From 8575be83e22451fe0d5403958a70526b56383cc0 Mon Sep 17 00:00:00 2001 From: "octo-sts[bot]" <157150467+octo-sts[bot]@users.noreply.github.com> Date: Fri, 20 Dec 2024 13:43:49 +0000 Subject: [PATCH] Adding Advisory GHSA-w32m-9786-jp63 for timestamp-authority (#10829) Co-authored-by: octo-sts[bot] <157150467+octo-sts@users.noreply.github.com> --- timestamp-authority.advisories.yaml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/timestamp-authority.advisories.yaml b/timestamp-authority.advisories.yaml index 1d494be08d..2f1094cd4d 100644 --- a/timestamp-authority.advisories.yaml +++ b/timestamp-authority.advisories.yaml @@ -100,6 +100,24 @@ advisories: type: vulnerable-code-not-included-in-package note: Only affects Windows + - id: CGA-jh22-p8xx-jqmp + aliases: + - CVE-2024-45338 + - GHSA-w32m-9786-jp63 + events: + - timestamp: 2024-12-20T13:19:11Z + type: detection + data: + type: scan/v1 + data: + subpackageName: timestamp-authority + componentID: 3bda7e47a8064c5a + componentName: golang.org/x/net + componentVersion: v0.28.0 + componentType: go-module + componentLocation: /usr/bin/timestamp-server + scanner: grype + - id: CGA-jv7h-cgwm-hfx6 aliases: - CVE-2024-45337