VDB
KO

GO-2024-3306

Vitess allows HTML injection in /debug/querylogz and /debug/env in vitess.io/vitess

Quick fix

GO-2024-3306 — vitess.io/vitess: upgrade to the fixed version with the command below.

go get vitess.io/vitess@v0.19.8

Details

Vitess allows HTML injection in /debug/querylogz and /debug/env in vitess.io/vitess

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / vitess.io/vitess
Introduced in: 0 Fixed in: 0.19.8
Fix go get vitess.io/vitess@v0.19.8

References