Skip to content

[Aikido] Fix multiple security issues#16

Open
aikido-autofix[bot] wants to merge 1 commit intothor-upstreamfrom
fix/aikido-security-update-packages-5277289-wHNf
Open

[Aikido] Fix multiple security issues#16
aikido-autofix[bot] wants to merge 1 commit intothor-upstreamfrom
fix/aikido-security-update-packages-5277289-wHNf

Conversation

@aikido-autofix
Copy link

This PR will resolve the following CVEs:

CVE ID Severity Description
CVE-2019-20933
🚨 CRITICAL
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).
CVE-2024-45337
🚨 CRITICAL
Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is ...

@socket-security
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants