We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Advisory GHSA-xw35-rrcp-g7xm references a vulnerability in the following Go modules:
Description:
The server allow to create any user who can trigger a pipeline run malicious workflows:
woodpecker-ci/woodpecker#3933
Is there a way for users to fix or remediate the vulnerability without upgrading? Enable the "gated" repo feature and review each change upfront
References:
Cross references: No existing reports found with this module or alias. See doc/triage.md for instructions on how to triage this report.
id: GO-ID-PENDING modules: - module: go.woodpecker-ci.org/woodpecker vulnerable_at: 1.0.5 - module: go.woodpecker-ci.org/woodpecker/v2 versions: - fixed: 2.7.0 vulnerable_at: 2.6.1 summary: Woodpecker's custom workspace allow to overwrite plugin entrypoint executable in go.woodpecker-ci.org/woodpecker cves: - CVE-2024-41121 ghsas: - GHSA-xw35-rrcp-g7xm references: - advisory: https://github.com/advisories/GHSA-xw35-rrcp-g7xm - advisory: https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-xw35-rrcp-g7xm - fix: https://github.com/woodpecker-ci/woodpecker/commit/764329ed1dbc47c4a517ccc749e3feb34059fac8 - fix: https://github.com/woodpecker-ci/woodpecker/pull/3933 - report: https://github.com/woodpecker-ci/woodpecker/issues/3924 source: id: GHSA-xw35-rrcp-g7xm created: 2024-07-19T20:01:20.387548324Z review_status: UNREVIEWED
The text was updated successfully, but these errors were encountered:
Change https://go.dev/cl/601382 mentions this issue: data/reports: add GO-2024-2999
data/reports: add GO-2024-2999
Sorry, something went wrong.
Change https://go.dev/cl/603235 mentions this issue: data/reports: add 29 unreviewed reports
data/reports: add 29 unreviewed reports
7162f20
No branches or pull requests
Advisory GHSA-xw35-rrcp-g7xm references a vulnerability in the following Go modules:
Description:
Impact
The server allow to create any user who can trigger a pipeline run malicious workflows:
Patches
woodpecker-ci/woodpecker#3933
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
Enable the "gated" repo feature and review each change upfront
References
References:
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: