Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/huandu/facebook: CVE-2024-35232 #2882

Closed
GoVulnBot opened this issue May 24, 2024 · 1 comment
Closed
Labels

Comments

@GoVulnBot
Copy link

CVE-2024-35232 references github.com/huandu/facebook, which may be a Go module.

Description:
github.com/huandu/facebook is a Go package that fully supports the Facebook Graph API with file upload, batch request and marketing API. access_token can be exposed in error message on fail in HTTP request. This issue has been patched in version 2.7.2.

References:

Cross references:
No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/huandu/facebook
      vulnerable_at: 1.8.1
      packages:
        - package: facebook
summary: CVE-2024-35232 in github.com/huandu/facebook
cves:
    - CVE-2024-35232
references:
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-35232
    - fix: https://github.com/huandu/facebook/commit/8b34431b91b32903c8821b1d7621bf81a029d8e4
    - web: https://cs.opensource.google/go/go/+/refs/tags/go1.22.3:src/net/http/client.go;l=629-633
    - web: https://cs.opensource.google/go/go/+/refs/tags/go1.22.3:src/net/url/url.go;l=30
    - web: https://github.com/huandu/facebook/blob/1591be276561bbdb019c0279f1d33cb18a650e1b/session.go#L558-L567
    - web: https://github.com/huandu/facebook/security/advisories/GHSA-3f65-m234-9mxr
source:
    id: CVE-2024-35232
    created: 2024-05-24T22:01:26.122077624Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/590277 mentions this issue: data/reports: add 26 unreviewed reports

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants