Skip to content

Problems with GHSA-2v4p-qf9q-27wj #9772

Description

@easwars

The grpc-go team recently published a security advisory: GHSA-2v4p-qf9q-27wj

The fix for the above vulnerability was made to our master branch after we cut the branch for release 1.84.0. The advisory initially mentioned that the vulnerability affected versions <=1.83.1, because at that point the most recent release was 1.83.1. As part of publishing the advisory we also pushed out a couple of patch releases, 1.82.2 and 1.83.2 and marked them as the patched versions in the advisory.

After publishing the advisory, we cherry-picked the change into the 1.84.x branch and pushed out 1.84.0 release that contained the fix.

But scanning tools are listing 1.84.0 to be affected by this vulnerability and downstream users of grpc-go using 1.84.0 are showing up as vulnerable.

How do we go about fixing this?

Please let us know if there is something more needs to be done from our side.

Thanks

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions