—
GO-2024-2644
Fluid vulnerable to OS Command Injection for Fluid Users with JuicefsRuntime in github.com/fluid-cloudnative/fluid
Quick fix
GO-2024-2644 — github.com/fluid-cloudnative/fluid: upgrade to the fixed version with the command below.
go get github.com/fluid-cloudnative/fluid@v0.9.3Details
Fluid vulnerable to OS Command Injection for Fluid Users with JuicefsRuntime in github.com/fluid-cloudnative/fluid
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/fluid-cloudnative/fluid
Introduced in:
0Fixed in: 0.9.3Fix
go get github.com/fluid-cloudnative/fluid@v0.9.3References
- https://github.com/fluid-cloudnative/fluid/security/advisories/GHSA-wx8q-4gm9-rj2g[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-51699[ADVISORY]
- https://github.com/fluid-cloudnative/fluid/commit/02b7cd8b79a26092df95d625664994bda485c722[FIX]
- https://github.com/fluid-cloudnative/fluid/commit/e0184cff8790ad000c3e8943392c7f544fad7d66[FIX]