simplycubed/terraform-google-static-assets

CVE-2021-44716 (High) detected in github.com/docker/distribution-v2.8.1+incompatible - autoclosed

Closed this issue · 1 comments

CVE-2021-44716 - High Severity Vulnerability

Vulnerable Library - github.com/docker/distribution-v2.8.1+incompatible

Library home page: https://proxy.golang.org/github.com/docker/distribution/@v/v2.8.1+incompatible.zip

Dependency Hierarchy:

  • github.com/gruntwork-io/terratest-v0.40.17 (Root Library)
    • github.com/google/go-containerregistry-v0.9.0
      • github.com/docker/distribution-v2.8.1+incompatible (Vulnerable Library)

Found in HEAD commit: e49e2f33b77657ce4ab7eac9abebafc4a1fd18ba

Found in base branch: master

Vulnerability Details

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

Publish Date: 2022-01-01

URL: CVE-2021-44716

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-vc3p-29h2-gpcp

Release Date: 2022-01-01

Fix Resolution: github.com/golang/net - 491a49abca63de5e07ef554052d180a1b5fe2d70


Step up your Open Source Security Game with Mend here

✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.