Skip to content

Critical Vulnerability in the rcon-cli binary #39

Description

@thijsvanloef

Hi! first of all, thank you for creating this package, i've included it by default in my Palworld docker container. I did however find something worth noting.

The binary uses stdlib v1.19.3 which includes multiple Critical and High vulnerabilities.
image

Would it be possible to provide a release with the stdlib updated to a more recent version?

Thanks in advance

Activity

  1. changed the title [-]Critical Vulnerability when including the rcon-cli package in Container[/-] [+]Critical Vulnerability in the rcon-cli binary[/+] on Jan 27, 2024
  2. thijsvanloef commented on Jan 27, 2024

    @thijsvanloef
    Author

    Since this is a standard go library, the solution should be to simply upgrade go in the build.yml workflow and rebuild the binary if i'm not mistaken.

  3. jammsen commented on Jan 29, 2024

    @jammsen

    +1 on this.

  4. self-assigned this
    on Feb 3, 2024
  5. jammsen commented on Feb 9, 2024

    @jammsen

    Hey @outdead is there any eta known on when this CVE gets fixed?

  6. jammsen commented on Feb 19, 2024

    @jammsen

    Hey @outdead - Now its 3 critical and 18 high CVEs in only that package.

    Can you please share an eta on when this will be fixed?

    image

    @thijsvanloef FYI

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions