blob: c2652a3efc2444ea6fd0d961c23e1268cdd7c15d [file] [log] [blame]
id: GO-2025-3648
modules:
- module: github.com/rancher/steve
non_go_versions:
- introduced: 0.3.0
- fixed: 0.3.3
- module: github.com/rancher/steve
versions:
- introduced: 0.2.0
- fixed: 0.2.1
- introduced: 0.4.0
- fixed: 0.4.4
- introduced: 0.5.0
- fixed: 0.5.13
vulnerable_at: 0.5.12
summary: |-
Steve doesn’t verify a server’s certificate and is susceptible to
man-in-the-middle (MitM) attacks in github.com/rancher/stev
cves:
- CVE-2023-32198
ghsas:
- GHSA-95fc-g4gj-mqmx
references:
- advisory: https://github.com/rancher/steve/security/advisories/GHSA-95fc-g4gj-mqmx
source:
id: GHSA-95fc-g4gj-mqmx
created: 2025-04-29T12:46:44.848556-04:00
review_status: UNREVIEWED