Fixed
Pinned fields
Click on the next to a field label to start pinning.
Details
Assignee
The OneThe OneReporter
Ian McCloyIan McCloy(Deactivated)Labels
CVE ID
CVE-2020-14040CVSS/Severity
HighComponents
Fix versions
Affects versions
Priority
MajorInstabug
Open Instabug
Details
Details
Assignee
The One
The OneReporter
Ian McCloy
Ian McCloy(Deactivated)Labels
CVE ID
CVE-2020-14040
CVSS/Severity
High
Components
Fix versions
Affects versions
Priority
Instabug
Open Instabug
PagerDuty
PagerDuty
PagerDuty
Sentry
Sentry
Sentry
Zendesk Support
Zendesk Support
Zendesk Support
Created May 6, 2022 at 1:24 PM
Updated August 31, 2024 at 10:58 AM
Resolved April 13, 2023 at 11:01 PM
SyncGateway 2.8.x has a High Severity vulnerability in the golang.org/x/text library.
HIGH:https://nvd.nist.gov/vuln/detail/CVE-2020-14040
@Ben Brooks - confirmed via slack that SGW 2.8.3 is using a version that's between
v0.3.0
andv0.3.1
(which will be affected by the CVE)https://github.com/couchbase/sync_gateway/blob/40f04c91d21a4d82db4927b6fc18bacd0862c0b9/manifest/2.8.xml#L78