-
Notifications
You must be signed in to change notification settings - Fork 74
Closed
Labels
Description
Advisory GHSA-9v35-4xcr-w9ph references a vulnerability in the following Go modules:
| Module |
|---|
| github.com/netbirdio/netbird |
Description:
A static initialization vector (IV) in the encrypt function of netbird v0.28.4 allows attackers to obtain sensitive information.
References:
- ADVISORY: GHSA-9v35-4xcr-w9ph
- ADVISORY: https://nvd.nist.gov/vuln/detail/CVE-2024-41260
- REPORT: CBC Encryption with Fixed IV in Encrypt Function netbirdio/netbird#2246
- WEB: https://gist.github.com/nyxfqq/92232108ac153e95d538bb17fc5ad636
No existing reports found with this module or alias.
See doc/quickstart.md for instructions on how to triage this report.
id: GO-ID-PENDING
modules:
- module: github.com/netbirdio/netbird
vulnerable_at: 0.28.7
summary: NetBird uses a static initialization vector (IV) in github.com/netbirdio/netbird
cves:
- CVE-2024-41260
ghsas:
- GHSA-9v35-4xcr-w9ph
references:
- advisory: https://github.com/advisories/GHSA-9v35-4xcr-w9ph
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-41260
- report: https://github.com/netbirdio/netbird/issues/2246
- web: https://gist.github.com/nyxfqq/92232108ac153e95d538bb17fc5ad636
source:
id: GHSA-9v35-4xcr-w9ph
created: 2024-08-07T15:01:14.124788104Z
review_status: UNREVIEWED