blob: cf09b60c2375b9df476ca2b445956f96fb6fe967 [file] [log] [blame]
id: GO-2024-2432
modules:
- module: github.com/cubefs/cubefs
non_go_versions:
- fixed: 3.3.1
vulnerable_at: 2.5.2+incompatible
summary: CubeFS timing attack can leak user passwords in github.com/cubefs/cubefs
cves:
- CVE-2023-46739
ghsas:
- GHSA-8579-7p32-f398
references:
- advisory: https://github.com/cubefs/cubefs/security/advisories/GHSA-8579-7p32-f398
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-46739
- fix: https://github.com/cubefs/cubefs/commit/6a0d5fa45a77ff20c752fa9e44738bf5d86c84bd
- fix: https://github.com/cubefs/cubefs/commit/c21d034d2fcd051ffd64afeafc68cbcb39d26551
source:
id: GHSA-8579-7p32-f398
created: 2024-06-14T11:34:40.709598-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE