blob: 761e91eae95a4fd3d3bfcf95d4daf57b61a214e9 [file] [log] [blame]
id: GO-2024-3058
modules:
- module: github.com/appleboy/gorush
versions:
- fixed: 1.18.5
vulnerable_at: 1.18.4
packages:
- package: github.com/appleboy/gorush/router
symbols:
- RunHTTPServer
summary: Gorush uses deprecated TLS versions in github.com/appleboy/gorush
description: |-
An issue in the RunHTTPServer function in Gorush allows attackers to intercept
and manipulate data due to the use of a deprecated TLS version.
cves:
- CVE-2024-41270
ghsas:
- GHSA-p3pf-mff8-3h47
references:
- advisory: https://github.com/advisories/GHSA-p3pf-mff8-3h47
- fix: https://github.com/appleboy/gorush/commit/067cb597e485e40b790a267187bf7f00730b1c4b
- report: https://github.com/appleboy/gorush/issues/792
- web: https://gist.github.com/nyxfqq/cfae38fada582a0f576d154be1aeb1fc
source:
id: GHSA-p3pf-mff8-3h47
created: 2024-08-16T17:25:03.501057-04:00
review_status: REVIEWED