QID 981256
QID 981256: Go (go) Security Update for github.com/wal-g/wal-g (GHSA-vrmr-f2qh-3hhf)
WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vrmr-f2qh-3hhf for updates pertaining to this vulnerability.
Vendor References
- GHSA-vrmr-f2qh-3hhf -
github.com/advisories/GHSA-vrmr-f2qh-3hhf
CVEs related to QID 981256
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vrmr-f2qh-3hhf | github.com/wal-g/wal-g |
|