hashicorp / docker-vault

Official Docker images for Vault
Mozilla Public License 2.0
500 stars 223 forks source link

Vault Binary in vault:1.13.3 docker image has CVE-2023-34231 Vuln (High) #342

Open eshafaq1 opened 1 year ago

eshafaq1 commented 1 year ago

│Vulnerability │ Severity │ Installed Version │ Fixed Version |CVE-2023-34231 │ HIGH │ v1.6.3 │ 1.6.19

There looks to be a vulnerability with a third party package (github.com/snowflakedb/gosnowflake) in the latest version of the vault docker image. Specifically the vault binary (bin/vault (gobinary) has this vulnerability from what Trivy is reporting. (see screenshot)

Screenshot 2023-08-07 at 1 42 53 PM

Filing this ticket in hope folks can get this patched and publish a new image.