blob: f2bb8c22c551001607aa5eabd0292cf2afa0abeb [file] [log] [blame]
id: GO-2023-1533
modules:
- module: github.com/anchore/syft
versions:
- introduced: 0.69.0
- fixed: 0.70.0
vulnerable_at: 0.69.1
summary: Credential disclosure in syft when SYFT_ATTEST_PASSWORD environment variable set in github.com/anchore/syft
cves:
- CVE-2023-24827
ghsas:
- GHSA-jp7v-3587-2956
references:
- advisory: https://github.com/anchore/syft/security/advisories/GHSA-jp7v-3587-2956
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-24827
- fix: https://github.com/anchore/syft/commit/9995950c70e849f9921919faffbfcf46401f71f3
source:
id: GHSA-jp7v-3587-2956
created: 2024-08-20T11:30:48.175309-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE