Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities found in Golang 1.17.2 #109

Closed
realshuting opened this issue Feb 17, 2022 · 1 comment · Fixed by kyverno/policy-reporter-ui#93, #110 or kyverno/policy-reporter-kyverno-plugin#12
Assignees

Comments

@realshuting
Copy link
Member

realshuting commented Feb 17, 2022

New vulnerabilities are found in Golang 1.17.2, we need to bump Golang version to 1.17.6 for all policy-reporter images:

  • ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation, link
  • Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field, link
@realshuting
Copy link
Member Author

realshuting commented Feb 17, 2022

Hi @fjogeleit - I bumped Go to 1.17.6 for all three policy-reporter images, can we generate new releases for this fix?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
1 participant