tianon / gosu

Simple Go-based setuid+setgid+setgroups+exec
Apache License 2.0
4.72k stars 320 forks source link

CVE-2023-29403 discovered in gosu #148

Closed abudan-wb closed 4 months ago

abudan-wb commented 4 months ago

When installing GOSU 1.17 in a alpine image install gosu, vulnerabilities scan shows that GOSU brings CVE-2023-29403 from runtime golang dependency.

Vulnerability scan report: scan report

https://nvd.nist.gov/vuln/detail/CVE-2023-29403

Please provide new update of GOSU.

tianon commented 4 months ago

Please (re-)read https://github.com/tianon/gosu/blob/052c5c2b186b84c4d9a41ed4f327490ef8d746fe/SECURITY.md