—
GO-2022-1032
Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package in github.com/cloudflare/goflow
Quick fix
GO-2022-1032 — github.com/cloudflare/goflow/v3: upgrade to the fixed version with the command below.
go get github.com/cloudflare/goflow/v3@v3.4.4Details
Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package in github.com/cloudflare/goflow
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/cloudflare/goflow
Introduced in:
0No fixed version published yet for github.com/cloudflare/goflow (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/cloudflare/goflow/v3
Introduced in:
0Fixed in: 3.4.4Fix
go get github.com/cloudflare/goflow/v3@v3.4.4References
- https://github.com/cloudflare/goflow/security/advisories/GHSA-9rpw-2h95-666c[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2022-2529[ADVISORY]
- https://github.com/cloudflare/goflow/commit/2b94619a6204443e3ca1769f4e459f9f57039c51[FIX]
- https://github.com/cloudflare/goflow/commit/c829ccd2c0aafdc9b886b20bf6f28095607f4998[FIX]
- https://github.com/cloudflare/goflow/releases/tag/v3.4.4[WEB]