Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability: Please upgrade dependences #818

Open
5 tasks done
digitive opened this issue Jul 14, 2024 · 0 comments
Open
5 tasks done

Vulnerability: Please upgrade dependences #818

digitive opened this issue Jul 14, 2024 · 0 comments
Labels
bug Something is not working.

Comments

@digitive
Copy link

Preflight checklist

Ory Network Project

No response

Describe the bug

Below vulnerabilities are found by snyk scanner:

✗ Medium severity vulnerability found in [github.com/hashicorp/go-retryablehttp](http://github.com/hashicorp/go-retryablehttp)
  Description: Insertion of Sensitive Information into Log File
  Info: https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMHASHICORPGORETRYABLEHTTP-7362036
  Introduced through: [github.com/ory/[email protected]](http://github.com/ory/[email protected]), [github.com/ory/fosite/[email protected]](http://github.com/ory/fosite/[email protected])
  From: [github.com/ory/[email protected]](http://github.com/ory/[email protected]) > [github.com/hashicorp/[email protected]](http://github.com/hashicorp/[email protected])
  From: [github.com/ory/fosite/[email protected]](http://github.com/ory/fosite/[email protected]) > [github.com/ory/fosite/token/[email protected]](http://github.com/ory/fosite/token/[email protected]) > [github.com/ory/[email protected]](http://github.com/ory/[email protected]) > [github.com/hashicorp/[email protected]](http://github.com/hashicorp/[email protected])
  Fixed in: 0.7.7
✗ High severity vulnerability found in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
  Description: Allocation of Resources Without Limits or Throttling
  Info: https://security.snyk.io/vuln/SNYK-GOLANG-GOOPENTELEMETRYIOCONTRIBINSTRUMENTATIONNETHTTPOTELHTTP-5963583
  Introduced through: github.com/ory/[email protected], [github.com/ory/fosite/[email protected]](http://github.com/ory/fosite/[email protected])
  From: [github.com/ory/[email protected]](http://github.com/ory/[email protected]) > github.com/ory/x/[email protected] > go.opentelemetry.io/contrib/instrumentation/net/http/[email protected]
  From: [github.com/ory/fosite/[email protected]](http://github.com/ory/fosite/[email protected]) > [github.com/ory/fosite/token/[email protected]](http://github.com/ory/fosite/token/[email protected]) > [github.com/ory/[email protected]](http://github.com/ory/[email protected]) > github.com/ory/x/[email protected] > go.opentelemetry.io/contrib/instrumentation/net/http/[email protected]
  Fixed in: 0.44.0
✗ High severity vulnerability found in [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp](http://go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp)
  Description: Allocation of Resources Without Limits or Throttling
  Info: https://security.snyk.io/vuln/SNYK-GOLANG-GOOPENTELEMETRYIOCONTRIBINSTRUMENTATIONNETHTTPOTELHTTP-5971109
  Introduced through: [github.com/ory/[email protected]](http://github.com/ory/[email protected]), [github.com/ory/fosite/[email protected]](http://github.com/ory/fosite/[email protected])
  From: [github.com/ory/[email protected]](http://github.com/ory/[email protected]) > [github.com/ory/x/[email protected]](http://github.com/ory/x/[email protected]) > [go.opentelemetry.io/contrib/instrumentation/net/http/[email protected]](http://go.opentelemetry.io/contrib/instrumentation/net/http/[email protected])
  From: [github.com/ory/fosite/[email protected]](http://github.com/ory/fosite/[email protected]) > [github.com/ory/fosite/token/[email protected]](http://github.com/ory/fosite/token/[email protected]) > [github.com/ory/[email protected]](http://github.com/ory/[email protected]) > [github.com/ory/x/[email protected]](http://github.com/ory/x/[email protected]) > [go.opentelemetry.io/contrib/instrumentation/net/http/[email protected]](http://go.opentelemetry.io/contrib/instrumentation/net/http/[email protected])
  Fixed in: 0.44.0
✗ High severity vulnerability found in go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace
  Description: Allocation of Resources Without Limits or Throttling
  Info: https://security.snyk.io/vuln/SNYK-GOLANG-GOOPENTELEMETRYIOCONTRIBINSTRUMENTATIONNETHTTPHTTPTRACEOTELHTTPTRACE-5971114
  Introduced through: [github.com/ory/[email protected]](http://github.com/ory/[email protected]), [github.com/ory/fosite/[email protected]](http://github.com/ory/fosite/[email protected])
  From: [github.com/ory/[email protected]](http://github.com/ory/[email protected]) > [github.com/ory/x/[email protected]](http://github.com/ory/x/[email protected]) > github.com/ory/x/[email protected] > go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/[email protected]
  From: [github.com/ory/fosite/[email protected]](http://github.com/ory/fosite/[email protected]) > [github.com/ory/fosite/token/[email protected]](http://github.com/ory/fosite/token/[email protected]) > [github.com/ory/[email protected]](http://github.com/ory/[email protected]) > [github.com/ory/x/[email protected]](http://github.com/ory/x/[email protected]) > github.com/ory/x/[email protected] > go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/[email protected]
  Fixed in: 0.44.0

Reproducing the bug

Refer to https://docs.snyk.io/scan-using-snyk/snyk-open-source

Relevant log output

No response

Relevant configuration

No response

Version

0.46.1

On which operating system are you observing this issue?

Linux

In which environment are you deploying?

None

Additional Context

No response

@digitive digitive added the bug Something is not working. label Jul 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something is not working.
Projects
None yet
Development

No branches or pull requests

1 participant