Vulnerability Database
Blog
FAQ
Docs
GO-2024-3136
See a problem?
Source
https://pkg.go.dev/vuln/GO-2024-3136
Import Source
https://vuln.go.dev/ID/GO-2024-3136.json
JSON Data
https://api.osv.dev/v1/vulns/GO-2024-3136
Aliases
CVE-2023-27584
GHSA-hpc8-7wpm-889w
Published
2024-09-26T18:24:03Z
Modified
2024-09-26T18:57:43.440200Z
Summary
Dragonfly2 has hard coded cyptographic key in d7y.io/dragonfly
Details
Dragonfly2 has hard coded cyptographic key in d7y.io/dragonfly
References
https://github.com/dragonflyoss/Dragonfly2/security/advisories/GHSA-hpc8-7wpm-889w
https://nvd.nist.gov/vuln/detail/CVE-2023-27584
https://github.com/dragonflyoss/Dragonfly2/commit/e9da69dc4048bf2a18a671be94616d85e3429433
https://github.com/dragonflyoss/Dragonfly2/releases/tag/v2.0.9
Affected packages
Go
/
d7y.io/dragonfly/v2
Package
Name
d7y.io/dragonfly/v2
View open source insights on deps.dev
Purl
pkg:golang/d7y.io/dragonfly/v2
Affected ranges
Type
SEMVER
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.1.0-beta.1
GO-2024-3136 - OSV