这是indexloc提供的服务,不要输入任何密码
Skip to content

CVEs detected in Golang stdlib for latest image #111

@nh250146

Description

@nh250146

The following CVEs were found, via trivy, in Golang's stdlib from the latest image on Docker hub.

Target serve

Vulnerabilities (4)

Package ID Severity Installed Version Fixed Version
stdlib CVE-2024-34156 HIGH 1.22.4 1.22.7, 1.23.1
stdlib CVE-2024-24791 MEDIUM 1.22.4 1.21.12, 1.22.5
stdlib CVE-2024-34155 MEDIUM 1.22.4 1.22.7, 1.23.1
stdlib CVE-2024-34158 MEDIUM 1.22.4 1.22.7, 1.23.1

No Misconfigurations found

It should be sufficient to bump the Golang version to 1.22.7 to resolve this

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions