Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address CVE-2024-41110 #1728

Open
BRONSOLO opened this issue Oct 7, 2024 · 4 comments
Open

Address CVE-2024-41110 #1728

BRONSOLO opened this issue Oct 7, 2024 · 4 comments

Comments

@BRONSOLO
Copy link
Contributor

BRONSOLO commented Oct 7, 2024

An upgrade of the Docker Golang package is needed to address: GHSA-v23v-6jw2-98fq

pkg current fixed
github.com/docker/docker v25.0.5+incompatible 23.0.15, 26.1.5, 27.1.1, 25.0.6
github.com/docker/docker v25.0.5+incompatible 23.0.15, 26.1.5, 27.1.1, 25.0.6
@diarmuidie
Copy link
Contributor

This was fixed in lifecycle v0.20.1 (kpack currently uses v0.17.2) but they noted that it is "Non-impactful as the lifecycle uses only the docker client library" : buildpacks/lifecycle#1391 (comment)

@BRONSOLO
Copy link
Contributor Author

Thanks @diarmuidie! Is the lifecycle dependency the only source of the github.com/docker/docker import? In other words, could we safely assume all images built for the kpack project that report this vulnerability are not impacted because the reported vulnerability is stemming from the lifecycle dependency, which uses only the docker client library?

@tomkennedy513
Copy link
Collaborator

ya this appears to only affect docker engine itself, so we should be okay

@BRONSOLO
Copy link
Contributor Author

Thanks @tomkennedy513. I suspect we can close this ticket out in that case (or leave it open until the lifecycle upgrade is applied).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants