Skip to content

Commit 3d41d8f

Browse files
tatianabgopherbot
authored andcommitted
data/reports: unexclude 20 reports (29)
- data/reports/GO-2022-1079.yaml - data/reports/GO-2022-1080.yaml - data/reports/GO-2022-1081.yaml - data/reports/GO-2022-1089.yaml - data/reports/GO-2022-1099.yaml - data/reports/GO-2022-1100.yaml - data/reports/GO-2022-1105.yaml - data/reports/GO-2022-1106.yaml - data/reports/GO-2022-1107.yaml - data/reports/GO-2022-1119.yaml - data/reports/GO-2022-1120.yaml - data/reports/GO-2022-1121.yaml - data/reports/GO-2022-1132.yaml - data/reports/GO-2022-1135.yaml - data/reports/GO-2022-1138.yaml - data/reports/GO-2022-1147.yaml - data/reports/GO-2022-1151.yaml - data/reports/GO-2022-1152.yaml - data/reports/GO-2022-1153.yaml - data/reports/GO-2022-1154.yaml Updates #1079 Updates #1080 Updates #1081 Updates #1089 Updates #1099 Updates #1100 Updates #1105 Updates #1106 Updates #1107 Updates #1119 Updates #1120 Updates #1121 Updates #1132 Updates #1135 Updates #1138 Updates #1147 Updates #1151 Updates #1152 Updates #1153 Updates #1154 Change-Id: Ice57e62cbaec73a848639ed6de50434eac91a368 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/607231 Reviewed-by: Damien Neil <[email protected]> LUCI-TryBot-Result: Go LUCI <[email protected]> Auto-Submit: Tatiana Bradley <[email protected]> Commit-Queue: Tatiana Bradley <[email protected]>
1 parent 004e616 commit 3d41d8f

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

60 files changed

+1765
-162
lines changed

data/excluded/GO-2022-1079.yaml

-8
This file was deleted.

data/excluded/GO-2022-1080.yaml

-8
This file was deleted.

data/excluded/GO-2022-1081.yaml

-8
This file was deleted.

data/excluded/GO-2022-1089.yaml

-8
This file was deleted.

data/excluded/GO-2022-1099.yaml

-8
This file was deleted.

data/excluded/GO-2022-1100.yaml

-12
This file was deleted.

data/excluded/GO-2022-1105.yaml

-8
This file was deleted.

data/excluded/GO-2022-1106.yaml

-8
This file was deleted.

data/excluded/GO-2022-1107.yaml

-6
This file was deleted.

data/excluded/GO-2022-1119.yaml

-8
This file was deleted.

data/excluded/GO-2022-1120.yaml

-8
This file was deleted.

data/excluded/GO-2022-1121.yaml

-8
This file was deleted.

data/excluded/GO-2022-1132.yaml

-8
This file was deleted.

data/excluded/GO-2022-1135.yaml

-8
This file was deleted.

data/excluded/GO-2022-1138.yaml

-8
This file was deleted.

data/excluded/GO-2022-1147.yaml

-8
This file was deleted.

data/excluded/GO-2022-1151.yaml

-8
This file was deleted.

data/excluded/GO-2022-1152.yaml

-8
This file was deleted.

data/excluded/GO-2022-1153.yaml

-8
This file was deleted.

data/excluded/GO-2022-1154.yaml

-8
This file was deleted.

data/osv/GO-2022-1079.json

+56
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2022-1079",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2022-39340",
8+
"GHSA-95x7-mh78-7w2r"
9+
],
10+
"summary": "OpenFGA subject to Information Disclosure via streamed-list-objects endpoint in github.com/openfga/openfga",
11+
"details": "OpenFGA subject to Information Disclosure via streamed-list-objects endpoint in github.com/openfga/openfga",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/openfga/openfga",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "0.2.4"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {}
32+
}
33+
],
34+
"references": [
35+
{
36+
"type": "ADVISORY",
37+
"url": "https://github.com/openfga/openfga/security/advisories/GHSA-95x7-mh78-7w2r"
38+
},
39+
{
40+
"type": "ADVISORY",
41+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39340"
42+
},
43+
{
44+
"type": "FIX",
45+
"url": "https://github.com/openfga/openfga/commit/779d73d4b6d067ee042ec9b59fec707eed71e42f"
46+
},
47+
{
48+
"type": "WEB",
49+
"url": "https://github.com/openfga/openfga/releases/tag/v0.2.4"
50+
}
51+
],
52+
"database_specific": {
53+
"url": "https://pkg.go.dev/vuln/GO-2022-1079",
54+
"review_status": "UNREVIEWED"
55+
}
56+
}

data/osv/GO-2022-1080.json

+56
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2022-1080",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2022-39341",
8+
"GHSA-vj4m-83m8-xpw5"
9+
],
10+
"summary": "OpenFGA Authorization Bypass via tupleset wildcard in github.com/openfga/openfga",
11+
"details": "OpenFGA Authorization Bypass via tupleset wildcard in github.com/openfga/openfga",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/openfga/openfga",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "0.2.4"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {}
32+
}
33+
],
34+
"references": [
35+
{
36+
"type": "ADVISORY",
37+
"url": "https://github.com/openfga/openfga/security/advisories/GHSA-vj4m-83m8-xpw5"
38+
},
39+
{
40+
"type": "ADVISORY",
41+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39341"
42+
},
43+
{
44+
"type": "FIX",
45+
"url": "https://github.com/openfga/openfga/commit/b466769cc100b2065047786578718d313f52695b"
46+
},
47+
{
48+
"type": "WEB",
49+
"url": "https://github.com/openfga/openfga/releases/tag/v0.2.4"
50+
}
51+
],
52+
"database_specific": {
53+
"url": "https://pkg.go.dev/vuln/GO-2022-1080",
54+
"review_status": "UNREVIEWED"
55+
}
56+
}

data/osv/GO-2022-1081.json

+56
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2022-1081",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2022-39342",
8+
"GHSA-f4mm-2r69-mg5f"
9+
],
10+
"summary": "OpenFGA Authorization Bypass in github.com/openfga/openfga",
11+
"details": "OpenFGA Authorization Bypass in github.com/openfga/openfga",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/openfga/openfga",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "0.2.4"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {}
32+
}
33+
],
34+
"references": [
35+
{
36+
"type": "ADVISORY",
37+
"url": "https://github.com/openfga/openfga/security/advisories/GHSA-f4mm-2r69-mg5f"
38+
},
39+
{
40+
"type": "ADVISORY",
41+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39342"
42+
},
43+
{
44+
"type": "FIX",
45+
"url": "https://github.com/openfga/openfga/commit/c8db1ee3d2a366f18e585dd33236340e76e784c4"
46+
},
47+
{
48+
"type": "WEB",
49+
"url": "https://github.com/openfga/openfga/releases/tag/v0.2.4"
50+
}
51+
],
52+
"database_specific": {
53+
"url": "https://pkg.go.dev/vuln/GO-2022-1081",
54+
"review_status": "UNREVIEWED"
55+
}
56+
}

0 commit comments

Comments
 (0)