blob: f9d01385e2a50f4b9b0fb4305eb2b1ddf0a82f55 [file]
id: GO-2024-3057
modules:
- module: github.com/netbirdio/netbird
versions:
- introduced: 0.23.2
- fixed: 0.29.2
vulnerable_at: 0.29.1
summary: NetBird uses a static initialization vector (IV) in github.com/netbirdio/netbird
cves:
- CVE-2024-41260
ghsas:
- GHSA-9v35-4xcr-w9ph
references:
- advisory: https://github.com/advisories/GHSA-9v35-4xcr-w9ph
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-41260
- fix: https://github.com/netbirdio/netbird/commit/cf6210a6f42355e88c422c624376f6fcdaea6729
- fix: https://github.com/netbirdio/netbird/pull/2569
- report: https://github.com/netbirdio/netbird/issues/2246
- web: https://gist.github.com/nyxfqq/92232108ac153e95d538bb17fc5ad636
source:
id: GHSA-9v35-4xcr-w9ph
created: 2025-12-15T16:00:16.437907858-05:00
review_status: UNREVIEWED