Vulnerability Report: GO-2024-3058
- CVE-2024-41270, GHSA-p3pf-mff8-3h47
- Affects: github.com/appleboy/gorush
- Published: Aug 19, 2024
An issue in the RunHTTPServer function in Gorush allows attackers to intercept and manipulate data due to the use of a deprecated TLS version.
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-p3pf-mff8-3h47.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.18.5
Aliases
References
- https://github.com/advisories/GHSA-p3pf-mff8-3h47
- https://github.com/appleboy/gorush/commit/067cb597e485e40b790a267187bf7f00730b1c4b
- https://github.com/appleboy/gorush/issues/792
- https://gist.github.com/nyxfqq/cfae38fada582a0f576d154be1aeb1fc
- https://vuln.go.dev/ID/GO-2024-3058.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.