Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/crossplane/crossplane
  4. ›
  5. GHSA-7h65-4p22-39j6

GHSA-7h65-4p22-39j6: github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

October 25, 2024

A critical vulnerability was reported in the versions of golang that Crossplane depends on. Details of the golang vulnerability are included below. Crossplane does not directly use the vulnerable functions from the net/netip package, but the version of golang libraries, runtime, and build tools have still been updated as part of this security advisory nonetheless.

Critical Vulnerabilities Vulnerability: CVE-2024-24790, golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses Description: The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

Affected versions: 1.17.1,1.16.2,1.15.5

See screenshot for more details

Click to open external image

Fixed versions: 1.17.2,1.16.3,1.15.6

Release notes:

  • https://github.com/crossplane/crossplane/releases/tag/v1.17.2
  • https://github.com/crossplane/crossplane/releases/tag/v1.16.3
  • https://github.com/crossplane/crossplane/releases/tag/v1.15.6

References

  • github.com/advisories/GHSA-7h65-4p22-39j6
  • github.com/crossplane/crossplane
  • github.com/crossplane/crossplane/security/advisories/GHSA-7h65-4p22-39j6

Code Behaviors & Features

Detect and mitigate GHSA-7h65-4p22-39j6 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.15.5 before 1.15.6, version 1.15.5, all versions starting from 1.16.2 before 1.16.3, version 1.16.2, all versions starting from 1.17.1 before 1.17.2, version 1.17.1

Fixed versions

  • 1.15.6
  • 1.16.3
  • 1.17.2

Solution

Upgrade to versions 1.15.6, 1.16.3, 1.17.2 or above.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Source file

go/github.com/crossplane/crossplane/GHSA-7h65-4p22-39j6.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:15 +0000.