Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

KrakenD v2.7 new vulnerability CVE-2024-34156 #922

Closed
MoeBensu opened this issue Sep 10, 2024 · 1 comment
Closed

KrakenD v2.7 new vulnerability CVE-2024-34156 #922

MoeBensu opened this issue Sep 10, 2024 · 1 comment

Comments

@MoeBensu
Copy link

MoeBensu commented Sep 10, 2024

Environment info:

  • KrakenD version: v2.6.3
  • System info: docker system

Describe the bug
CVE-2024-34156 has been published against the stdlib lib in go binaries and is found by trivy in docker image v2.7 which uses go1.22.5

Screenshot 2024-09-10 at 09 37 56

It is recommended to fix with the patch go1.22.7 or the very recent minor update go1.23.1. Which one would you prefer to go with?

It is also the question, wether the package encoding/gob is used in krakend-ce or not.

Commands used
trivy image -v devopsfaith/krakend:2.7

Expected behavior
No high/critical vulnerability report.

@kpacha
Copy link
Member

kpacha commented Sep 10, 2024

The pkg gopkg.in/square/go-jose.v2 has been replaced and the stdlib updated to 1.22.7. The PR (#920) was merged yesterday and today we released v2.7.1 (https://github.com/krakend/krakend-ce/releases/tag/v2.7.1)

@kpacha kpacha closed this as completed Sep 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants