github.com/opencost/opencost is vulnerable to Inadequate Encryption Strength
30
Low Risk
Affected versions of this package allow the use of insecure TLS 1.0 and TLS 1.1 protocols, exposing communications to man-in-the-middle attacks. This vulnerability compromises the confidentiality and integrity of data by enabling attackers to intercept and manipulate the data being transmitted.
You are affected if you are using a version that falls within the vulnerable range and your configurations allow for TLS 1.0 or TLS 1.1.
github.com/opencost/opencost is vulnerable to Inadequate Encryption Strength in versions 0.0.1 - 1.118.0.
Upgrade the github.com/opencost/opencost library to the patch version or strengthen TLS configuration to use TLS 1.2 or higher.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant