Skip to content

chore: security dependency updates#574

Open
mklos-kw wants to merge 7 commits intomainfrom
chore/bumps
Open

chore: security dependency updates#574
mklos-kw wants to merge 7 commits intomainfrom
chore/bumps

Conversation

@mklos-kw
Copy link
Copy Markdown
Member

No description provided.

Fixes:
- github.com/go-git/go-git/v5: credential leak via cross-host redirect (CVE, alert #44)
- github.com/go-git/go-git/v5: malicious idx file asymmetric memory consumption (alert #39)
- github.com/go-git/go-git/v5: missing validation decoding Index v4 files leads to panic (alert #38)
- github.com/cloudflare/circl: incorrect calculation in secp384r1 CombinedMult (alert #21)
Fixes pre-auth panics, MQTT ACL bypass, credential disclosure,
auth bypass, identity spoofing, JetStream auth bypass, DoS via
WebSocket/leafnode, and message tracing redirect vulnerabilities.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant