Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix Critical CVE #161

Merged
merged 3 commits into from
Jul 24, 2024
Merged

Fix Critical CVE #161

merged 3 commits into from
Jul 24, 2024

Conversation

yash-acquia
Copy link
Contributor

@yash-acquia yash-acquia commented Jul 23, 2024

What happened?
An orca scan detected the CVE-2024-24790

What are we trying to fix?
Update the go version from 1.20.4 to 1.22.5

Vulnerability_id Package Name Vulnerable Version Patch Version Type Severity
CVE-2024-24790 stdlib 1.20.4 1.21.11, 1.22.4 gobinary CRITICAL

Environment

  • Kubernetes version: v1.28.9-eks
  • CSI driver image and version: docker.io/warmmetal/csi-image v1.2.3

@yash-acquia yash-acquia requested a review from a team as a code owner July 23, 2024 08:31
@mugdha-adhav mugdha-adhav merged commit 6b10664 into warm-metal:main Jul 24, 2024
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants