QID 997649
Date Published: 2024-03-07
QID 997649: GO (Go) Security Update for github.com/cloudevents/sdk-go/v2 (GHSA-5pf6-2qwx-pxm2)
What kind of vulnerability is it? Who is impacted? Using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-5pf6-2qwx-pxm2 for updates and patch information.
Vendor References
- GHSA-5pf6-2qwx-pxm2 -
github.com/advisories/GHSA-5pf6-2qwx-pxm2
CVEs related to QID 997649
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5pf6-2qwx-pxm2 | github.com/cloudevents/sdk-go/v2 |
|