Vulnerability Report: GO-2023-2017
- CVE-2023-38976, GHSA-8697-479h-5mfp
- Affects: github.com/weaviate/weaviate
- Published: Nov 02, 2023
- Modified: May 20, 2024
A type conversion issue in Weaviate may allow a remote attack that would cause a denial of service.
For detailed information about this vulnerability, visit https://github.com/weaviate/weaviate/security/advisories/GHSA-8697-479h-5mfp.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.18.6, from v1.19.0 before v1.19.13, from v1.20.0 before v1.20.6
Aliases
References
- https://github.com/weaviate/weaviate/security/advisories/GHSA-8697-479h-5mfp
- https://github.com/weaviate/weaviate/issues/3258
- https://github.com/weaviate/weaviate/pull/3431
- https://github.com/weaviate/weaviate/commit/2a7b208d9aca07e28969e3be82689c184ccf9118
- https://github.com/weaviate/weaviate/releases/tag/v1.18.6
- https://github.com/weaviate/weaviate/releases/tag/v1.19.13
- https://github.com/weaviate/weaviate/releases/tag/v1.20.6
- https://vuln.go.dev/ID/GO-2023-2017.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.