Uploaded image for project: 'OpenShift Hive'
  1. OpenShift Hive
  2. HIVE-2937

SNYK-GOLANG-GOLANGORGXCRYPTOSSHAGENT-12668891

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • None

      ✗ High severity vulnerability found in golang.org/x/crypto/ssh/agent
      Description: Improper Handling of Unexpected Data Type
      Info: https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXCRYPTOSSHAGENT-12668891
      Introduced through: github.com/openshift/installer/pkg/asset/machines/aws@1.4.19-ec5, github.com/openshift/installer/pkg/asset/machines/azure@1.4.19-ec5, github.com/openshift/installer/pkg/asset/machines/nutanix@1.4.19-ec5, github.com/openshift/installer/pkg/asset/machines/vsphere@1.4.19-ec5, github.com/openshift/installer/pkg/asset/machines/ibmcloud@1.4.19-ec5, github.com/openshift/installer/pkg/asset/machines/openstack@1.4.19-ec5, github.com/openshift/installer/pkg/asset/machines/gcp@1.4.19-ec5
      From: github.com/openshift/installer/pkg/asset/machines/aws@1.4.19-ec5 > github.com/openshift/installer/pkg/asset/manifests/capiutils@1.4.19-ec5 > github.com/openshift/installer/pkg/asset/installconfig@1.4.19-ec5 > github.com/openshift/installer/pkg/types/validation@1.4.19-ec5 > github.com/openshift/installer/pkg/types/baremetal/validation@1.4.19-ec5 > github.com/digitalocean/go-libvirt@#fcabe97a6eed > github.com/digitalocean/go-libvirt/socket/dialers@#fcabe97a6eed > golang.org/x/crypto/ssh/agent@0.36.0
      From: github.com/openshift/installer/pkg/asset/machines/azure@1.4.19-ec5 > github.com/openshift/installer/pkg/asset/manifests/capiutils@1.4.19-ec5 > github.com/openshift/installer/pkg/asset/installconfig@1.4.19-ec5 > github.com/openshift/installer/pkg/types/validation@1.4.19-ec5 > github.com/openshift/installer/pkg/types/baremetal/validation@1.4.19-ec5 > github.com/digitalocean/go-libvirt@#fcabe97a6eed > github.com/digitalocean/go-libvirt/socket/dialers@#fcabe97a6eed > golang.org/x/crypto/ssh/agent@0.36.0
      From: github.com/openshift/installer/pkg/asset/machines/nutanix@1.4.19-ec5 > github.com/openshift/installer/pkg/asset/manifests/capiutils@1.4.19-ec5 > github.com/openshift/installer/pkg/asset/installconfig@1.4.19-ec5 > github.com/openshift/installer/pkg/types/validation@1.4.19-ec5 > github.com/openshift/installer/pkg/types/baremetal/validation@1.4.19-ec5 > github.com/digitalocean/go-libvirt@#fcabe97a6eed > github.com/digitalocean/go-libvirt/socket/dialers@#fcabe97a6eed > golang.org/x/crypto/ssh/agent@0.36.0
      and 4 more...

      Caught by ci/prow/security
      Logs from one of the runs are here

              efried.openshift Eric Fried
              sumehta Suhani Mehta
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: