Skip to content

fix: upgrade golang.org/x/crypto to 0.31.0 (CVE-2024-45337)#1001

Open
orbisai0security wants to merge 1 commit into
bannedbook:masterfrom
orbisai0security:fix-cve-2024-45337-fqnews2-libcore-go.mod
Open

fix: upgrade golang.org/x/crypto to 0.31.0 (CVE-2024-45337)#1001
orbisai0security wants to merge 1 commit into
bannedbook:masterfrom
orbisai0security:fix-cve-2024-45337-fqnews2-libcore-go.mod

Conversation

@orbisai0security

Copy link
Copy Markdown

Summary

Upgrade golang.org/x/crypto from v0.17.0 to 0.31.0 to fix CVE-2024-45337.

Vulnerability

Field Value
ID CVE-2024-45337
Severity CRITICAL
Scanner trivy
Rule CVE-2024-45337
File fqnews2/libcore/go.mod

Description: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

Changes

  • fqnews2/libcore/go.mod
  • fqnews2/libcore/go.sum

Verification

  • Build passes
  • Scanner re-scan confirms fix
  • LLM code review passed

Automated security fix by OrbisAI Security

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant