Skip to content

Commit fde9a9f

Browse files
authored
security: fix CVE-2023-48795 (#382)
1 parent 6d81420 commit fde9a9f

File tree

2 files changed

+64
-12
lines changed

2 files changed

+64
-12
lines changed

auth_server/go.mod

Lines changed: 57 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
module github.com/cesanta/docker_auth/auth_server
22

3-
go 1.16
3+
go 1.17
44

55
require (
66
cloud.google.com/go/storage v1.29.0
@@ -14,24 +14,72 @@ require (
1414
github.com/go-ldap/ldap v3.0.3+incompatible
1515
github.com/go-redis/redis v6.15.9+incompatible
1616
github.com/go-sql-driver/mysql v1.6.0
17-
github.com/gorilla/mux v1.8.0 // indirect
18-
github.com/klauspost/compress v1.15.11 // indirect
1917
github.com/lib/pq v1.10.7
2018
github.com/mattn/go-sqlite3 v2.0.3+incompatible
21-
github.com/montanaflynn/stats v0.6.6 // indirect
2219
github.com/schwarmco/go-cartesian-product v0.0.0-20180515110546-d5ee747a6dc9
23-
github.com/sirupsen/logrus v1.9.0 // indirect
2420
github.com/syndtr/goleveldb v1.0.0
25-
github.com/youmark/pkcs8 v0.0.0-20201027041543-1326539a0a0a // indirect
2621
go.mongodb.org/mongo-driver v1.10.2
27-
golang.org/x/crypto v0.14.0
22+
golang.org/x/crypto v0.17.0
2823
golang.org/x/net v0.17.0
2924
golang.org/x/oauth2 v0.13.0
3025
google.golang.org/api v0.126.0
31-
gopkg.in/asn1-ber.v1 v1.0.0-20181015200546-f715ec2f112d // indirect
3226
gopkg.in/fsnotify.v1 v1.4.7
3327
gopkg.in/mgo.v2 v2.0.0-20190816093944-a6b53ec6cb22
3428
gopkg.in/yaml.v2 v2.4.0
35-
xorm.io/builder v0.3.12 // indirect
3629
xorm.io/xorm v1.3.2
3730
)
31+
32+
require (
33+
cloud.google.com/go v0.110.2 // indirect
34+
cloud.google.com/go/compute v1.20.1 // indirect
35+
cloud.google.com/go/compute/metadata v0.2.3 // indirect
36+
cloud.google.com/go/iam v0.13.0 // indirect
37+
github.com/Knetic/govaluate v3.0.1-0.20171022003610-9aa49832a739+incompatible // indirect
38+
github.com/go-jose/go-jose/v3 v3.0.1 // indirect
39+
github.com/goccy/go-json v0.9.11 // indirect
40+
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
41+
github.com/golang/mock v1.6.0 // indirect
42+
github.com/golang/protobuf v1.5.3 // indirect
43+
github.com/golang/snappy v0.0.4 // indirect
44+
github.com/google/go-cmp v0.5.9 // indirect
45+
github.com/google/s2a-go v0.1.4 // indirect
46+
github.com/google/uuid v1.3.0 // indirect
47+
github.com/googleapis/enterprise-certificate-proxy v0.2.3 // indirect
48+
github.com/googleapis/gax-go/v2 v2.11.0 // indirect
49+
github.com/gorilla/mux v1.8.0 // indirect
50+
github.com/json-iterator/go v1.1.12 // indirect
51+
github.com/klauspost/compress v1.15.11 // indirect
52+
github.com/kr/pretty v0.3.0 // indirect
53+
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
54+
github.com/modern-go/reflect2 v1.0.2 // indirect
55+
github.com/montanaflynn/stats v0.6.6 // indirect
56+
github.com/pkg/errors v0.9.1 // indirect
57+
github.com/rogpeppe/go-internal v1.9.0 // indirect
58+
github.com/sirupsen/logrus v1.9.0 // indirect
59+
github.com/xdg-go/pbkdf2 v1.0.0 // indirect
60+
github.com/xdg-go/scram v1.1.1 // indirect
61+
github.com/xdg-go/stringprep v1.0.3 // indirect
62+
github.com/youmark/pkcs8 v0.0.0-20201027041543-1326539a0a0a // indirect
63+
go.opencensus.io v0.24.0 // indirect
64+
golang.org/x/sync v0.2.0 // indirect
65+
golang.org/x/sys v0.15.0 // indirect
66+
golang.org/x/text v0.14.0 // indirect
67+
golang.org/x/tools v0.7.0 // indirect
68+
golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2 // indirect
69+
google.golang.org/appengine v1.6.8 // indirect
70+
google.golang.org/genproto v0.0.0-20230530153820-e85fd2cbaebc // indirect
71+
google.golang.org/genproto/googleapis/api v0.0.0-20230530153820-e85fd2cbaebc // indirect
72+
google.golang.org/genproto/googleapis/rpc v0.0.0-20230530153820-e85fd2cbaebc // indirect
73+
google.golang.org/grpc v1.55.0 // indirect
74+
google.golang.org/protobuf v1.31.0 // indirect
75+
gopkg.in/asn1-ber.v1 v1.0.0-20181015200546-f715ec2f112d // indirect
76+
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c // indirect
77+
lukechampine.com/uint128 v1.2.0 // indirect
78+
modernc.org/cc/v3 v3.36.3 // indirect
79+
modernc.org/ccgo/v3 v3.16.9 // indirect
80+
modernc.org/libc v1.17.1 // indirect
81+
modernc.org/opt v0.1.3 // indirect
82+
modernc.org/sqlite v1.18.1 // indirect
83+
modernc.org/strutil v1.1.3 // indirect
84+
xorm.io/builder v0.3.12 // indirect
85+
)

auth_server/go.sum

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1267,8 +1267,9 @@ golang.org/x/crypto v0.0.0-20220622213112-05595931fe9d/go.mod h1:IxCIyHEi3zRg3s0
12671267
golang.org/x/crypto v0.1.0/go.mod h1:RecgLatLF4+eUMCP1PoPZQb+cVrJcOPbHkTkbkB9sbw=
12681268
golang.org/x/crypto v0.7.0/go.mod h1:pYwdfH91IfpZVANVyUOhSIPZaFoJGxTFbZhFTx+dXZU=
12691269
golang.org/x/crypto v0.9.0/go.mod h1:yrmDGqONDYtNj3tH8X9dzUun2m2lzPa9ngI6/RUPGR0=
1270-
golang.org/x/crypto v0.14.0 h1:wBqGXzWJW6m1XrIKlAH0Hs1JJ7+9KBwnIO8v66Q9cHc=
12711270
golang.org/x/crypto v0.14.0/go.mod h1:MVFd36DqK4CsrnJYDkBA3VC4m2GkXAM0PvzMCn4JQf4=
1271+
golang.org/x/crypto v0.17.0 h1:r8bRNjWL3GshPW3gkd+RpvzWrZAwPS49OmTGZ/uhM4k=
1272+
golang.org/x/crypto v0.17.0/go.mod h1:gCAAfMLgwOJRpTjQ2zCCt2OcSfYMTeZVSRtQlPC7Nq4=
12721273
golang.org/x/exp v0.0.0-20180321215751-8460e604b9de/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
12731274
golang.org/x/exp v0.0.0-20180807140117-3d87b88a115f/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
12741275
golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
@@ -1544,8 +1545,9 @@ golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
15441545
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
15451546
golang.org/x/sys v0.7.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
15461547
golang.org/x/sys v0.8.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
1547-
golang.org/x/sys v0.13.0 h1:Af8nKPmuFypiUBjVoU9V20FiaFXOcuZI21p0ycVYYGE=
15481548
golang.org/x/sys v0.13.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
1549+
golang.org/x/sys v0.15.0 h1:h48lPFYpsTvQJZF4EKyI4aLHaev3CxivZmv7yZig9pc=
1550+
golang.org/x/sys v0.15.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
15491551
golang.org/x/term v0.0.0-20201117132131-f5c789dd3221/go.mod h1:Nr5EML6q2oocZ2LXRh80K7BxOlk5/8JxuGnuhpl+muw=
15501552
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
15511553
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
@@ -1558,6 +1560,7 @@ golang.org/x/term v0.6.0/go.mod h1:m6U89DPEgQRMq3DNkDClhWw02AUbt2daBVO4cn4Hv9U=
15581560
golang.org/x/term v0.7.0/go.mod h1:P32HKFT3hSsZrRxla30E9HqToFYAQPCMs/zFMBUFqPY=
15591561
golang.org/x/term v0.8.0/go.mod h1:xPskH00ivmX89bAKVGSKKtLOWNx2+17Eiy94tnKShWo=
15601562
golang.org/x/term v0.13.0/go.mod h1:LTmsnFJwVN6bCy1rVCoS+qHT1HhALEFxKncY3WNNh4U=
1563+
golang.org/x/term v0.15.0/go.mod h1:BDl952bC7+uMoWR75FIrCDx79TPU9oHkTZ9yRbYOrX0=
15611564
golang.org/x/text v0.0.0-20170915032832-14c0d48ead0c/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
15621565
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
15631566
golang.org/x/text v0.3.1-0.20180807135948-17ff2d5776d2/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
@@ -1574,8 +1577,9 @@ golang.org/x/text v0.6.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
15741577
golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
15751578
golang.org/x/text v0.8.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8=
15761579
golang.org/x/text v0.9.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8=
1577-
golang.org/x/text v0.13.0 h1:ablQoSUd0tRdKxZewP80B+BaqeKJuVhuRxj/dkrun3k=
15781580
golang.org/x/text v0.13.0/go.mod h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE=
1581+
golang.org/x/text v0.14.0 h1:ScX5w1eTa3QqT8oi6+ziP7dTV1S2+ALU0bI+0zXKWiQ=
1582+
golang.org/x/text v0.14.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU=
15791583
golang.org/x/time v0.0.0-20180412165947-fbb02b2291d2/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
15801584
golang.org/x/time v0.0.0-20181108054448-85acf8d2951c/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
15811585
golang.org/x/time v0.0.0-20190308202827-9d24e82272b4/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=

0 commit comments

Comments
 (0)