Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bumped Go version to get some CVE fixes #256

Merged
merged 1 commit into from
Apr 12, 2023
Merged

Conversation

Enmk
Copy link
Member

@Enmk Enmk commented Apr 11, 2023

Changelog category (leave one):

  • Security fix

Changelog entry (a user-readable short description of the changes that goes to CHANGELOG.md):

Building clickhouse-diagnostics against Golang 1.19.8 in order to get CVE fixes :

pkg:golang/stdlib@1.19.5

✗ HIGH CVE-2022-41725 [Uncontrolled Resource Consumption]
  https://dso.docker.com/cve/CVE-2022-41725
  Affected range : <1.19.6
  Fixed version  : 1.19.6
  CVSS Score     : 7.5
  CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

✗ HIGH CVE-2022-41724 [Uncontrolled Resource Consumption]
  https://dso.docker.com/cve/CVE-2022-41724
  Affected range : <1.19.6
  Fixed version  : 1.19.6
  CVSS Score     : 7.5
  CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

✗ HIGH CVE-2022-41723 [Uncontrolled Resource Consumption]
  https://dso.docker.com/cve/CVE-2022-41723
  Affected range : <1.19.6
  Fixed version  : 1.19.6
  CVSS Score     : 7.5
  CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

✗ HIGH CVE-2022-41722 [Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')]
  https://dso.docker.com/cve/CVE-2022-41722
  Affected range : <1.19.6
  Fixed version  : 1.19.6
  CVSS Score     : 7.5
  CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

✗ MEDIUM CVE-2023-24532 [Incorrect Calculation]
  https://dso.docker.com/cve/CVE-2023-24532
  Affected range : <1.19.7
  Fixed version  : 1.19.7
  CVSS Score     : 5.3
  CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

✗ UNSPECIFIED CVE-2023-24538 [Improper Control of Generation of Code ('Code Injection')]
  https://dso.docker.com/cve/CVE-2023-24538
  Affected range : <1.19.8
  Fixed version  : 1.19.8

✗ UNSPECIFIED CVE-2023-24537 [Loop with Unreachable Exit Condition ('Infinite Loop')]
  https://dso.docker.com/cve/CVE-2023-24537
  Affected range : <1.19.8
  Fixed version  : 1.19.8

✗ UNSPECIFIED CVE-2023-24536 [Uncontrolled Resource Consumption]
  https://dso.docker.com/cve/CVE-2023-24536
  Affected range : <1.19.8
  Fixed version  : 1.19.8

✗ UNSPECIFIED CVE-2023-24534 [Uncontrolled Resource Consumption]
  https://dso.docker.com/cve/CVE-2023-24534
  Affected range : <1.19.8
  Fixed version  : 1.19.8

Lots of high-severity CVE were fixed in 1.19.8:

pkg:golang/stdlib@1.19.5

    ✗ HIGH CVE-2022-41725 [Uncontrolled Resource Consumption]
      https://dso.docker.com/cve/CVE-2022-41725
      Affected range : <1.19.6
      Fixed version  : 1.19.6
      CVSS Score     : 7.5
      CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

    ✗ HIGH CVE-2022-41724 [Uncontrolled Resource Consumption]
      https://dso.docker.com/cve/CVE-2022-41724
      Affected range : <1.19.6
      Fixed version  : 1.19.6
      CVSS Score     : 7.5
      CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

    ✗ HIGH CVE-2022-41723 [Uncontrolled Resource Consumption]
      https://dso.docker.com/cve/CVE-2022-41723
      Affected range : <1.19.6
      Fixed version  : 1.19.6
      CVSS Score     : 7.5
      CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

    ✗ HIGH CVE-2022-41722 [Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')]
      https://dso.docker.com/cve/CVE-2022-41722
      Affected range : <1.19.6
      Fixed version  : 1.19.6
      CVSS Score     : 7.5
      CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

    ✗ MEDIUM CVE-2023-24532 [Incorrect Calculation]
      https://dso.docker.com/cve/CVE-2023-24532
      Affected range : <1.19.7
      Fixed version  : 1.19.7
      CVSS Score     : 5.3
      CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

    ✗ UNSPECIFIED CVE-2023-24538 [Improper Control of Generation of Code ('Code Injection')]
      https://dso.docker.com/cve/CVE-2023-24538
      Affected range : <1.19.8
      Fixed version  : 1.19.8

    ✗ UNSPECIFIED CVE-2023-24537 [Loop with Unreachable Exit Condition ('Infinite Loop')]
      https://dso.docker.com/cve/CVE-2023-24537
      Affected range : <1.19.8
      Fixed version  : 1.19.8

    ✗ UNSPECIFIED CVE-2023-24536 [Uncontrolled Resource Consumption]
      https://dso.docker.com/cve/CVE-2023-24536
      Affected range : <1.19.8
      Fixed version  : 1.19.8

    ✗ UNSPECIFIED CVE-2023-24534 [Uncontrolled Resource Consumption]
      https://dso.docker.com/cve/CVE-2023-24534
      Affected range : <1.19.8
      Fixed version  : 1.19.8
@Enmk Enmk merged commit 5b5c0fd into customizations/22.8.15 Apr 12, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant