Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-24790 #367

Closed
ZelphirKaltstahl opened this issue Aug 18, 2024 · 6 comments
Closed

CVE-2024-24790 #367

ZelphirKaltstahl opened this issue Aug 18, 2024 · 6 comments

Comments

@ZelphirKaltstahl
Copy link

The current latest official (according to https://hub.docker.com/_/caddy/tags) docker image is affected by CVE-2024-24790 (for example https://security-tracker.debian.org/tracker/CVE-2024-24790 or https://nvd.nist.gov/vuln/detail/CVE-2024-24790).

Are there any plans to upgrade to a newer version of go? If I understand correctly, 1.21.13-1 should have it fixed.

@jdvorak001
Copy link

... or 1.22.4+ or 1.23.

@mholt
Copy link
Member

mholt commented Aug 19, 2024

As noted elsewhere this does not really affect Caddy, but a new image with Go 1.23 is probably a good idea.

@mholt mholt transferred this issue from caddyserver/caddy Aug 19, 2024
@francislavoie
Copy link
Member

No point to keep this open, it's a duplicate.

@ZelphirKaltstahl
Copy link
Author

ZelphirKaltstahl commented Aug 19, 2024

Can you link at least to that "elsewhere", so that people searching for this CVE can find that documentation as well? I think that would be helpful.

Edit: Nvm, I found it: #361

@mholt
Copy link
Member

mholt commented Aug 19, 2024

(It's already linked above ☝️ )

@itaysk
Copy link

itaysk commented Sep 1, 2024

As noted elsewhere this does not really affect Caddy

@mholt
Hello from team Trivy :) Just chiming in to say that Trivy now allows software maintainers (you) to publish vulnerability analysis about your software (packages, libraries, container images) so that vulnerability scanners will automatically suppress those irrelevant vulnerabilities for end users. You can read more here:
https://aquasecurity.github.io/trivy/latest/docs/supply-chain/vex/repo/#publishing-vex-documents
https://github.com/aquasecurity/vexhub
Feel free to reach me or the Trivy team if you have any issues/feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants