github.com/elastic/elastic-agent-libs/transport is vulnerable to Use of Weak Hash
25
Low Risk
Affected versions of this package are affected by weak encryption caused by the absence of a Subject Key Identifier (SKI) in Go. As demonstrated in RFC 5280, when the SKI is missing, its generation depends on SHA-1, a deprecated algorithm due to its susceptibility to collision attacks.
You are affected if you are using a version that falls within the vulnerable range.
github.com/elastic/elastic-agent-libs/transport is vulnerable to Use of Weak Hash in versions 0.2.4 - 0.17.5.
Upgrade the github.com/elastic/elastic-agent-libs/transport library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant