blob: 062ca55813b992df98433586de025e27d4542d5d [file] [log] [blame]
id: GO-2024-2934
modules:
- module: github.com/stacklok/minder
versions:
- fixed: 0.0.52
vulnerable_at: 0.0.51
summary: Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder
cves:
- CVE-2024-37904
ghsas:
- GHSA-hpcg-xjq5-g666
references:
- advisory: https://github.com/stacklok/minder/security/advisories/GHSA-hpcg-xjq5-g666
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-37904
- fix: https://github.com/stacklok/minder/commit/35bab8f9a6025eea9e6e3cef6bd80707ac03d2a9
- fix: https://github.com/stacklok/minder/commit/7979b43
- web: https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L55-L89
- web: https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L56-L62
source:
id: GHSA-hpcg-xjq5-g666
created: 2024-06-27T15:53:59.10909-04:00
review_status: UNREVIEWED