Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve CVE-2024-41110 (github.com/docker/docker package) #7025

Closed
kennytrytek-wf opened this issue Sep 11, 2024 · 2 comments
Closed

Resolve CVE-2024-41110 (github.com/docker/docker package) #7025

kennytrytek-wf opened this issue Sep 11, 2024 · 2 comments
Labels
frozen-due-to-age Locked due to a period of inactivity. Please open new issues or PRs if more discussion is needed.

Comments

@kennytrytek-wf
Copy link
Contributor

This pull request resolves CVE-2024-41110 [High]: #7020

Dependabot has opened pull requests since July 30th to update this dependency, but none have been merged yet. Here is the first pull request: #6999

Please review and merge #7020.

@ptodev
Copy link
Contributor

ptodev commented Oct 10, 2024

Hello! Apologies for the late reply. Agent v0.43.3 contains an updated Docker dependency (version 25.0.6) which doesn't have this vulnerability. Apologies, but this wasn't mentioned in the release notes. Sometimes we don't include CVE fixes in the release notes since it can be hard to tell if something is really a vulnerability and if it's realistically exploitable in Agent.

@ptodev ptodev closed this as completed Oct 10, 2024
@kennytrytek-wf
Copy link
Contributor Author

Thanks! I wasn't too concerned about it, just trying to keep on top of requests from our security team.

@github-actions github-actions bot added the frozen-due-to-age Locked due to a period of inactivity. Please open new issues or PRs if more discussion is needed. label Nov 10, 2024
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Nov 10, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
frozen-due-to-age Locked due to a period of inactivity. Please open new issues or PRs if more discussion is needed.
Projects
None yet
Development

No branches or pull requests

2 participants