Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/crypto: CVE-2023-39325 #65407

Closed
phillipsj opened this issue Jan 31, 2024 · 2 comments
Closed

x/crypto: CVE-2023-39325 #65407

phillipsj opened this issue Jan 31, 2024 · 2 comments
Labels
NeedsInvestigation Someone must examine and confirm this is a valid issue and not a duplicate of an existing one. Security
Milestone

Comments

@phillipsj
Copy link

Go version

golang:1.20 container

Output of go env in your module/workspace:

NA

What did you do?

Installed a module that uses x/crypto 0.18.0, which uses x/net 0.10.0.

What did you see happen?

This was flagged for this CVE because of the older version of x/net used by x/crypto.

What did you expect to see?

I would expect x/crypto to being using a fixed version of x/net 0.17 or newer.

@gopherbot gopherbot added this to the Unreleased milestone Jan 31, 2024
@mknyszek
Copy link
Contributor

CC @golang/security

@mknyszek mknyszek added Security NeedsInvestigation Someone must examine and confirm this is a valid issue and not a duplicate of an existing one. labels Jan 31, 2024
@rolandshoemaker
Copy link
Member

CVE-2023-39325 affects the HTTP/2 server, which is not used by x/crypto. We do not make unnecessary updates to modules to upgrade dependencies on modules which have vulnerabilities in code that is not used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
NeedsInvestigation Someone must examine and confirm this is a valid issue and not a duplicate of an existing one. Security
Projects
None yet
Development

No branches or pull requests

4 participants