—
GO-2026-5196
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
상세
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
Go / github.com/coder/coder
최초 영향 버전:
0 No fixed version published yet for github.com/coder/coder (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/coder/coder/v2
최초 영향 버전:
0 수정 버전: 2.24.5 수정
go get github.com/coder/coder/v2@v2.24.5 참고
- https://github.com/coder/coder/security/advisories/GHSA-6x44-w3xg-hqqf [ADVISORY]
- https://github.com/coder/coder/pull/25286 [FIX]
- https://github.com/coder/coder/releases/tag/v2.24.5 [WEB]
- https://github.com/coder/coder/releases/tag/v2.29.13 [WEB]
- https://github.com/coder/coder/releases/tag/v2.30.8 [WEB]
- https://github.com/coder/coder/releases/tag/v2.31.12 [WEB]
- https://github.com/coder/coder/releases/tag/v2.32.2 [WEB]
- https://github.com/coder/coder/releases/tag/v2.33.3 [WEB]