Skip to content

Conversation

@0xmountaintop
Copy link

@0xmountaintop 0xmountaintop commented Aug 21, 2024

cherry-pick 51c7eee

@0xmountaintop 0xmountaintop marked this pull request as draft August 21, 2024 12:41
@semgrep-app
Copy link

semgrep-app bot commented Aug 21, 2024

Semgrep found 1 ssc-46663897-ab0c-04dc-126b-07fe2ce42fb2 finding:

Risk: Affected versions of golang.org/x/net, golang.org/x/net/http2, and net/http are vulnerable to Uncontrolled Resource Consumption. An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames.

Fix: Upgrade this library to at least version 0.23.0 at go-ethereum/go.mod:146.

Reference(s): GHSA-4v7x-pqxf-cx7m, CVE-2023-45288

Ignore this finding from ssc-46663897-ab0c-04dc-126b-07fe2ce42fb2.

@0xmountaintop 0xmountaintop force-pushed the syncUpstream/shadow-fork branch from d30a547 to bee02a5 Compare August 23, 2024 05:01
@0xmountaintop 0xmountaintop marked this pull request as ready for review August 23, 2024 05:02
@0xmountaintop 0xmountaintop merged commit 0c312be into syncUpstream/active Aug 23, 2024
@0xmountaintop 0xmountaintop deleted the syncUpstream/shadow-fork branch August 23, 2024 05:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants