Could you guy’s please fix this [HIGH] CVE-2023-0464 - libcrypto3-3.0.8-r0, and this golang.org/x/net │ CVE-2022-41723 │ HIGH │ v0.6.0 │ 0.7.0 │ golang.org/x/net/http2: avoid quadratic complexity in HPACK │ and please release a new version asap.
There are several pull requests open against hashi products to address this. See e.g.
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| HCSEC-2023-02 - Vault, Consul, Boundary, and Waypoint Affected By Denial of Service in Go’s net/http (CVE-2022-41717) | 0 | 5384 | February 8, 2023 | |
| HCSEC-2021-34 - Vault, Consul, Boundary, and Waypoint Affected By Denial of Service in Golang’s net/http (CVE-2021-44716) | 0 | 5157 | December 22, 2021 | |
| Denial Of Service vulnerability discovered in Golang. (CVE-2022-27664) - consul | 0 | 420 | December 2, 2022 | |
| Consul-Terraform-Sync v0.3.1 | 0 | 415 | January 18, 2022 | |
| Consul-Terraform-Sync v0.4.3 | 0 | 481 | January 18, 2022 |