Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-24790 and CVE-2024-24791 #1876

Open
KoamSK opened this issue Aug 5, 2024 · 1 comment
Open

CVE-2024-24790 and CVE-2024-24791 #1876

KoamSK opened this issue Aug 5, 2024 · 1 comment

Comments

@KoamSK
Copy link

KoamSK commented Aug 5, 2024

There are two recent critical and high vulnerabilities in the stdlib library in Go:

CVE-2024-24790
CVE-2024-24791

Currently, the GitHub workflows use an outdated Go version. For example, in .github/workflows/release.yml:

Current:
GO_VERSION: 1.19

We need to update it to address these vulnerabilities:

Edit:
GO_VERSION: 1.21

Copy link

github-actions bot commented Oct 5, 2024

Stale issue message

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant