—
GO-2024-2987
Skupper uses a static cookie secret for the openshift oauth-proxy in github.com/skupperproject/skupper
Quick fix
GO-2024-2987 — github.com/skupperproject/skupper: upgrade to the fixed version with the command below.
go get github.com/skupperproject/skupper@v0.0.0-20240703184342-c26bce4079ffDetails
Skupper uses a static cookie secret for the openshift oauth-proxy in github.com/skupperproject/skupper
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/skupperproject/skupper
Introduced in:
0Fixed in: 0.0.0-20240703184342-c26bce4079ffFix
go get github.com/skupperproject/skupper@v0.0.0-20240703184342-c26bce4079ffReferences
- https://github.com/advisories/GHSA-w799-v85j-88pg[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-6535[ADVISORY]
- https://github.com/skupperproject/skupper/commit/d2cb3782e807853694ee66b6e3d4a1917485eb71[FIX]
- https://access.redhat.com/errata/RHSA-2024:4865[WEB]
- https://access.redhat.com/errata/RHSA-2024:4871[WEB]
- https://access.redhat.com/security/cve/CVE-2024-6535[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2296024[WEB]