{"id":"GO-2023-2134","summary":"Artifact Hub allows unsafe rego built-in in github.com/artifacthub/hub","details":"Artifact Hub allows unsafe rego built-in in github.com/artifacthub/hub","aliases":["CVE-2023-45822","GHSA-9pc8-m4vp-ggvf"],"modified":"2026-03-03T04:54:18.923222Z","published":"2024-08-21T14:30:22Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2023-2134","review_status":"UNREVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/artifacthub/hub/security/advisories/GHSA-9pc8-m4vp-ggvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45822"},{"type":"WEB","url":"https://artifacthub.io/packages/helm/artifact-hub/artifact-hub?modal=changelog&version=1.16.0"},{"type":"WEB","url":"https://www.openpolicyagent.org"},{"type":"WEB","url":"https://www.openpolicyagent.org/docs/latest/#rego"}],"affected":[{"package":{"name":"github.com/artifacthub/hub","ecosystem":"Go","purl":"pkg:golang/github.com/artifacthub/hub"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.16.0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-2134.json"}}],"schema_version":"1.7.3"}