Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pinned vulnerable version of crypto library #2078

Closed
aebrahim opened this issue Dec 21, 2023 · 3 comments
Closed

Pinned vulnerable version of crypto library #2078

aebrahim opened this issue Dec 21, 2023 · 3 comments
Assignees
Labels
type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns.

Comments

@aebrahim
Copy link

aebrahim commented Dec 21, 2023

Bug Description

This pins golang.org/x/crypto v0.16.0 which is vulnerable to GHSA-45x7-px36-x8w8 / CVE-2023-48795

Please merge #2077 to upgrade the dependency.

Example code (or command)

No response

Stacktrace

No response

Steps to reproduce?

grype gcr.io/cloud-sql-connectors/cloud-sql-proxy:latest

Environment

  1. Linux (focal on a Google Cloud Workstation)
  2. cloud-sql-proxy version 2.8.1+container

Additional Details

No response

@aebrahim aebrahim added the type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. label Dec 21, 2023
@jackwotherspoon
Copy link
Collaborator

Version bump has been merged for the crypto dep. This will go out in our next release which will be early/middle of January as we are currently in a holiday release freeze.

@aebrahim
Copy link
Author

@jackwotherspoon thank you for the prompt fix and clear response. I just wanted to let you know that your attention to detail for these open source proxy repositories is a big part of why our team remains confident in using Google Cloud SQL.

@jackwotherspoon
Copy link
Collaborator

@aebrahim Thanks for the kind words. Always our pleasure to help maintain and contribute to Cloud SQL and its users 😄

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns.
Projects
None yet
Development

No branches or pull requests

2 participants