data/reports: review GO-2024-2584 - data/reports/GO-2024-2584.yaml Updates golang/vulndb#2584 Fixes golang/vulndb#6618 Change-Id: Ie76a8f62320800dd94b2f9a633b44babb649ebfd Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/842985 Reviewed-by: Damien Neil <dneil@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Auto-Submit: Ian Alexander <jitsu@google.com>
diff --git a/data/osv/GO-2024-2584.json b/data/osv/GO-2024-2584.json index 129823a..7029a30 100644 --- a/data/osv/GO-2024-2584.json +++ b/data/osv/GO-2024-2584.json
@@ -26,6 +26,9 @@ }, { "introduced": "0.50.0" + }, + { + "fixed": "0.50.5" } ] }
diff --git a/data/reports/GO-2024-2584.yaml b/data/reports/GO-2024-2584.yaml index e31b884..fecc302 100644 --- a/data/reports/GO-2024-2584.yaml +++ b/data/reports/GO-2024-2584.yaml
@@ -4,6 +4,7 @@ versions: - fixed: 0.47.10 - introduced: 0.50.0 + - fixed: 0.50.5 vulnerable_at: 0.47.9 packages: - package: github.com/cosmos/cosmos-sdk/x/auth/vesting @@ -22,6 +23,4 @@ - advisory: https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-86h5-xcpx-cfqc - fix: https://github.com/cosmos/cosmos-sdk/commit/7dbed2fc0c3ed7c285645e21cb1037d8810372ae - fix: https://github.com/cosmos/cosmos-sdk/commit/d1b5b0c5ae2c51206cc1849e09e4d59986742cc3 -notes: - - The GHSA says that 0.50.5 is a fixed version, but it currently doesn't exist. review_status: REVIEWED