—
GO-2024-3343
Open Cluster Management vulnerable to Trust Boundary Violation in open-cluster-management.io/ocm
Quick fix
GO-2024-3343 — open-cluster-management.io/ocm: upgrade to the fixed version with the command below.
go get open-cluster-management.io/ocm@v0.13.0Details
Open Cluster Management vulnerable to Trust Boundary Violation in open-cluster-management.io/ocm
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/open-cluster-management.io/ocm
Introduced in:
0Fixed in: 0.13.0Fix
go get open-cluster-management.io/ocm@v0.13.0References
- https://github.com/advisories/GHSA-jhh6-6fhp-q2xp[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-9779[ADVISORY]
- https://access.redhat.com/security/cve/CVE-2024-9779[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2317916[WEB]
- https://github.com/open-cluster-management-io/ocm/pull/325[WEB]
- https://github.com/open-cluster-management-io/ocm/releases/tag/v0.13.0[WEB]
- https://github.com/open-cluster-management-io/registration-operator/issues/361[WEB]