Vulnerability Report: GO-2022-0316
- CVE-2022-23628, GHSA-hcw3-j74m-qc58
- Affects: github.com/open-policy-agent/opa
- Published: Jul 27, 2022
- Modified: May 20, 2024
Pretty-printing an AST that contains synthetic nodes can change the logic of some statements by reordering array literals.
For detailed information about this vulnerability, visit https://github.com/open-policy-agent/opa/security/advisories/GHSA-hcw3-j74m-qc58.
Affected Packages
-
PathGo VersionsSymbols
-
from v0.33.1 before v0.37.2
Aliases
References
- https://github.com/open-policy-agent/opa/security/advisories/GHSA-hcw3-j74m-qc58
- https://github.com/open-policy-agent/opa/commit/932e4ffc37a590ace79e9b75ca4340288c220239
- https://github.com/open-policy-agent/opa/commit/2bd8edab9e10e2dc9cf76ae8335ced0c224f3055
- https://vuln.go.dev/ID/GO-2022-0316.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.