​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-fxp3-36mf-h753

Published

Last updated

https://images.chainguard.dev/security/CGA-fxp3-36mf-h753
Package

kube-state-metrics-2.6

Latest Update
Fixed
Fixed Version

2.6.0-r1

Aliases
  • CVE-2022-27664
  • GHSA-69cg-p879-7622

Severity

7.5

High

CVSS V3

Summary

golang.org/x/net/http2 Denial of Service vulnerability

Description

In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images