QID 995629
Date Published: 2023-10-25
QID 995629: GO (Go) Security Update for github.com/artifacthub/hub (GHSA-hmq4-c2r4-5q8h)
During a security audit of Artifact Hub's code base, a security researcher at OffSec identified a bug in which by using symbolic links in certain kinds of repositories loaded into Artifact Hub, it was possible to read internal files.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hmq4-c2r4-5q8h for updates and patch information.
Vendor References
- GHSA-hmq4-c2r4-5q8h -
github.com/advisories/GHSA-hmq4-c2r4-5q8h
CVEs related to QID 995629
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hmq4-c2r4-5q8h | github.com/artifacthub/hub |
|