[GH-ISSUE #4706] 关于FRP-0.61.2版本当前依赖库存在的安全漏洞 #3716

Closed
opened 2026-05-05 14:23:03 -06:00 by gitea-mirror · 1 comment
Owner

Originally created by @YouZiFeiLe on GitHub (Mar 12, 2025).
Original GitHub issue: https://github.com/fatedier/frp/issues/4706

Bug Description

当前FRP-0.61.2版本多个依赖库存在安全漏洞

CVE-2024-45337
golang / golang.org/x/crypto / 0.30.0

CVE-2024-45338
golang / golang.org/x/net / 0.32.0

CVE-2025-22869
golang / golang.org/x/crypto / 0.30.0

CVE-2025-22868
golang / golang.org/x/oauth2 / 0.16.0

CVE-2025-27144
golang / github.com/go-jose/go-jose/v4 / 4.0.1

请对依赖库进行常规版本升级,谢谢

Image

frpc Version

0.61.2

frps Version

0.61.2

System Architecture

linux/amd64

Configurations

请对依赖库进行常规版本升级,谢谢

Logs

No response

Steps to reproduce

...

Affected area

  • Docs
  • Installation
  • Performance and Scalability
  • Security
  • User Experience
  • Test and Release
  • Developer Infrastructure
  • Client Plugin
  • Server Plugin
  • Extensions
  • Others
Originally created by @YouZiFeiLe on GitHub (Mar 12, 2025). Original GitHub issue: https://github.com/fatedier/frp/issues/4706 ### Bug Description 当前FRP-0.61.2版本多个依赖库存在安全漏洞 CVE-2024-45337 golang / golang.org/x/crypto / 0.30.0 CVE-2024-45338 golang / golang.org/x/net / 0.32.0 CVE-2025-22869 golang / golang.org/x/crypto / 0.30.0 CVE-2025-22868 golang / golang.org/x/oauth2 / 0.16.0 CVE-2025-27144 golang / github.com/go-jose/go-jose/v4 / 4.0.1 请对依赖库进行常规版本升级,谢谢 ![Image](https://github.com/user-attachments/assets/ec0443d5-b2bd-4ee3-9708-d953a06464c1) ### frpc Version 0.61.2 ### frps Version 0.61.2 ### System Architecture linux/amd64 ### Configurations 请对依赖库进行常规版本升级,谢谢 ### Logs _No response_ ### Steps to reproduce 1. 2. 3. ... ### Affected area - [ ] Docs - [ ] Installation - [ ] Performance and Scalability - [x] Security - [ ] User Experience - [ ] Test and Release - [ ] Developer Infrastructure - [ ] Client Plugin - [ ] Server Plugin - [ ] Extensions - [ ] Others
gitea-mirror 2026-05-05 14:23:03 -06:00
Author
Owner

@github-actions[bot] commented on GitHub (Mar 27, 2025):

Issues go stale after 14d of inactivity. Stale issues rot after an additional 3d of inactivity and eventually close.

<!-- gh-comment-id:2756068642 --> @github-actions[bot] commented on GitHub (Mar 27, 2025): Issues go stale after 14d of inactivity. Stale issues rot after an additional 3d of inactivity and eventually close.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/frp#3716
No description provided.