github.com/ydb-platform/ydb-go-sdk/v3 is vulnerable to NULL Pointer Dereference
16
Low Risk
Affected versions of this package are vulnerable to an explicit null-dereference in the internal/credentials/static.go::parseExpiresAt function. This flaw can lead to crashes, potentially causing a Denial of Service (DoS). Proper handling of null values is necessary to prevent such issues, as it could result in system instability or unresponsiveness when exploited.
You are affected if you are using a version that falls within the vulnerable range.
github.com/ydb-platform/ydb-go-sdk/v3 is vulnerable to NULL Pointer Dereference in versions 3.34.0 - 3.99.1.
Upgrade the github.com/ydb-platform/ydb-go-sdk/v3 library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant