Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-24921 - yq built with go1.17.7 #1153

Closed
Bhavnit34 opened this issue Mar 24, 2022 · 2 comments
Closed

CVE-2022-24921 - yq built with go1.17.7 #1153

Bhavnit34 opened this issue Mar 24, 2022 · 2 comments
Labels

Comments

@Bhavnit34
Copy link

Bhavnit34 commented Mar 24, 2022

Describe the bug

When installing yq 4.23.1 I've noticed that the binary has been built using go1.17.7 and therefore is vulnerable to CVE-2022-24921, even though 8cb2422 had bumped the go version to 1.18 before 4.23.1 was released.

Version of yq: 4.23.1
Operating system: mac and linux
Installed via: release page

I have tested this on https://github.com/mikefarah/yq/releases/download/v4.23.1/yq_darwin_amd64 , https://github.com/mikefarah/yq/releases/download/v4.23.1/yq_linux_amd64 and https://github.com/mikefarah/yq/releases/download/v4.23.1/yq_linux_s390x

❯ strings yq | grep go1.
h1:go1bK/D/BFZV2I8cIQd1NKEZ+0owSTG1fDTci4IqFcE=
go1.17.7
@mikefarah
Copy link
Owner

Oh I see - dependabot updated the docker images, but not the git release workflow - will fix for next release

@mikefarah
Copy link
Owner

Fixed in 4.24.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants