This repository was archived by the owner on Jan 7, 2026. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 89
Expand file tree
/
Copy pathblobfuse2.advisories.yaml
More file actions
138 lines (131 loc) · 3.7 KB
/
Copy pathblobfuse2.advisories.yaml
File metadata and controls
138 lines (131 loc) · 3.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
schema-version: 2.0.2
package:
name: blobfuse2
advisories:
- id: CGA-263v-mx64-hp4r
aliases:
- CVE-2025-47914
- GHSA-f6x5-jh6r-wrfv
events:
- timestamp: 2025-11-21T09:24:08Z
type: detection
data:
type: scan/v1
data:
subpackageName: blobfuse2
componentID: 2eeb023273dc4995
componentName: golang.org/x/crypto
componentVersion: v0.36.0
componentType: go-module
componentLocation: /usr/bin/blobfuse2
scanner: grype
- timestamp: 2025-11-21T11:46:34Z
type: fixed
data:
fixed-version: 2.4.2-r6
- id: CGA-g7c4-wv7m-46r4
aliases:
- CVE-2025-58181
- GHSA-j5w8-q4qc-rx2x
events:
- timestamp: 2025-11-21T09:24:09Z
type: detection
data:
type: scan/v1
data:
subpackageName: blobfuse2
componentID: 2eeb023273dc4995
componentName: golang.org/x/crypto
componentVersion: v0.36.0
componentType: go-module
componentLocation: /usr/bin/blobfuse2
scanner: grype
- timestamp: 2025-11-21T11:46:36Z
type: fixed
data:
fixed-version: 2.4.2-r6
- id: CGA-gjc9-8674-5xpx
aliases:
- CVE-2025-4673
- GHSA-62jj-gr2r-5c34
events:
- timestamp: 2025-06-14T07:32:09Z
type: detection
data:
type: scan/v1
data:
subpackageName: blobfuse2
componentID: cba644ff3e1b8fa0
componentName: stdlib
componentVersion: go1.24.2
componentType: go-module
componentLocation: /usr/bin/bfusemon
scanner: grype
- timestamp: 2025-06-14T09:37:58Z
type: fixed
data:
fixed-version: 2.4.2-r2
- id: CGA-pjgr-qxqv-5rwq
aliases:
- CVE-2025-47906
- GHSA-gwrf-jf3h-w649
events:
- timestamp: 2025-09-20T08:40:08Z
type: detection
data:
type: scan/v1
data:
subpackageName: blobfuse2
componentID: 31a8bf6fe10f9cac
componentName: stdlib
componentVersion: go1.24.5
componentType: go-module
componentLocation: /usr/bin/bfusemon
scanner: grype
- timestamp: 2025-09-21T07:09:03Z
type: fixed
data:
fixed-version: 2.4.2-r4
- id: CGA-v25j-8xhx-pxwr
aliases:
- CVE-2025-47907
- GHSA-j5pm-7495-qmr3
events:
- timestamp: 2025-08-10T11:47:15Z
type: detection
data:
type: scan/v1
data:
subpackageName: blobfuse2
componentID: 31a8bf6fe10f9cac
componentName: stdlib
componentVersion: go1.24.5
componentType: go-module
componentLocation: /usr/bin/bfusemon
scanner: grype
- timestamp: 2025-08-11T07:08:29Z
type: false-positive-determination
data:
type: vulnerable-code-not-included-in-package
note: Govulncheck found no affected symbols in the scanned Go binaries.
- id: CGA-x66h-xr9x-x2xc
aliases:
- CVE-2025-22874
- GHSA-6f52-wpx2-hvf2
events:
- timestamp: 2025-06-14T07:32:08Z
type: detection
data:
type: scan/v1
data:
subpackageName: blobfuse2
componentID: cba644ff3e1b8fa0
componentName: stdlib
componentVersion: go1.24.2
componentType: go-module
componentLocation: /usr/bin/bfusemon
scanner: grype
- timestamp: 2025-06-14T09:37:58Z
type: fixed
data:
fixed-version: 2.4.2-r2