—
GO-2024-2885
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder
Quick fix
GO-2024-2885 — github.com/stacklok/minder: upgrade to the fixed version with the command below.
go get github.com/stacklok/minder@v0.0.51Details
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/stacklok/minder
Introduced in:
0Fixed in: 0.0.51Fix
go get github.com/stacklok/minder@v0.0.51References
- https://github.com/stacklok/minder/security/advisories/GHSA-8fmj-33gw-g7pw[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-35238[ADVISORY]
- https://github.com/stacklok/minder/commit/fe321d345b4f738de6a06b13207addc72b59f892[FIX]
- https://github.com/stacklok/minder/blob/daccbc12e364e2d407d56b87a13f7bb24cbdb074/internal/verifier/sigstore/container/container.go#L271-L300[WEB]