From 1a9cf70642eeae4ccc7bcdaa6afb8dc3cda97fa8 Mon Sep 17 00:00:00 2001 From: "octo-sts[bot]" <157150467+octo-sts[bot]@users.noreply.github.com> Date: Fri, 20 Dec 2024 07:44:32 +0000 Subject: [PATCH] Adding Advisory GHSA-w32m-9786-jp63 for cert-manager-istio-csr (#10753) Co-authored-by: octo-sts[bot] <157150467+octo-sts@users.noreply.github.com> --- cert-manager-istio-csr.advisories.yaml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/cert-manager-istio-csr.advisories.yaml b/cert-manager-istio-csr.advisories.yaml index 8c06bb26f2..5c703e7a1e 100644 --- a/cert-manager-istio-csr.advisories.yaml +++ b/cert-manager-istio-csr.advisories.yaml @@ -116,6 +116,24 @@ advisories: type: vulnerable-code-not-included-in-package note: 'The upstream project ignored the vulnerability since they import non-tagged versions in go.mod, for more information see: https://github.com/cert-manager/istio-csr/pull/344/files.' + - id: CGA-m24w-7f29-vfjq + aliases: + - CVE-2024-45338 + - GHSA-w32m-9786-jp63 + events: + - timestamp: 2024-12-20T07:22:49Z + type: detection + data: + type: scan/v1 + data: + subpackageName: cert-manager-istio-csr + componentID: 7eea074db6939525 + componentName: golang.org/x/net + componentVersion: v0.30.0 + componentType: go-module + componentLocation: /usr/bin/cmd + scanner: grype + - id: CGA-pw2v-5gqw-v996 aliases: - CVE-2021-39155