Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make 1.17.5 the default application version due to CVE-2024-8365 #1058

Open
pvlkov opened this issue Sep 25, 2024 · 1 comment
Open

Make 1.17.5 the default application version due to CVE-2024-8365 #1058

pvlkov opened this issue Sep 25, 2024 · 1 comment
Labels
enhancement New feature or request

Comments

@pvlkov
Copy link

pvlkov commented Sep 25, 2024

Is your feature request related to a problem? Please describe.
The vulnerability/regression mentioned in https://nvd.nist.gov/vuln/detail/CVE-2024-8365 was fixed in Vault version 1.17.5, however the default application version in the newest Helm chart version is still 1.17.2.

Describe the solution you'd like
1.17.5 should be the default version in the Helm chart, so that users do not need to manually override the image tag.

Describe alternatives you've considered
Manually overriding the image tag.

Additional context
Add any other context or screenshots about the feature request here.

@pvlkov pvlkov added the enhancement New feature or request label Sep 25, 2024
@pvlkov
Copy link
Author

pvlkov commented Nov 7, 2024

Can we expect any reaction here? A 6.5 CVSS score vulnerability is not trivial and should not just be ignored. Would it help if a PR would be provided (although it is only a couple of lines of changes...)?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant