Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 37: FEDORA-2023-1b25579262 Critical: Kingpin Authentication Bypass

fedora
Calendar Grey September 21, 2023
Dist Fedora Esm H88
Patch release for golang-gopkg-alecthomas-kingpin-2 in Fedora mitigating CVE-2022-46146 through an upgrade to version v0.10.0.
Security fix for CVE-2022-46146, update to v0.10.0

Summary

Kingpin is a fluent-style, type-safe command-line parser. It supports flags,

nested commands, and positional arguments.

Update Information:

Security fix for CVE-2022-46146, update to v0.10.0

Change Log

* Thu Jan 19 2023 Fedora Release Engineering - 2.2.6-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild

References


[ 1 ] Bug #2149436 - CVE-2022-46146 exporter-toolkit: authentication bypass via cache poisoning https://bugzilla.redhat.com/show_bug.cgi?id=2149436

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1b25579262' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: golang-gopkg-alecthomas-kingpin-2
Product: Fedora 37
Version: 2.3.2
Release: 1.fc37
Summary: Go command line and flag parser

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here