aws / aws/amazon-vpc-cni-plugins

upgrade go version to prevent rapid reset http2 DOS on API server

Open
#105 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
68
Forks
54
PR merge metrics
No merged PRs in 30d

Description

### Summary

Hi, I'm reaching to ask if there is a plan to upgrade go version to address the CVE-2023-39325 : https://github.com/advisories/GHSA-4374-p667-p6c8.

Thank you.

### Description

### Expected Behavior

### Observed Behavior

### Environment Details

### Supporting Log Snippets

Contributor guide

Open the contributing guide

Research direction

No files or tests are named. Start by locating the repository's Go version declarations and build or release configuration, then determine how the CVE affects the API server. Done means the Go version is upgraded and the relevant build or test checks confirm the project still works.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
networking
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.