Status
Impact
There are two separately named releases for 'go-tuf'. This application currently depends on both, 'go-tuf', and 'go-tuf/v2'. go-tuf does not contain a fix for this vulnerability, and looks depreciated in favor of 'go-tuf/v2'. Pending fix from upstream, which will involve removing their dependency on the depreciated version. Related information: https://github.com/github/advisory-database/pull/4893.
Status
Status
Fixed version
2.4.0-r5Status