i-love-flamingo / pugtemplate

A Pug Template engine for Flamingo

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

dependencies: fix vunlerability

jeinfeldt opened this issue · comments

Hello friends,
when running Nancy on pugtemplate it detects a vulnerable dependency.

I am on pugtemplate master and execute:

go list -json -m all | docker run --rm -i sonatypecommunity/nancy:latest sleuth


Checking for updates...
Already up-to-date.
1 known vulnerabilities affecting installed version
┃ [CVE-2019-11840]  Use of Insufficiently Random Values                                                                                                                                                                       ┃
┃ Description        ┃ An issue was discovered in supplementary Go cryptography libraries, aka                                                                                                                                ┃
┃                    ┃ golang-googlecode-go-crypto, before 2019-03-20. A flaw was found in the                                                                                                                                ┃
┃                    ┃ amd64 implementation of golang.org/x/crypto/salsa20 and                                                                                                                                                ┃
┃                    ┃ golang.org/x/crypto/salsa20/salsa. If more than 256 GiB of keystream is                                                                                                                                ┃
┃                    ┃ generated, or if the counter otherwise grows greater than 32 bits, the                                                                                                                                 ┃
┃                    ┃ amd64 implementation will first generate incorrect output, and then cycle                                                                                                                              ┃
┃                    ┃ back to previously generated keystream. Repeated keystream bytes can lead                                                                                                                              ┃
┃                    ┃ to loss of confidentiality in encryption applications, or to predictability                                                                                                                            ┃
┃                    ┃ in CSPRNG applications.                                                                                                                                                                                ┃
┃ OSS Index ID       ┃ 5121f5ff-9831-44a6-af2e-24f7301d1df7                                                                                                                                                                   ┃
┃ CVSS Score         ┃ 5.9/10 (Medium)                                                                                                                                                                                        ┃
┃ CVSS Vector        ┃ CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N                                                                                                                                                           ┃
┃ Link for more info ┃ https://ossindex.sonatype.org/vuln/5121f5ff-9831-44a6-af2e-24f7301d1df7?component-type=golang&component-name=golang.org%2Fx%2Fcrypto&utm_source=nancy-client&utm_medium=integration&utm_content=1.0.15 ┃

1 Vulnerable Packages

┃ Summary                       ┃
┃ Audited Dependencies    ┃ 103 ┃
┃ Vulnerable Dependencies ┃ 1   ┃