Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

关于FRP-0.61.2版本当前依赖库存在的安全漏洞 #4706

Open
1 of 11 tasks
YouZiFeiLe opened this issue Mar 12, 2025 · 1 comment
Open
1 of 11 tasks

关于FRP-0.61.2版本当前依赖库存在的安全漏洞 #4706

YouZiFeiLe opened this issue Mar 12, 2025 · 1 comment

Comments

@YouZiFeiLe
Copy link

Bug Description

当前FRP-0.61.2版本多个依赖库存在安全漏洞

CVE-2024-45337
golang / golang.org/x/crypto / 0.30.0

CVE-2024-45338
golang / golang.org/x/net / 0.32.0

CVE-2025-22869
golang / golang.org/x/crypto / 0.30.0

CVE-2025-22868
golang / golang.org/x/oauth2 / 0.16.0

CVE-2025-27144
golang / github.com/go-jose/go-jose/v4 / 4.0.1

请对依赖库进行常规版本升级,谢谢

Image

frpc Version

0.61.2

frps Version

0.61.2

System Architecture

linux/amd64

Configurations

请对依赖库进行常规版本升级,谢谢

Logs

No response

Steps to reproduce

...

Affected area

  • Docs
  • Installation
  • Performance and Scalability
  • Security
  • User Experience
  • Test and Release
  • Developer Infrastructure
  • Client Plugin
  • Server Plugin
  • Extensions
  • Others
Copy link

Issues go stale after 14d of inactivity. Stale issues rot after an additional 3d of inactivity and eventually close.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant