security: CVE-2023-49569 - go-git/v5 #3272
cmontemuino
started this conversation in
General
Replies: 2 comments 2 replies
-
Thanks for mentioning it, @cmontemuino. 👍 |
Beta Was this translation helpful? Give feedback.
1 reply
-
Hey, seems like the issue on go is already closed, pull request is merged. Can You guys release new version with this package fixed? Best Regards :) @cmontemuino @nabokihms |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
We've observed (Trivy scan) ghcr.io/dexidp/dex:v2.37.0 includes critical vulnerability CVE-2023-4956 in package
github.com/go-git/go-git/v5
.The vulnerability does not come from dex binary, but
gotemplate
. I've filed an issue in their repo and proposed a fix: hairyhenderson/gomplate#1960When it's accepted and released, then a new version of
dexidp/dex
might be created.Note: it makes all images that depend on dexidp/dex contain that critical vulnerability.
Beta Was this translation helpful? Give feedback.
All reactions