Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability CVE-2024-45337 found in Ekuiper image #3444

Open
OlgasAcc opened this issue Dec 15, 2024 · 2 comments
Open

Vulnerability CVE-2024-45337 found in Ekuiper image #3444

OlgasAcc opened this issue Dec 15, 2024 · 2 comments

Comments

@OlgasAcc
Copy link

Environment:

  • eKuiper version (e.g. 1.3.0): 1.4.6-alpine
  • OS (e.g. cat /etc/os-release): Ubuntu, MacOS

What happened and what you expected to happen:

The critical vulnerability has been reported by our Aqua scanner, could you please upgrade the problematic dependency for v1.x and 2.x?
https://github.com/lf-edge/ekuiper/security/advisories/GHSA-g9m3-63ph-99c5

NVD URL : https://nvd.nist.gov/vuln/detail/CVE-2024-45337
Fix Version : 0.31.0

Thanks

@ngjaying
Copy link
Collaborator

Hi @OlgasAcc , thanks for rasing this up. Would you possible to help fix this problem in master-1.14 branch? Due to resource limit, we generally cannot maintain too many versions.

@OlgasAcc
Copy link
Author

Hi @ngjaying sure, this is a PR: #3447. Could you please review?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants