wasm3: add many knownVulnerabilities

This commit is contained in:
Robert Scott 2022-09-25 18:02:35 +01:00
parent 2ff1d7bf8a
commit 25dbfa36fd

View file

@ -29,5 +29,18 @@ stdenv.mkDerivation rec {
platforms = platforms.all;
maintainers = with maintainers; [ malbarbo ];
license = licenses.mit;
knownVulnerabilities = [
# wasm3 expects all wasm code to be pre-validated, any users
# should be aware that running unvalidated wasm will potentially
# lead to RCE until upstream have added a builtin validator
"CVE-2022-39974"
"CVE-2022-34529"
"CVE-2022-28990"
"CVE-2022-28966"
"CVE-2021-45947"
"CVE-2021-45946"
"CVE-2021-45929"
"CVE-2021-38592"
];
};
}