fix: bump golang.org/x/net to v0.33.0 to mitigate CVE-2024-45338 #997
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description of your changes
There is a new CVE CVE-2024-45338 published yesterday marked with HIGH severity. This CVE impacts the low-level library golang/x/net, which is again, widely used by most components that have network access.
This CVE affects the code path on the golang.org/x/net/html package, on the API calls Parse/ParseXXX functions. This CVE is exploitable if your code is taking direct user input and feeding to the x/net/html function. The previous implementation is subject to denial-of-service attack for handling huge payload with the strings.ToLower call.
Fixes #
I have:
make reviewable
to ensure this PR is ready for review.How has this code been tested
Special notes for your reviewer