Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-6r78-m64m-qwcf: Moq v4.20.0 and 4.20.1 share hashed user data

Moq v4.20.0 and 4.20.1 include support for SponsorLink, which runs an obfuscated DLL at build time that scans local git config data and shares the user’s hashed email address with SponsorLink’s remote servers. There is no option to disable this.

Moq v4.20.2 has removed this functionality.

ghsa
#git

Moq v4.20.0 and 4.20.1 share hashed user data

Low severity GitHub Reviewed Published Aug 10, 2023 to the GitHub Advisory Database • Updated Aug 10, 2023

ghsa: Latest News

GHSA-7p9f-6x8j-gxxp: CRI-O: Maliciously structured checkpoint file can gain arbitrary node access