Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical Golang vulnerability in v0.13.2 #362

Open
mdfst opened this issue Jun 20, 2024 · 8 comments · May be fixed by #366
Open

Critical Golang vulnerability in v0.13.2 #362

mdfst opened this issue Jun 20, 2024 · 8 comments · May be fixed by #366
Assignees
Labels

Comments

@mdfst
Copy link

mdfst commented Jun 20, 2024

Envconsul version

/usr/local/bin/envconsul --version
envconsul v0.13.2 (dd416ce)

Which is the latest release available
https://github.com/hashicorp/envconsul/releases

Contains critical golang vulnerability

usr/local/bin/envconsul (gobinary)
==================================
Total: 1 (CRITICAL: 1)

Installed version: 1.20.4    
Fixed Version: 1.21.11, 1.22.4

https://nvd.nist.gov/vuln/detail/CVE-2024-24790
golang/go#67680

@marrws
Copy link

marrws commented Jul 1, 2024

Related to #324

@marrws
Copy link

marrws commented Aug 7, 2024

@armon @catsby @ryanuber @hc-github-team-es-release-engineering I'm really sorry for the ping but this is important.

Can we get a new release so the vulnerabilities don't keep piling up?

@marrws
Copy link

marrws commented Aug 26, 2024

Sorry to ping you directly @NicoletaPopoviciu

Can we get a new release so the vulnerabilities don't keep piling up?

@marrws
Copy link

marrws commented Aug 26, 2024

Sorry to ping you directly @dhiaayachi

Can we get a new release so the vulnerabilities don't keep piling up?

@chris-peterson
Copy link

chris-peterson commented Sep 30, 2024

I hate to respond with "+1", but I'm also in need of a release.

a container I'm using envconsul in got dinged for CVE-2022-23806 (and related)

I believe these would all be resolved by republishing anything after go updated

@noahtrilling
Copy link

According to the CODEOWNERS file in this repository, the Consul team are the owners of envconsul. Since the issues in this repository seem unmonitored, I've created an issue in the Consul repository to get the vulnerabilities addressed.

Consul #21879

@1FastSTi
Copy link

Also CVE-2023-45288

@dduzgun-security
Copy link

dduzgun-security commented Dec 20, 2024

Hi all, thanks for reporting the issue and really sorry about the delay on this.
Created #366 to resolve the issue, it should be resolved in the next release.

For future reporting of vulnerabilities, we recommend reaching to the [email protected] email to have faster replies as described in our guide https://www.hashicorp.com/trust/security/vulnerability-management.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

6 participants