You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Our Security Scanning tools have identified Vulnerability in how go-restful parses. Can you please review this and help us with an update on following:
Documentation that explains the mitigation strategy that we can apply to reduce the severity level
Details on when is this going to be fixed with the expected version number and if its already fixed which version number is it fixed in.
Issues found in build: v0.14.0
Vulnerability Description
Package github.com/emicklei/go-restful/v3 Package Version v3.8.0 Compliance ID 416 Fixed Status Fixed Description github.com/emicklei/go-restful/v3 module from all versions is vulnerable to Authentication Bypass by Primary Weakness. There is an inconsistency in how go-restful parses URL paths. This inconsistency could lead several security check bypass in a complex system. Vulnerability Link emicklei/go-restful#497
Could you confirm when are you going to update to the latest version of go-restful?
The text was updated successfully, but these errors were encountered:
Our Security Scanning tools have identified Vulnerability in how go-restful parses. Can you please review this and help us with an update on following:
Documentation that explains the mitigation strategy that we can apply to reduce the severity level
Details on when is this going to be fixed with the expected version number and if its already fixed which version number is it fixed in.
Issues found in build: v0.14.0
Vulnerability Description
Package github.com/emicklei/go-restful/v3 Package Version v3.8.0 Compliance ID 416 Fixed Status Fixed Description github.com/emicklei/go-restful/v3 module from all versions is vulnerable to Authentication Bypass by Primary Weakness. There is an inconsistency in how go-restful parses URL paths. This inconsistency could lead several security check bypass in a complex system. Vulnerability Link emicklei/go-restful#497
Could you confirm when are you going to update to the latest version of go-restful?
The text was updated successfully, but these errors were encountered: