Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

backport the security patch of CVE-2024-21506 #1778

Closed

Conversation

Crispy-fried-chicken
Copy link

Here is a vulnerability which is mentioned in #1564 and fixed in the v4.6branch 56b6b6d, but is not fixed in the branch of v4.4, maybe it should be backported?

@keanamo keanamo added the tracked-in-jira Ticket filed in Mongo's Jira system label Aug 8, 2024
@ShaneHarvey
Copy link
Member

Hi @Crispy-fried-chicken, we don't support the v4.4 version anymore. Is there any reason you cannot upgrade to 4.6.3+, 4.7+ or 4.8.0? We follow semantic version so your app should be able to upgrade without issue.

@Crispy-fried-chicken
Copy link
Author

Crispy-fried-chicken commented Aug 9, 2024

Hi, @ShaneHarvey ,Given the complexity of my project, upgrading directly to versions 4.6.3+, 4.7+, or 4.8.0 could potentially cause various supply chain security challenges. Moreover, I know that a significant number of users are still dependent on version v4.4. With this in mind, could you please consider implementing the fix in the v4.4 branch? This would greatly contribute to maintaining security and stability for those continuing to use this version.

@blink1073
Copy link
Member

could potentially cause various supply chain security challenges

We only have one direct dependency, dnspython, and it did not change between the two versions. We don't have the infrastructure set up to make a release against this branch.

@blink1073
Copy link
Member

Unfortunately we are unable accept this change.

@blink1073 blink1073 closed this Aug 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
tracked-in-jira Ticket filed in Mongo's Jira system
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants