blob: 87da5937a5f5da5962c956fad33b301738b1edf4 [file] [log] [blame]
id: GO-2024-2981
modules:
- module: github.com/openclarity/kubeclarity/backend
versions:
- fixed: 0.0.0-20240711173334-1d1178840703
summary: SQL Injection in the KubeClarity REST API in github.com/openclarity/kubeclarity/backend
cves:
- CVE-2024-39909
ghsas:
- GHSA-5248-h45p-9pgw
references:
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-39909
- web: https://github.com/openclarity/kubeclarity/blob/main/backend/pkg/database/id_view.go#L79
- web: https://github.com/openclarity/kubeclarity/commit/1d1178840703a72d9082b7fc4aea0a3326c5d294
notes:
- fix: 'github.com/openclarity/kubeclarity/backend: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
source:
id: GHSA-5248-h45p-9pgw
created: 2024-08-16T16:55:23.63598-04:00
review_status: UNREVIEWED