Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-29526 (Medium) detected in multiple libraries #3417

Closed
Tracked by #3447
mend-bolt-for-github bot opened this issue Jul 25, 2022 · 0 comments
Closed
Tracked by #3447

CVE-2022-29526 (Medium) detected in multiple libraries #3417

mend-bolt-for-github bot opened this issue Jul 25, 2022 · 0 comments
Assignees
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-bolt-for-github
Copy link
Contributor

mend-bolt-for-github bot commented Jul 25, 2022

CVE-2022-29526 - Medium Severity Vulnerability

Vulnerable Libraries - github.com/fatih/color-v1.9.0, github.com/knative/pkg-9c5a7317fa9de4a38ad8a4ed4cd483accbac9aae, github.com/hashicorp/go-sockaddr-v1.0.2, github.com/nxadm/tail-v1.4.8

github.com/fatih/color-v1.9.0

Color package for Go (golang)

Dependency Hierarchy:

  • github.com/hashicorp/vault/api-v1.7.2 (Root Library)
    • github.com/hashicorp/vault/sdk-v1.4.2
      • github.com/hashicorp/go-hclog-v1.1.0
        • github.com/fatih/color-v1.9.0 (Vulnerable Library)
github.com/knative/pkg-9c5a7317fa9de4a38ad8a4ed4cd483accbac9aae

Knative common packages

Dependency Hierarchy:

  • github.com/knative/pkg-9c5a7317fa9de4a38ad8a4ed4cd483accbac9aae (Vulnerable Library)
github.com/hashicorp/go-sockaddr-v1.0.2

IP Address/UNIX Socket convenience functions for Go

Dependency Hierarchy:

  • github.com/hashicorp/vault/api-v1.7.2 (Root Library)
    • github.com/hashicorp/vault/sdk-v1.4.2
      • github.com/hashicorp/go-sockaddr-v1.0.2 (Vulnerable Library)
github.com/nxadm/tail-v1.4.8

[Revamped] Go package for reading from continuously updated files (tail -f)

Dependency Hierarchy:

  • github.com/onsi/ginkgo-v1.16.5 (Root Library)
    • github.com/nxadm/tail-v1.4.8 (Vulnerable Library)

Found in HEAD commit: 268a2ab9466249fe1555d71e9454828d4fce42fe

Found in base branch: main

Vulnerability Details

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Publish Date: 2022-06-23

URL: CVE-2022-29526

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with Mend here

@mend-bolt-for-github mend-bolt-for-github bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Jul 25, 2022
@tomkerkhove tomkerkhove moved this to Proposed in Roadmap - KEDA Core Jul 25, 2022
@JorTurFer JorTurFer moved this from Proposed to To Do in Roadmap - KEDA Core Jul 28, 2022
@JorTurFer JorTurFer self-assigned this Jul 28, 2022
Repository owner moved this from To Do to Ready To Ship in Roadmap - KEDA Core Aug 5, 2022
@tomkerkhove tomkerkhove moved this from Ready To Ship to Done in Roadmap - KEDA Core Aug 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
Archived in project
Development

No branches or pull requests

1 participant