deckhouse / deckhouse-cli

Command Line Interface to work with Deckhouse Kubernetes Platform
Apache License 2.0
7 stars 8 forks source link

chore: bump github.com/containers/buildah to 1.37.4 #49

Closed mvasl closed 1 month ago

mvasl commented 1 month ago

This is a fix for the following CVEs:

d8 (gobinary)
=============
Total: 2 (UNKNOWN: 0, LOW: 0, MEDIUM: 2, HIGH: 0, CRITICAL: 0)

┌───────────────────────────────┬───────────────┬──────────┬──────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────┐
│            Library            │ Vulnerability │ Severity │  Status  │ Installed Version │ Fixed Version │                        Title                         │
├───────────────────────────────┼───────────────┼──────────┼──────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────┤
│ github.com/containers/buildah │ CVE-2024-9407 │ MEDIUM   │ fixed    │ v1.35.1           │ 1.37.4        │ Buildah: Podman: Improper Input Validation in        │
│                               │               │          │          │                   │               │ bind-propagation Option of Dockerfile RUN --mount... │
│                               │               │          │          │                   │               │ https://avd.aquasec.com/nvd/cve-2024-9407            │
│                               ├───────────────┤          ├──────────┤                   ├───────────────┼──────────────────────────────────────────────────────┤
│                               │ CVE-2024-9675 │          │ affected │                   │               │ buildah: Buildah allows arbitrary directory mount    │
│                               │               │          │          │                   │               │ https://avd.aquasec.com/nvd/cve-2024-9675            │
└───────────────────────────────┴───────────────┴──────────┴──────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────┘