Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix CVE-2023-39325, CVE-2023-3978 and CVE-2023-44487 #464

Merged
merged 1 commit into from
Oct 16, 2023
Merged

Conversation

LionelJouin
Copy link
Member

@LionelJouin LionelJouin commented Oct 12, 2023

Description

Update of golang.org/x/net
Update of security tools in makefile
Update of the grpc-health-probe binary

Still requires an update of golang.org/x/net in https://github.com/grpc-ecosystem/grpc-health-probe

Issue link

CVE-2023-39325 (GHSA-4374-p667-p6c8)
CVE-2023-3978 (GHSA-2wrh-6pvc-2jm9)
CVE-2023-44487 (GHSA-qppj-fm5r-hxr3)

https://jenkins.nordix.org/job/meridio-periodic-security-scan/403/artifact/_output/report.txt

Checklist

  • Purpose
    • Bug fix
    • New functionality
    • Documentation
    • Refactoring
    • CI
  • Test
    • Unit test
    • E2E Test
    • Tested manually
  • Introduce a breaking change
    • Yes (description required)
    • No

@LionelJouin LionelJouin changed the title Fix CVE-2023-39325 and CVE-2023-3978 Fix CVE-2023-39325, CVE-2023-3978 and CVE-2023-44487 Oct 14, 2023
Update of golang.org/x/net
Update of security tools in makefile
Update of the grpc-health-probe binary
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

1 participant