Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Wiz Remediate Vulnerabilities in: /sdk/internal/go.mod, /sdk/keyvault/azkeys/testdata/perf/go.mod, /sdk/keyvault/azsecrets... #13

Open
wants to merge 19 commits into
base: master
Choose a base branch
from

Conversation

tomfeigin
Copy link

Wiz has identified Vulnerabilities in the following files: /sdk/internal/go.mod, /sdk/keyvault/azkeys/testdata/perf/go.mod, /sdk/keyvault/azsecrets/go.mod, /sdk/messaging/azservicebus/go.mod, /sdk/resourcemanager/billing/armbilling/go.mod, /sdk/resourcemanager/cdn/armcdn/go.mod, /sdk/resourcemanager/changeanalysis/armchangeanalysis/go.mod, /sdk/resourcemanager/containerregistry/armcontainerregistry/go.mod, /sdk/resourcemanager/containerservice/armcontainerservice/go.mod, /sdk/resourcemanager/databricks/armdatabricks/go.mod, /sdk/resourcemanager/datadog/armdatadog/go.mod, /sdk/resourcemanager/datafactory/armdatafactory/go.mod, /sdk/resourcemanager/hybridkubernetes/armhybridkubernetes/go.mod, /sdk/resourcemanager/policyinsights/armpolicyinsights/go.mod, /sdk/resourcemanager/privatedns/armprivatedns/go.mod, /sdk/resourcemanager/servicebus/armservicebus/go.mod, /sdk/resourcemanager/solutions/armmanagedapplications/go.mod, /sdk/resourcemanager/sql/armsql/go.mod, /sdk/resourcemanager/trafficmanager/armtrafficmanager/go.mod. This PR contains the remediations for them.

/sdk/internal/go.mod

Vulnerabilities:
CVE-2021-44716
CVE-2022-41717
CVE-2021-31525
CVE-2021-33194

/sdk/keyvault/azkeys/testdata/perf/go.mod

Vulnerabilities:
CVE-2022-41717
CVE-2023-39325
CVE-2023-44487
CVE-2023-3978
CVE-2021-44716
CVE-2022-41723
CVE-2023-45288
CVE-2022-27664

/sdk/keyvault/azsecrets/go.mod

Vulnerabilities:
CVE-2022-41723
CVE-2023-3978
CVE-2023-44487
CVE-2022-27664
CVE-2023-45288
CVE-2022-41717
CVE-2023-39325

/sdk/messaging/azservicebus/go.mod

Vulnerabilities:
CVE-2023-39325
CVE-2022-41723
CVE-2022-27664
CVE-2023-3978
CVE-2023-45288
CVE-2023-44487
CVE-2022-41717

/sdk/resourcemanager/billing/armbilling/go.mod

Vulnerabilities:
CVE-2023-44487
CVE-2022-27664
CVE-2022-41717
CVE-2023-3978
CVE-2023-45288
CVE-2023-39325
CVE-2022-41723

/sdk/resourcemanager/cdn/armcdn/go.mod

Vulnerabilities:
CVE-2023-3978
CVE-2023-39325
CVE-2023-45288
CVE-2022-41723
CVE-2023-44487
CVE-2022-27664
CVE-2022-41717

/sdk/resourcemanager/changeanalysis/armchangeanalysis/go.mod

Vulnerabilities:
CVE-2023-3978
CVE-2022-27664
CVE-2023-39325
CVE-2022-41717

/sdk/resourcemanager/containerregistry/armcontainerregistry/go.mod

Vulnerabilities:
CVE-2022-27664
CVE-2022-41723
CVE-2023-44487
CVE-2023-39325
CVE-2023-3978
CVE-2023-45288
CVE-2022-41717

/sdk/resourcemanager/containerservice/armcontainerservice/go.mod

Vulnerabilities:
CVE-2022-41717
CVE-2023-3978
CVE-2023-45288
CVE-2023-39325
CVE-2022-41723
CVE-2023-44487
CVE-2022-27664

/sdk/resourcemanager/databricks/armdatabricks/go.mod

Vulnerabilities:
CVE-2022-27664

/sdk/resourcemanager/datadog/armdatadog/go.mod

Vulnerabilities:
CVE-2022-41717
CVE-2022-41723
CVE-2022-27664
CVE-2023-3978

/sdk/resourcemanager/datafactory/armdatafactory/go.mod

Vulnerabilities:
CVE-2023-45288

/sdk/resourcemanager/hybridkubernetes/armhybridkubernetes/go.mod

Vulnerabilities:
CVE-2022-41723
CVE-2022-41717

/sdk/resourcemanager/policyinsights/armpolicyinsights/go.mod

Vulnerabilities:
CVE-2022-27664
CVE-2023-3978
CVE-2022-41723
CVE-2023-45288
CVE-2023-39325
CVE-2023-44487
CVE-2022-41717

/sdk/resourcemanager/privatedns/armprivatedns/go.mod

Vulnerabilities:
CVE-2022-41717
CVE-2022-41723

/sdk/resourcemanager/servicebus/armservicebus/go.mod

Vulnerabilities:
CVE-2023-39325
CVE-2023-44487
CVE-2023-45288
CVE-2022-41723
CVE-2023-3978
CVE-2022-27664

/sdk/resourcemanager/solutions/armmanagedapplications/go.mod

Vulnerabilities:
CVE-2023-44487
CVE-2022-27664
CVE-2023-45288
CVE-2022-41723
CVE-2022-41717
CVE-2023-3978
CVE-2023-39325

/sdk/resourcemanager/sql/armsql/go.mod

Vulnerabilities:
CVE-2023-3978
CVE-2022-27664
CVE-2022-41717
CVE-2022-41723
CVE-2023-44487
CVE-2023-45288
CVE-2023-39325

/sdk/resourcemanager/trafficmanager/armtrafficmanager/go.mod

Vulnerabilities:
CVE-2023-44487
CVE-2023-45288
CVE-2022-41723
CVE-2023-3978
CVE-2023-39325

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant