diff options
| author | Markus Pettersson <markus.pettersson@mullvad.net> | 2025-03-12 08:51:50 +0100 |
|---|---|---|
| committer | Markus Pettersson <markus.pettersson@mullvad.net> | 2025-03-12 12:40:41 +0100 |
| commit | 4cab60977ac4991934804d68b5fef64f99b6329e (patch) | |
| tree | 16e76c772c381a84a5d084130d23652ad7226049 | |
| parent | 2935cc630c8bc59f548504ffa841e14f76ec7632 (diff) | |
| download | mullvadvpn-4cab60977ac4991934804d68b5fef64f99b6329e.tar.xz mullvadvpn-4cab60977ac4991934804d68b5fef64f99b6329e.zip | |
Update end date for silencing CVEs in `libwg/osv-scanner.toml`
| -rw-r--r-- | wireguard-go-rs/libwg/osv-scanner.toml | 14 |
1 files changed, 7 insertions, 7 deletions
diff --git a/wireguard-go-rs/libwg/osv-scanner.toml b/wireguard-go-rs/libwg/osv-scanner.toml index c6fd4f3e2e..de8ad2ac5d 100644 --- a/wireguard-go-rs/libwg/osv-scanner.toml +++ b/wireguard-go-rs/libwg/osv-scanner.toml @@ -2,41 +2,41 @@ # Stack exhaustion in Decoder.Decode in encoding/gob [[IgnoredVulns]] id = "CVE-2024-34156" # GO-2024-3106 -ignoreUntil = 2025-03-18 +ignoreUntil = 2025-06-12 reason = "wireguard-go does not use the affected code" # Stack exhaustion in Parse in go/build/constraint [[IgnoredVulns]] id = "CVE-2024-34158" # GO-2024-3107 -ignoreUntil = 2025-03-18 +ignoreUntil = 2025-06-12 reason = "wireguard-go does not use the affected code" # Stack exhaustion in all Parse functions in go/parser [[IgnoredVulns]] id = "CVE-2024-34155" # GO-2024-3105 -ignoreUntil = 2025-03-18 +ignoreUntil = 2025-06-12 reason = "wireguard-go does not use the affected code" # Denial of service in HTML Parse function in go/net/html [[IgnoredVulns]] id = "CVE-2024-45338" # GO-2024-3333 -ignoreUntil = 2025-03-19 +ignoreUntil = 2025-06-12 reason = "wireguard-go does not use the affected code" # Denial of service in HTML Parse function in go/net/html [[IgnoredVulns]] id = "GHSA-w32m-9786-jp63" # GO-2024-3333 -ignoreUntil = 2025-03-19 +ignoreUntil = 2025-06-12 reason = "wireguard-go does not use the affected code" # Sensitive headers incorrectly sent after cross-domain redirect in net/http [[IgnoredVulns]] id = "CVE-2024-45336" # GO-2025-3420 -ignoreUntil = 2025-04-28 +ignoreUntil = 2025-06-12 reason = "wireguard-go does not use the affected code" # Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509 [[IgnoredVulns]] id = "CVE-2024-45341" # GO-2025-3373 -ignoreUntil = 2025-04-28 +ignoreUntil = 2025-06-12 reason = "wireguard-go does not use the affected code" |
