1
+ {
2
+ "schema_version" : " 1.3.1" ,
3
+ "id" : " GO-2024-2997" ,
4
+ "modified" : " 0001-01-01T00:00:00Z" ,
5
+ "published" : " 0001-01-01T00:00:00Z" ,
6
+ "aliases" : [
7
+ " CVE-2024-21583"
8
+ ],
9
+ "summary" : " CVE-2024-21583 in github.com/gitpod-io/gitpod" ,
10
+ "details" : " CVE-2024-21583 in github.com/gitpod-io/gitpod" ,
11
+ "affected" : [
12
+ {
13
+ "package" : {
14
+ "name" : " github.com/gitpod-io/gitpod" ,
15
+ "ecosystem" : " Go"
16
+ },
17
+ "ranges" : [
18
+ {
19
+ "type" : " SEMVER" ,
20
+ "events" : [
21
+ {
22
+ "introduced" : " 0"
23
+ }
24
+ ]
25
+ }
26
+ ],
27
+ "ecosystem_specific" : {}
28
+ }
29
+ ],
30
+ "references" : [
31
+ {
32
+ "type" : " ADVISORY" ,
33
+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-21583"
34
+ },
35
+ {
36
+ "type" : " FIX" ,
37
+ "url" : " https://github.com/gitpod-io/gitpod/commit/da1053e1013f27a56e6d3533aa251dbd241d0155"
38
+ },
39
+ {
40
+ "type" : " FIX" ,
41
+ "url" : " https://github.com/gitpod-io/gitpod/pull/19973"
42
+ },
43
+ {
44
+ "type" : " WEB" ,
45
+ "url" : " https://app.safebase.io/portal/71ccd717-aa2d-4a1e-942e-c768d37e9e0c/preview?product=[…]942e-c768d37e9e0c\u0026 tcuUid=1d505bda-9a38-4ca5-8724-052e6337f34d"
46
+ },
47
+ {
48
+ "type" : " WEB" ,
49
+ "url" : " https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODCOMPONENTSSERVERGOPKGLIB-7452074"
50
+ },
51
+ {
52
+ "type" : " WEB" ,
53
+ "url" : " https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODCOMPONENTSWSPROXYPKGPROXY-7452075"
54
+ },
55
+ {
56
+ "type" : " WEB" ,
57
+ "url" : " https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODINSTALLINSTALLERPKGCOMPONENTSAUTH-7452076"
58
+ },
59
+ {
60
+ "type" : " WEB" ,
61
+ "url" : " https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODINSTALLINSTALLERPKGCOMPONENTSPUBLICAPISERVER-7452077"
62
+ },
63
+ {
64
+ "type" : " WEB" ,
65
+ "url" : " https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODINSTALLINSTALLERPKGCOMPONENTSSERVER-7452078"
66
+ },
67
+ {
68
+ "type" : " WEB" ,
69
+ "url" : " https://security.snyk.io/vuln/SNYK-JS-GITPODGITPODPROTOCOL-7452079"
70
+ }
71
+ ],
72
+ "credits" : [
73
+ {
74
+ "name" : " Elliot Ward (Snyk Security Research)"
75
+ }
76
+ ],
77
+ "database_specific" : {
78
+ "url" : " https://pkg.go.dev/vuln/GO-2024-2997" ,
79
+ "review_status" : " UNREVIEWED"
80
+ }
81
+ }
0 commit comments