blob: bc20729790e6c889850bf1b907ca80ad5e5773a0 [file] [log] [blame]
id: GO-2022-0936
modules:
- module: github.com/in-toto/in-toto-golang
versions:
- fixed: 0.3.0
vulnerable_at: 0.2.0
summary: Improperly Implemented path matching for in-toto-golang in github.com/in-toto/in-toto-golang
cves:
- CVE-2021-41087
ghsas:
- GHSA-vrxp-mg9f-hwf3
references:
- advisory: https://github.com/in-toto/in-toto-golang/security/advisories/GHSA-vrxp-mg9f-hwf3
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2021-41087
- fix: https://github.com/in-toto/in-toto-golang/commit/f2c57d1e0f15e3ffbeac531829c696b72ecc4290
source:
id: GHSA-vrxp-mg9f-hwf3
created: 2024-08-20T14:32:28.208411-04:00
review_status: UNREVIEWED
unexcluded: NOT_IMPORTABLE