go package report

Is github.com/deis/workflow-manager safe?

1 known vulnerability, worst severity MEDIUM.

cvss
4.6

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-jpfp-xq3p-4h3r, the advisory selected below

// advisories

GHSA-jpfp-xq3p-4h3r

MEDIUMCVE-2016-15036

UNSUPPORTED WHEN ASSIGNED A vulnerability was found in Deis Workflow Manager up to 2.3.2. It has been classified as problematic. This affects an unknown part. The manipulation leads to race condition. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 2.3.3 is able to address this issue. The patch is named 31fe3bccbdde134a185752e53380330d

Affected
>=0, <2.3.3+incompatible
Fixed in
2.3.3
Weakness
CWE-362
Published
2023-12-23
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


Checked 2026-09-22 at 01:38 UTC. The most recent advisory here was published 2023-12-23. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is github.com/deis/workflow-manager safe? go package security report | CyberXYZ