| id: GO-2024-3136 |
| modules: |
| - module: d7y.io/dragonfly/v2 |
| versions: |
| - fixed: 2.1.0-beta.1 |
| vulnerable_at: 2.1.0-beta.0 |
| summary: Dragonfly2 has hard coded cyptographic key in d7y.io/dragonfly |
| cves: |
| - CVE-2023-27584 |
| ghsas: |
| - GHSA-hpc8-7wpm-889w |
| references: |
| - advisory: https://github.com/dragonflyoss/Dragonfly2/security/advisories/GHSA-hpc8-7wpm-889w |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-27584 |
| - web: https://github.com/dragonflyoss/Dragonfly2/commit/e9da69dc4048bf2a18a671be94616d85e3429433 |
| - web: https://github.com/dragonflyoss/Dragonfly2/releases/tag/v2.0.9 |
| source: |
| id: GHSA-hpc8-7wpm-889w |
| created: 2024-09-26T14:14:02.766385-04:00 |
| review_status: UNREVIEWED |