-
Notifications
You must be signed in to change notification settings - Fork 2.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[release/2.7] github.com/miekg/dns is vulnerable to CVE-2017-15133 #3467
Comments
Looks like a false positive. The CVE is in the DNS server component of miekg/dns (see miekg/dns#631), and the only purpose it's used for in this repository's codebase is for the client parts (in the github.com/xenolf/lego dependency); https://github.com/distribution/distribution/blob/release/2.7/vendor/github.com/xenolf/lego/acme/dns_challenge.go |
Thanks @thaJeztah, shall we close this issue as consumers of 2.7.2 will be able to link to your statement for their audit stuff? |
Perhaps others should double-check, but overall, I think we should be "ok", and no need to update. I should also link my comment on #3471 (comment), because the same applies to this one.
|
Given the latest release is |
Agreed. |
We use a revision of github.com/miekg/dns older than v1.0.0
distribution/vendor.conf
Line 24 in 18230b7
The text was updated successfully, but these errors were encountered: