WS-2021-0200 (High) detected in github.com/docker/distribution-v2.7.1-0.20190205005809-0d3efadf0154+incompatible #8
Labels
security vulnerability
Security vulnerability detected by WhiteSource
WS-2021-0200 - High Severity Vulnerability
Vulnerable Library - github.com/docker/distribution-v2.7.1-0.20190205005809-0d3efadf0154+incompatible
The Docker toolset to pack, ship, store, and deliver content
Library home page: https://proxy.golang.org/github.com/docker/distribution/@v/v2.7.1-0.20190205005809-0d3efadf0154+incompatible.zip
Dependency Hierarchy:
Found in HEAD commit: 74c0db1e26014a7f5e115cea39a5b8613c912db7
Found in base branch: master
Vulnerability Details
Yaml in versions v2.2.0 to v2.2.2 is vulnerable to denial of service vector.
Related to decode.go
Publish Date: 2021-04-14
URL: WS-2021-0200
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/GO-2021-0061
Release Date: 2021-04-14
Fix Resolution: v2.2.3
The text was updated successfully, but these errors were encountered: