—
GO-2024-2853
sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address in github.com/tg123/sshpiper
Quick fix
GO-2024-2853 — github.com/tg123/sshpiper: upgrade to the fixed version with the command below.
go get github.com/tg123/sshpiper@v1.3.0Details
sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address in github.com/tg123/sshpiper
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/tg123/sshpiper
Introduced in:
1.0.50Fixed in: 1.3.0Fix
go get github.com/tg123/sshpiper@v1.3.0References
- https://github.com/tg123/sshpiper/security/advisories/GHSA-4w53-6jvp-gg52[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-35175[ADVISORY]
- https://github.com/tg123/sshpiper/commit/2ddd69876a1e1119059debc59fe869cb4e754430[FIX]
- https://github.com/tg123/sshpiper/commit/70fb830dca26bea7ced772ce5d834a3e88ae7f53[FIX]