Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2021-3538 on package github.com/satori/go.uuid #82

Closed
Benjaminvdv opened this issue Aug 8, 2023 · 1 comment
Closed

CVE-2021-3538 on package github.com/satori/go.uuid #82

Benjaminvdv opened this issue Aug 8, 2023 · 1 comment

Comments

@Benjaminvdv
Copy link
Contributor

Hello,

Go module github.com/satori/go.uuid version 1.2.0 is unmaintained and has a weak number generator, thus should be replaced.

CVE details: https://nvd.nist.gov/vuln/detail/CVE-2021-3538
Reported issue: satori/go.uuid#120 (which also links to satori/go.uuid#73 for more context.

As others have advised, this could potentially be replaced with https://github.com/gofrs/uuid or https://github.com/google/uuid.

Hopefully this provides enough context.

With regards,
Benjamin

@Tieske
Copy link
Member

Tieske commented Sep 5, 2023

Pr was merged, closing.

@Tieske Tieske closed this as completed Sep 5, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants