aws / aws/eks-distro

GHSA-c5q2-7r4c-mv6g/CVE-2024-28180 detected in square/go-jose

Open
#3,613 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
1.5k
Forks
198
Avg merge
10h 46m
Merged PRs (30d)
28

Description

**What happened**:
[GHSA-c5q2-7r4c-mv6g](https://github.com/advisories/GHSA-c5q2-7r4c-mv6g)/[CVE-2024-28180](https://nvd.nist.gov/vuln/detail/CVE-2024-28180) was detected in multiple versions of eks-distro

square/go-jose deprecated since January 10, 2023, are there plans to replace it with https://github.com/go-jose/go-jose?

**What you expected to happen**:
go-jose is either replaced with maintained version or is removed.

Contributor guide

Open the contributing guide

Research direction

Start by tracing eks-distro's dependency references to square/go-jose and review the GHSA-c5q2-7r4c-mv6g/CVE-2024-28180 advisory. Compare the maintained go-jose option, then verify that the vulnerable dependency is replaced or removed and the advisory is no longer detected.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.