Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical Vulnerability in the rcon-cli binary #39

Open
thijsvanloef opened this issue Jan 27, 2024 · 4 comments
Open

Critical Vulnerability in the rcon-cli binary #39

thijsvanloef opened this issue Jan 27, 2024 · 4 comments
Assignees
Labels
bug Something isn't working

Comments

@thijsvanloef
Copy link

Hi! first of all, thank you for creating this package, i've included it by default in my Palworld docker container. I did however find something worth noting.

The binary uses stdlib v1.19.3 which includes multiple Critical and High vulnerabilities.
image

Would it be possible to provide a release with the stdlib updated to a more recent version?

Thanks in advance

@thijsvanloef thijsvanloef changed the title Critical Vulnerability when including the rcon-cli package in Container Critical Vulnerability in the rcon-cli binary Jan 27, 2024
@thijsvanloef
Copy link
Author

thijsvanloef commented Jan 27, 2024

Since this is a standard go library, the solution should be to simply upgrade go in the build.yml workflow and rebuild the binary if i'm not mistaken.

@jammsen
Copy link

jammsen commented Jan 29, 2024

+1 on this.

@outdead outdead self-assigned this Feb 3, 2024
@outdead outdead added the bug Something isn't working label Feb 3, 2024
@jammsen
Copy link

jammsen commented Feb 9, 2024

Hey @outdead is there any eta known on when this CVE gets fixed?

@jammsen
Copy link

jammsen commented Feb 19, 2024

Hey @outdead - Now its 3 critical and 18 high CVEs in only that package.

Can you please share an eta on when this will be fixed?

image

@thijsvanloef FYI

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants