CVE-2022-29526 (Medium) detected in golang.org/x/sys-v0.0.0-20210510120138-977fb7262007 - autoclosed #47
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-29526 - Medium Severity Vulnerability
Vulnerable Library - golang.org/x/sys-v0.0.0-20210510120138-977fb7262007
Library home page: https://proxy.golang.org/golang.org/x/sys/@v/v0.0.0-20210510120138-977fb7262007.zip
Dependency Hierarchy:
Found in HEAD commit: 2aada85674c55286335b211e44ebd8a6e4c394bb
Found in base branch: master
Vulnerability Details
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
Publish Date: 2022-06-23
URL: CVE-2022-29526
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://security-tracker.debian.org/tracker/CVE-2022-29526
Release Date: 2022-06-23
Fix Resolution: go1.17.10,go1.18.2,go1.19
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: