GoogleContainerTools / distroless

🥑 Language focused docker images, minus the operating system.
Apache License 2.0
18.16k stars 1.11k forks source link

Python 3.11 CVE patches - CVE-2023-41105, CVE-2023-40217, CVE-2023-24329 #1613

Open JasperJuergensen opened 1 week ago

JasperJuergensen commented 1 week ago

Please describe the image you encountered this with and a link to the debian security tracker https://security-tracker.debian.org/tracker/CVE-2023-41105 https://security-tracker.debian.org/tracker/CVE-2023-40217 https://security-tracker.debian.org/tracker/CVE-2023-24329

All three vulnerabilities are fixed with version 3.11.2-6+deb12u2, which has been available for Debian bookworm since 02 May 2024 (according to the Debian Changelog) and installed into the Debian FTP archive since 21 May 2024 (according to the Build status).

loosebazooka commented 4 days ago

Yeah our updater has been having issues. Hope to fix soon.