From 4cda3a1ab8c7e5a78c3d9425d3411f0d8b451fb6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 17 Apr 2025 14:32:27 +0000 Subject: [PATCH] Publish GHSA-x5m7-63c6-fx79 --- .../2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json b/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json index 709d2e9522d..2471b69b88e 100644 --- a/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json +++ b/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-x5m7-63c6-fx79", - "modified": "2024-05-17T00:31:00Z", + "modified": "2025-04-17T14:30:39Z", "published": "2024-04-25T18:30:39Z", + "withdrawn": "2025-04-17T14:30:39Z", "aliases": [ "CVE-2024-1139" ], - "summary": "Cluster Monitoring Operator contains a credentials leak", - "details": "A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.", + "summary": "Withdrawn Advisory: Cluster Monitoring Operator contains a credentials leak", + "details": "# Withdrawn Advisory\nThis advisory has been withdrawn because the vulnerability does not affect a package in the Go registry. For more information, see the discussion [here](https://github.com/github/advisory-database/pull/5467#issuecomment-2812187822). This link is maintained to preserve external references.\n\n# Original Description\n\nA credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.", "severity": [ { "type": "CVSS_V3",