blob: a6ea36750623662077524e7b9935741883996064 [file] [log] [blame]
id: GO-2024-3038
modules:
- module: github.com/regclient/regclient
versions:
- fixed: 0.7.1
vulnerable_at: 0.7.0
summary: In regclient, pinned manifest digests may be ignored in github.com/regclient/regclient
ghsas:
- GHSA-qv35-3gw6-8q4j
references:
- advisory: https://github.com/regclient/regclient/security/advisories/GHSA-qv35-3gw6-8q4j
- fix: https://github.com/regclient/regclient/commit/7d17cff26c22196b5ddd66bda8c5ee4abf3d1269
source:
id: GHSA-qv35-3gw6-8q4j
created: 2024-08-05T17:04:00.059433-04:00
review_status: UNREVIEWED