4 open findings · 0 with upstream fix available · 0 after VEX (4 suppressed)
not_affected · vulnerable_code_not_presentnot_affected · vulnerable_code_not_present| Package | Version | Severity | CVE | Fix | Description | VEX |
|---|---|---|---|---|---|---|
| github.com/aws/aws-sdk-go | v1.55.8 | MEDIUM | GO-2022-0646 | — | A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without compu | VEX |
| github.com/aws/aws-sdk-go | v1.55.8 | MEDIUM | GO-2022-0646 | — | A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without compu | VEX |
| github.com/aws/aws-sdk-go | v1.55.8 | LOW | GO-2022-0635 | — | A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bu | VEX |
| github.com/aws/aws-sdk-go | v1.55.8 | LOW | GO-2022-0635 | — | A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bu | VEX |