Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deps: update golang.org/x/crypto #13335

Closed
wants to merge 1 commit into from
Closed

Conversation

mickael-hc
Copy link
Contributor

Fixes a vulnerability (CVE-2021-43565) in the golang.org/x/crypto/ssh package which allowed unauthenticated clients to cause a panic in SSH servers.

Vault should not be affected by this denial-of-service vulnerability as Vault does not use this library to expose an SSH server.

@mickael-hc mickael-hc added dependencies Pull requests that update a dependency file pr/no-changelog labels Dec 3, 2021
Fixes a vulnerability (CVE-2021-43565) in the golang.org/x/crypto/ssh package which allowed unauthenticated clients to cause a panic in SSH servers.

Vault should not be affected by this denial-of-service vulnerability as Vault does not use this library to expose an SSH server.
@mickael-hc mickael-hc force-pushed the deps/update-golang-crypto branch from 8e3823e to ac02a7f Compare January 5, 2022 16:00
@vercel vercel bot temporarily deployed to Preview – vault-storybook January 5, 2022 16:00 Inactive
@vercel vercel bot temporarily deployed to Preview – vault January 5, 2022 16:00 Inactive
@mickael-hc
Copy link
Contributor Author

mickael-hc commented Feb 18, 2022

Resolved in #14138

@mickael-hc mickael-hc closed this Feb 18, 2022
@mickael-hc mickael-hc deleted the deps/update-golang-crypto branch February 18, 2022 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file pr/no-changelog
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant