Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GHSA-qq97-vm5h-rrhg: OCI Manifest Type Confusion Issue #224

Closed
KevinPoole opened this issue Dec 29, 2022 · 1 comment
Closed

GHSA-qq97-vm5h-rrhg: OCI Manifest Type Confusion Issue #224

KevinPoole opened this issue Dec 29, 2022 · 1 comment

Comments

@KevinPoole
Copy link

Anchore and Twistlock both identify Pumba as being vulnerable to Github Security Advisory described here GHSA-qq97-vm5h-rrhg.

Described fix is to upgrade github.com/docker/distribution to at least v2.8.0-beta.1 if you are running v2.x release. If you use the code from the main branch, update at least to the commit after b59a6f827947f9e0e67df0cfb571046de4733586.

-Kevin

@alexei-led
Copy link
Owner

fixed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants