mirror of
https://github.com/etcd-io/etcd.git
synced 2024-09-27 06:25:44 +00:00
Found 1 known vulnerability. Vulnerability #1: GO-2022-1144 An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection. Call stacks in your code: Error: tools/etcd-dump-metrics/main.go:158:5: go.etcd.io/etcd/v3/tools/etcd-dump-metrics.main calls go.etcd.io/etcd/server/v3/embed.StartEtcd, which eventually calls golang.org/x/net/http2.Server.ServeConn Found in: golang.org/x/net/http2@v0.2.0 Fixed in: golang.org/x/net/http2@v0.4.0 More info: https://pkg.go.dev/vuln/GO-2022-1144 Error: Process completed with exit code 3. Signed-off-by: Benjamin Wang <wachao@vmware.com>
91 lines
4.2 KiB
Modula-2
91 lines
4.2 KiB
Modula-2
module go.etcd.io/etcd/tools/v3
|
|
|
|
go 1.19
|
|
|
|
require (
|
|
github.com/alexkohler/nakedret v1.0.0
|
|
github.com/chzchzchz/goword v0.0.0-20170907005317-a9744cb52b03
|
|
github.com/coreos/license-bill-of-materials v0.0.0-20190913234955-13baff47494e
|
|
github.com/gogo/protobuf v1.3.2
|
|
github.com/google/addlicense v1.0.0
|
|
github.com/gordonklaus/ineffassign v0.0.0-20210914165742-4cc7213b9bc8
|
|
github.com/grpc-ecosystem/grpc-gateway v1.16.0
|
|
github.com/gyuho/gocovmerge v0.0.0-20171205171859-50c7e6afd535
|
|
github.com/hexfusion/schwag v0.0.0-20211117114134-3ceb0191ccbf
|
|
github.com/mdempsky/unconvert v0.0.0-20200228143138-95ecdbfc0b5f
|
|
github.com/mgechev/revive v1.2.1
|
|
github.com/mikefarah/yq/v4 v4.24.2
|
|
go.etcd.io/gofail v0.0.0-20221125214112-fc21f61ba88a
|
|
go.etcd.io/protodoc v0.0.0-20180829002748-484ab544e116
|
|
go.etcd.io/raft/v3 v3.0.0-20221201111702-eaa6808e1f7a
|
|
gotest.tools/gotestsum v1.7.0
|
|
gotest.tools/v3 v3.1.0
|
|
honnef.co/go/tools v0.3.0
|
|
mvdan.cc/unparam v0.0.0-20220316160445-06cc5682983b
|
|
)
|
|
|
|
require (
|
|
github.com/BurntSushi/toml v1.1.0 // indirect
|
|
github.com/PuerkitoBio/purell v1.1.1 // indirect
|
|
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect
|
|
github.com/a8m/envsubst v1.3.0 // indirect
|
|
github.com/akhenakh/hunspellgo v0.0.0-20160221122622-9db38fa26e19 // indirect
|
|
github.com/asaskevich/govalidator v0.0.0-20200907205600-7a23bdc65eef // indirect
|
|
github.com/bmatcuk/doublestar/v4 v4.0.2 // indirect
|
|
github.com/chavacava/garif v0.0.0-20220316182200-5cad0b5181d4 // indirect
|
|
github.com/dnephin/pflag v1.0.7 // indirect
|
|
github.com/elliotchance/orderedmap v1.4.0 // indirect
|
|
github.com/fatih/color v1.13.0 // indirect
|
|
github.com/fatih/structtag v1.2.0 // indirect
|
|
github.com/fsnotify/fsnotify v1.4.9 // indirect
|
|
github.com/ghodss/yaml v1.0.0 // indirect
|
|
github.com/go-openapi/analysis v0.21.2 // indirect
|
|
github.com/go-openapi/errors v0.19.9 // indirect
|
|
github.com/go-openapi/jsonpointer v0.19.5 // indirect
|
|
github.com/go-openapi/jsonreference v0.19.6 // indirect
|
|
github.com/go-openapi/loads v0.21.1 // indirect
|
|
github.com/go-openapi/spec v0.20.4 // indirect
|
|
github.com/go-openapi/strfmt v0.21.0 // indirect
|
|
github.com/go-openapi/swag v0.19.15 // indirect
|
|
github.com/go-stack/stack v1.8.0 // indirect
|
|
github.com/goccy/go-yaml v1.9.5 // indirect
|
|
github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b // indirect
|
|
github.com/golang/protobuf v1.5.2 // indirect
|
|
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
|
|
github.com/inconshreveable/mousetrap v1.0.0 // indirect
|
|
github.com/jinzhu/copier v0.3.5 // indirect
|
|
github.com/jonboulle/clockwork v0.2.2 // indirect
|
|
github.com/josharian/intern v1.0.0 // indirect
|
|
github.com/magiconair/properties v1.8.6 // indirect
|
|
github.com/mailru/easyjson v0.7.6 // indirect
|
|
github.com/mattn/go-colorable v0.1.12 // indirect
|
|
github.com/mattn/go-isatty v0.0.14 // indirect
|
|
github.com/mattn/go-runewidth v0.0.9 // indirect
|
|
github.com/mgechev/dots v0.0.0-20210922191527-e955255bf517 // indirect
|
|
github.com/mitchellh/go-homedir v1.1.0 // indirect
|
|
github.com/mitchellh/mapstructure v1.4.1 // indirect
|
|
github.com/oklog/ulid v1.3.1 // indirect
|
|
github.com/olekukonko/tablewriter v0.0.5 // indirect
|
|
github.com/pkg/errors v0.9.1 // indirect
|
|
github.com/spf13/cobra v1.4.0 // indirect
|
|
github.com/spf13/pflag v1.0.5 // indirect
|
|
github.com/timtadh/data-structures v0.5.3 // indirect
|
|
github.com/timtadh/lexmachine v0.2.2 // indirect
|
|
github.com/trustmaster/go-aspell v0.0.0-20200701131845-c2b1f55bec8f // indirect
|
|
go.mongodb.org/mongo-driver v1.7.3 // indirect
|
|
golang.org/x/exp/typeparams v0.0.0-20220218215828-6cf2b201936e // indirect
|
|
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4 // indirect
|
|
golang.org/x/net v0.4.0 // indirect
|
|
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4 // indirect
|
|
golang.org/x/sys v0.3.0 // indirect
|
|
golang.org/x/term v0.3.0 // indirect
|
|
golang.org/x/text v0.5.0 // indirect
|
|
golang.org/x/tools v0.1.12 // indirect
|
|
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
|
|
google.golang.org/genproto v0.0.0-20200513103714-09dca8ec2884 // indirect
|
|
google.golang.org/protobuf v1.27.1 // indirect
|
|
gopkg.in/op/go-logging.v1 v1.0.0-20160211212156-b2cb9fa56473 // indirect
|
|
gopkg.in/yaml.v2 v2.4.0 // indirect
|
|
gopkg.in/yaml.v3 v3.0.1 // indirect
|
|
)
|