blob: 414e8cf8e8f54967780324541d80688af4401ce5 [file] [log] [blame]
id: GO-2024-2434
modules:
- module: github.com/cubefs/cubefs
non_go_versions:
- fixed: 3.3.1
vulnerable_at: 2.5.2+incompatible
summary: CubeFS leaks users key in logs in github.com/cubefs/cubefs
cves:
- CVE-2023-46742
ghsas:
- GHSA-vwch-g97w-hfg2
references:
- advisory: https://github.com/cubefs/cubefs/security/advisories/GHSA-vwch-g97w-hfg2
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-46742
- fix: https://github.com/cubefs/cubefs/commit/8dccce6ac8dff3db44d7e9074094c7303a5ff5dd
source:
id: GHSA-vwch-g97w-hfg2
created: 2024-06-14T11:34:49.71851-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE