Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump golang.org/x/net and golang.org/x/net/http2 version to 0.0.0-20220906165146-f3363e06e74c #141

Open
Bjyothi2023 opened this issue Sep 1, 2023 · 3 comments

Comments

@Bjyothi2023
Copy link

We are seeing CVE-2022-27664 vulnerability reported because of Getmesh having v0.0.0-20210614182718-04defd469f4e

Affected packages are : golang.org/x/net , golang.org/x/net/http2 and golang.org/x/net/http/httpguts
version reporting this vulnerability : v0.0.0-20210614182718-04defd469f4e
Fix is available in : 0.0.0-20220906165146-f3363e06e74c

I request you to please update all the affected packages mentioned above to fix version 0.0.0-20220906165146-f3363e06e74c

@Bjyothi2023
Copy link
Author

Hello Team, Could you please help resolving this issue. It is impacting the projects that are using this tool as the Vulnerability scanner are reporting these issues and it is blocking us from proceeding further.

@Bjyothi2023
Copy link
Author

Hi Team,

Any update on this.
We have multiple tickets blocked because of this issue , as our scanners are reporting this vulnerability and we can't proceed further.
Requesting you to please prioritise this issue.
Thanks in advance.

@Bjyothi2023
Copy link
Author

One more vulnerbaility CVE-2022-41717 reported because of "golang.org/x/net/http2" version v0.0.0-20210614182718-04defd469f4e.

Fix is available in version 0.4.0
Please update "golang.org/x/net/http2" version to 0.4.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant