Skip to content

puppet-agent's packaged curl is vulnerable to CVE-2024-2004 and CVE-2024-2398 #811

@cthorn42

Description

@cthorn42

Curl recently announced a new released of their 8 series. Puppet-agent is still a bit behind on the 7.x version, and there were two security announcements that affect the 7.x version in the latest 8.x release.
Here are the following two issues:

Assuming we aren't close to the 8.x curl migration, we should backport the patches for the above issues into our puppet-runtime for both branches.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingtriagedJira issue has been created for this

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions