docker-library / ruby

Docker Official Image packaging for Ruby
http://www.ruby-lang.org/
BSD 2-Clause "Simplified" License
590 stars 334 forks source link

ruby:3.2.0-alpine3.17 pkgconf CVE-2023-24056 CRITICAL #404

Closed sixcolors closed 1 year ago

sixcolors commented 1 year ago

ruby:3.2.0-alpine3.17 needs to be rebuilt to remove CVE-2023-24056 with pkgconf

pkgconf CVE-2023-24056 CRITICAL vulnerable version: 1.9.3-r0 fixed in 1.9.4-r0

alpine:3.17 has fixed this. Rebuild should resolve.

tianon commented 1 year ago

Duplicate of #402