blob: b61056c9deb6aa2f28dc25c6bed79b8de3db288d [file] [log] [blame]
id: GO-2024-2433
modules:
- module: github.com/cubefs/cubefs
non_go_versions:
- fixed: 3.3.1
vulnerable_at: 2.5.2+incompatible
summary: CubeFS leaks magic secret key when starting Blobstore access service in github.com/cubefs/cubefs
cves:
- CVE-2023-46741
ghsas:
- GHSA-8h2x-gr2c-c275
references:
- advisory: https://github.com/cubefs/cubefs/security/advisories/GHSA-8h2x-gr2c-c275
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-46741
- fix: https://github.com/cubefs/cubefs/commit/972f0275ee8d5dbba4b1530da7c145c269b31ef5
source:
id: GHSA-8h2x-gr2c-c275
created: 2024-06-14T11:34:45.410074-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE