GHSA-7prj-hgx4-2xc3

Suggest an improvement
Source
https://github.com/advisories/GHSA-7prj-hgx4-2xc3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-7prj-hgx4-2xc3/GHSA-7prj-hgx4-2xc3.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-7prj-hgx4-2xc3
Aliases
Published
2024-12-12T19:20:26Z
Modified
2024-12-13T21:46:53Z
Summary
Potential Vulnerabilities Due to Outdated golang.org/x/crypto Dependency in NanoProxy
Details

A security issue was identified in the NanoProxy project related to the golang.org/x/crypto dependency. The project was using an outdated version of this dependency, which potentially exposed the system to security vulnerabilities that have been addressed in subsequent updates.

Impact: The specific vulnerabilities in the outdated version of golang.org/x/crypto could include authorization bypasses, data breaches, or other security risks. These vulnerabilities can be exploited by attackers to compromise the integrity, confidentiality, or availability of the system.

Resolution: The issue has been fixed in NanoProxy by upgrading the golang.org/x/crypto dependency to version 0.31.0. Users are strongly encouraged to update their instances of NanoProxy to include this fix and ensure they are using the latest secure version of all dependencies.

Fixed Version: * golang.org/x/crypto upgraded to version 0.31.0.

Database specific
{
    "nvd_published_at": null,
    "github_reviewed": true,
    "github_reviewed_at": "2024-12-12T19:20:26Z",
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-1395",
        "CWE-285"
    ]
}
References

Affected packages

Go / github.com/ryanbekhen/nanoproxy

Package

Name
github.com/ryanbekhen/nanoproxy
View open source insights on deps.dev
Purl
pkg:golang/github.com/ryanbekhen/nanoproxy

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.15.0