28
]
26
29
}
32
35
{
33
36
"type" : " ADVISORY" ,
34
37
"url" : " https://github.com/ubuntu/authd/security/advisories/GHSA-4gfw-wf7c-w6g2"
35
- },
36
- {
37
- "type" : " ADVISORY" ,
38
- "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-9312"
39
- },
40
- {
41
- "type" : " ADVISORY" ,
42
- "url" : " https://www.cve.org/CVERecord?id=CVE-2024-9312"
43
38
}
44
39
],
45
40
"database_specific" : {
46
41
"url" : " https://pkg.go.dev/vuln/GO-2024-3188" ,
47
- "review_status" : " UNREVIEWED "
42
+ "review_status" : " REVIEWED "
48
43
}
49
44
}
Original file line number Diff line number Diff line change 1
1
id : GO-2024-3188
2
2
modules :
3
3
- module : github.com/ubuntu/authd
4
- unsupported_versions :
5
- - last_affected : 0.0.0-20230706090440-d8cb2d561419
6
- vulnerable_at : 0.0.0-20230706090440-d8cb2d561419
4
+ versions :
5
+ - fixed : 0.3.6
6
+ vulnerable_at : 0.3.5
7
7
summary : Authd allows attacker-controlled usernames to yield controllable UIDs in github.com/ubuntu/authd
8
8
cves :
9
9
- CVE-2024-9312
10
10
ghsas :
11
11
- GHSA-4gfw-wf7c-w6g2
12
12
references :
13
13
- advisory : https://github.com/ubuntu/authd/security/advisories/GHSA-4gfw-wf7c-w6g2
14
- - advisory : https://nvd.nist.gov/vuln/detail/CVE-2024-9312
15
- - advisory : https://www.cve.org/CVERecord?id=CVE-2024-9312
16
14
source :
17
15
id : GHSA-4gfw-wf7c-w6g2
18
- created : 2024-10-11T10:16:08.934095-04 :00
19
- review_status : UNREVIEWED
16
+ created : 2025-01-29T09:47:20.814811-05 :00
17
+ review_status : REVIEWED
You can’t perform that action at this time.
0 commit comments