✗ High severity vulnerability found in golang.org/x/crypto/ssh
Description: Allocation of Resources Without Limits or Throttling
Info: https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXCRYPTOSSH-8747056
Introduced through: github.com/openshift/installer/pkg/validate@#dfd4c085a721, github.com/openshift/installer/pkg/asset/machines/azure@#dfd4c085a721, github.com/openshift/installer/pkg/destroy/ovirt@#dfd4c085a721, github.com/openshift/installer/pkg/destroy/vsphere@#dfd4c085a721, github.com/openshift/installer/pkg/destroy/gcp@#dfd4c085a721, github.com/openshift/installer/pkg/asset/machines/aws@#dfd4c085a721, github.com/openshift/installer/pkg/asset/machines/vsphere@#dfd4c085a721, github.com/openshift/installer/pkg/asset/machines/openstack@#dfd4c085a721, github.com/openshift/installer/pkg/asset/machines/gcp@#dfd4c085a721
From: github.com/openshift/installer/pkg/validate@#dfd4c085a721 > golang.org/x/crypto/ssh@0.31.0
From: github.com/openshift/installer/pkg/asset/machines/azure@#dfd4c085a721 > sigs.k8s.io/cluster-api-provider-azure/api/v1beta1@#a52056dfb88c > golang.org/x/crypto/ssh@0.31.0
From: github.com/openshift/installer/pkg/destroy/ovirt@#dfd4c085a721 > github.com/openshift/installer/pkg/asset/installconfig/ovirt@#dfd4c085a721 > github.com/openshift/installer/pkg/types/validation@#dfd4c085a721 > golang.org/x/crypto/ssh@0.31.0
and 32 more...
Fixed in: 0.35.0
- links to
- mentioned on