github.com/openziti/sdk-golang is vulnerable to Race Condition
20
Low Risk
Affected versions of this package have a vulnerability that can lead to a runtime panic due to unsafe concurrent access to the SupportedProtocols map in the Ziti Go SDK. When multiple goroutines call getEdgeRouterConn() simultaneously, it may cause a fatal runtime error. An attacker could exploit this by sending numerous concurrent requests, resulting in a denial of service (DoS) by crashing the application.
You are affected if you are using a version that falls within the vulnerable range.
github.com/openziti/sdk-golang is vulnerable to Race Condition in versions 0.11.6 - 1.0.1.
Upgrade the github.com/openziti/sdk-golang library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant