Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-24791 in sops binary v3.9.0 #1572

Open
oschni opened this issue Aug 2, 2024 · 4 comments
Open

CVE-2024-24791 in sops binary v3.9.0 #1572

oschni opened this issue Aug 2, 2024 · 4 comments

Comments

@oschni
Copy link

oschni commented Aug 2, 2024

Our scanning jobs have identified a new CVE "CVE-2024-24791" in the sops binary v3.9.0. This is an issue with the Go standard library net/http.

Is it possible to rebuilt sops binaries once the vulnerability has been fixed?

@oschni oschni changed the title CVE-2024-24791 in sops Binary v3.9.0 CVE-2024-24791 in sops binary v3.9.0 Aug 2, 2024
@duthils
Copy link
Contributor

duthils commented Sep 14, 2024

This CVE is fixed in go 1.22.5, see the release announcement.

The go toolchain was updated to 1.22.5 in #1589

@felixfontein
Copy link
Contributor

I know almost nothing about how goreleaser works, but the release workflow still runs with Go 1.21.x. I created #1615 to change that. (PR to update Go version in CI: #1531.)

@duthils
Copy link
Contributor

duthils commented Sep 14, 2024

Oh, right... For the record, the CVE issue is also fixed in 1.21.12, see the release announcement.

@reneleonhardt
Copy link
Contributor

FYI the latest security fixes have not been backported anymore, so 1.21.13 shoudn't be used anymore:
https://go.dev/doc/devel/release#go1.22.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants