Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Golang vulnerabilities in v0.13.1 #324

Closed
FabienLfy opened this issue Feb 22, 2023 · 7 comments
Closed

Golang vulnerabilities in v0.13.1 #324

FabienLfy opened this issue Feb 22, 2023 · 7 comments

Comments

@FabienLfy
Copy link

Envconsul version

envconsul v0.13.1

CVE Vulnerabilities

Here is a list of Golang vulnerabilities that can be fixed by doing a version upgrade of the package:

@Woolleysi
Copy link

In addition, Trivy scanner identifies vulnerabilities in:

golang.org/x/net

golang.org/x/text

Thanks

@marrws
Copy link

marrws commented Nov 13, 2023

In addition, Trivy scanner identifies vulnerabilities in:

golang.org/x/net

This has been addressed by the bot in #344 and #347

golang.org/x/text
* CVE-2022-32149
Thanks

This one should be solved by 2794ee0

@marrws
Copy link

marrws commented Nov 27, 2023

@hc-github-team-es-release-engineering Since #344 and #347 have been merged. Can we get a new release of envcosul with these fixes?

@zffocussss
Copy link

I agree with @marrws ,we need a new release including the security fixes

@marrws
Copy link

marrws commented Jun 10, 2024

We got v0.13.2 on may 22
Sorry, misread the release

@marrws
Copy link

marrws commented Jun 10, 2024

@armon @catsby @ryanuber @hc-github-team-es-release-engineering I'm really sorry for the ping but this is important.

Can we get a new release so the vulnerabilities don't keep piling up?

@dduzgun-security
Copy link

dduzgun-security commented Dec 20, 2024

Thanks for reporting. Closing duplicated issue to centralize conversation/updates in this issue #362 and this PR #366. A fix should be available on the next release.

For future reporting of vulnerabilities, we recommend reaching to the [email protected] email to have faster replies as described in our guide https://www.hashicorp.com/trust/security/vulnerability-management.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants