| id: GO-2023-1533 |
| modules: |
| - module: github.com/anchore/syft |
| versions: |
| - introduced: 0.69.0 |
| - fixed: 0.70.0 |
| vulnerable_at: 0.69.1 |
| summary: Credential disclosure in syft when SYFT_ATTEST_PASSWORD environment variable set in github.com/anchore/syft |
| cves: |
| - CVE-2023-24827 |
| ghsas: |
| - GHSA-jp7v-3587-2956 |
| references: |
| - advisory: https://github.com/anchore/syft/security/advisories/GHSA-jp7v-3587-2956 |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-24827 |
| - fix: https://github.com/anchore/syft/commit/9995950c70e849f9921919faffbfcf46401f71f3 |
| source: |
| id: GHSA-jp7v-3587-2956 |
| created: 2024-08-20T11:30:48.175309-04:00 |
| review_status: UNREVIEWED |
| unexcluded: EFFECTIVELY_PRIVATE |