security: CVE-2023-49569 - go-git/v5 #3272
cmontemuino
started this conversation in
General
Replies: 2 comments 2 replies
-
|
Thanks for mentioning it, @cmontemuino. 👍 |
Beta Was this translation helpful? Give feedback.
1 reply
-
|
Hey, seems like the issue on go is already closed, pull request is merged. Can You guys release new version with this package fixed? Best Regards :) @cmontemuino @nabokihms |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
We've observed (Trivy scan) ghcr.io/dexidp/dex:v2.37.0 includes critical vulnerability CVE-2023-4956 in package
github.com/go-git/go-git/v5.The vulnerability does not come from dex binary, but
gotemplate. I've filed an issue in their repo and proposed a fix: hairyhenderson/gomplate#1960When it's accepted and released, then a new version of
dexidp/dexmight be created.Note: it makes all images that depend on dexidp/dex contain that critical vulnerability.
Beta Was this translation helpful? Give feedback.
All reactions