-
Notifications
You must be signed in to change notification settings - Fork 3.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[ CVE-2024-6104 ] Update github.com/hashicorp/go-retryablehttp package #13079
Comments
|
Thanks for bubbling up this issue. A pull-request has been to address this vulnerability - a subsequent change has been made to the Packer SDK, as well. We will release Packer 1.11.1 next week. Given our LTS support model we will only update the latest version of Packer, and will not back port to 1.10.3. |
I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. |
Currently we are observing security vulnerability with packer.
Packer Version : 1.10.3 / v1.11.0
CVE- CVE-2024-6104
Severity : MEDIUM
So wanted to any plan on releasing patch for this in next release. if not when can we expect release with this patch.
The text was updated successfully, but these errors were encountered: