Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

golang.org/x/net CVEs #26

Closed
ntang86 opened this issue Sep 1, 2023 · 3 comments
Closed

golang.org/x/net CVEs #26

ntang86 opened this issue Sep 1, 2023 · 3 comments

Comments

@ntang86
Copy link

ntang86 commented Sep 1, 2023

Hi, the old release v.0.3.0 has vulnerability issue with golang.org/x/net v0.0.0-20221004154528-8021a29435af
https://security-tracker.debian.org/tracker/CVE-2022-41723
https://security-tracker.debian.org/tracker/CVE-2022-41721

Are we planning on a new release?

Thank you

@sethvargo
Copy link
Member

Hi @ntang86 - the module requires Go 1.19, which marked this CVE as fixed. Are you seeing something different?

@ntang86
Copy link
Author

ntang86 commented Sep 1, 2023

Sorry, I'm not sure of what it means on the Debian website :/
Here is the Github CVE report GHSA-vvpx-j8f3-3w6h

I compiled cloud-run-proxy with the v.0.3.0 release and copied the binary into the final destination, but google artifact registry still detect the CVE. And that's because of the indirect dependency, any version of this package < v0.7.0, is affected

golang.org/x/net v0.0.0-20221004154528-8021a29435af

image

@sethvargo
Copy link
Member

Okay I just cut https://github.com/GoogleCloudPlatform/cloud-run-proxy/releases/tag/v0.4.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants