CVE-2021-38561 (High) detected in github.com/golang/text-v0.3.0, github.com/envoyproxy/protoc-gen-validate-v0.1.0 #4
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2021-38561 - High Severity Vulnerability
github.com/golang/text-v0.3.0
[mirror] Go text processing support
Dependency Hierarchy:
github.com/envoyproxy/protoc-gen-validate-v0.1.0
protoc plugin to generate polyglot message validators
Dependency Hierarchy:
Found in HEAD commit: fa466b4cb231cf20de932a98d0953a1952d1cac5
Found in base branch: main
Due to improper index calculation, an incorrectly formatted language tag can cause Parse
to panic, due to an out of bounds read. If Parse is used to process untrusted user inputs,
this may be used as a vector for a denial of service attack.
Publish Date: 2021-08-12
URL: CVE-2021-38561
Base Score Metrics:
Type: Upgrade version
Origin: https://osv.dev/vulnerability/GO-2021-0113
Release Date: 2021-08-12
Fix Resolution: v0.3.7
The text was updated successfully, but these errors were encountered: