Skip to content

Conversation

@Enmk
Copy link
Member

@Enmk Enmk commented Apr 13, 2023

  • Security fix: Do not install clickhouse-diagnostics due to large number of CVEs that popup in golang runtime

Enmk added 5 commits April 11, 2023 16:41
Lots of high-severity CVE were fixed in 1.19.8:

pkg:golang/[email protected]

    ✗ HIGH CVE-2022-41725 [Uncontrolled Resource Consumption]
      https://dso.docker.com/cve/CVE-2022-41725
      Affected range : <1.19.6
      Fixed version  : 1.19.6
      CVSS Score     : 7.5
      CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

    ✗ HIGH CVE-2022-41724 [Uncontrolled Resource Consumption]
      https://dso.docker.com/cve/CVE-2022-41724
      Affected range : <1.19.6
      Fixed version  : 1.19.6
      CVSS Score     : 7.5
      CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

    ✗ HIGH CVE-2022-41723 [Uncontrolled Resource Consumption]
      https://dso.docker.com/cve/CVE-2022-41723
      Affected range : <1.19.6
      Fixed version  : 1.19.6
      CVSS Score     : 7.5
      CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

    ✗ HIGH CVE-2022-41722 [Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')]
      https://dso.docker.com/cve/CVE-2022-41722
      Affected range : <1.19.6
      Fixed version  : 1.19.6
      CVSS Score     : 7.5
      CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

    ✗ MEDIUM CVE-2023-24532 [Incorrect Calculation]
      https://dso.docker.com/cve/CVE-2023-24532
      Affected range : <1.19.7
      Fixed version  : 1.19.7
      CVSS Score     : 5.3
      CVSS Vector    : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

    ✗ UNSPECIFIED CVE-2023-24538 [Improper Control of Generation of Code ('Code Injection')]
      https://dso.docker.com/cve/CVE-2023-24538
      Affected range : <1.19.8
      Fixed version  : 1.19.8

    ✗ UNSPECIFIED CVE-2023-24537 [Loop with Unreachable Exit Condition ('Infinite Loop')]
      https://dso.docker.com/cve/CVE-2023-24537
      Affected range : <1.19.8
      Fixed version  : 1.19.8

    ✗ UNSPECIFIED CVE-2023-24536 [Uncontrolled Resource Consumption]
      https://dso.docker.com/cve/CVE-2023-24536
      Affected range : <1.19.8
      Fixed version  : 1.19.8

    ✗ UNSPECIFIED CVE-2023-24534 [Uncontrolled Resource Consumption]
      https://dso.docker.com/cve/CVE-2023-24534
      Affected range : <1.19.8
      Fixed version  : 1.19.8
Due to large number of CVEs that popup in golang runtime
Bumped Go version to get some CVE fixes
…ostics

Do not install clickhouse-diagnostics
@Enmk
Copy link
Member Author

Enmk commented Apr 13, 2023

Merging earlier - PR introduces no functional changes, so it is safe to assume that no test would break comparing to the previous one (#250)

@Enmk Enmk merged commit a454ebb into releases/22.8.15 Apr 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants