—
GO-2024-2984
Linkerd potential access to the shutdown endpoint in github.com/linkerd/linkerd2
Quick fix
GO-2024-2984 — github.com/linkerd/linkerd2: upgrade to the fixed version with the command below.
go get github.com/linkerd/linkerd2@v0.5.1-0.20240614165515-35fb2d6d11efDetails
Linkerd potential access to the shutdown endpoint in github.com/linkerd/linkerd2
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/linkerd/linkerd2
Introduced in:
0Fixed in: 0.5.1-0.20240614165515-35fb2d6d11efFix
go get github.com/linkerd/linkerd2@v0.5.1-0.20240614165515-35fb2d6d11efReferences
- https://nvd.nist.gov/vuln/detail/CVE-2024-40632[ADVISORY]
- https://github.com/linkerd/linkerd2/commit/35fb2d6d11ef6520ae516dd717790529f85224fa[FIX]
- https://github.com/linkerd/linkerd2-proxy/blob/46957de49f25fd4661af7b7c52659148f4d6dd27/linkerd/app/admin/src/server.rs[WEB]
- https://github.com/linkerd/linkerd2/security/advisories/GHSA-6v94-gj6x-jqj7[WEB]