Vulnerability Report: GO-2023-2137
- CVE-2023-45825, GHSA-q24m-6h38-5xj8
- Affects: github.com/ydb-platform/ydb-go-sdk/v3
- Published: Oct 24, 2023
- Modified: May 20, 2024
A custom credentials object that does not implement the fmt.Stringer interface may leak sensitive information (e.g., credentials) via logs.
For detailed information about this vulnerability, visit https://github.com/ydb-platform/ydb-go-sdk/security/advisories/GHSA-q24m-6h38-5xj8.
Affected Packages
-
PathGo VersionsSymbols
-
from v3.48.6 before v3.53.3
22 affected symbols
- Connector
- Driver.Close
- Driver.Coordination
- Driver.Discovery
- Driver.Ratelimiter
- Driver.Scheme
- Driver.Scripting
- Driver.Table
- Driver.Topic
- Driver.With
- IsTimeoutError
- IsTransportError
- MustConnector
- MustOpen
- New
- Open
- Unwrap
- WithAccessTokenCredentials
- WithAnonymousCredentials
- WithCertificatesFromFile
- WithRequestType
- WithTraceID
-
from v3.48.6 before v3.53.3
-
from v3.48.6 before v3.53.3
-
from v3.48.6 before v3.53.3
-
from v3.48.6 before v3.53.3
Aliases
References
- https://github.com/ydb-platform/ydb-go-sdk/security/advisories/GHSA-q24m-6h38-5xj8
- https://github.com/ydb-platform/ydb-go-sdk/pull/859
- https://github.com/ydb-platform/ydb-go-sdk/commit/a0d92057c4e1bbdc5e85ae8d649edb0232b8fd4c
- https://vuln.go.dev/ID/GO-2023-2137.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.