Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability CVE-2024-21538 #11412

Open
rafik43 opened this issue Dec 11, 2024 · 2 comments
Open

Vulnerability CVE-2024-21538 #11412

rafik43 opened this issue Dec 11, 2024 · 2 comments
Labels
question Further information is requested

Comments

@rafik43
Copy link

rafik43 commented Dec 11, 2024

Hi, we are getting flagged for CVE-2024-21538 vulnerability.

We are using the image - mcr.microsoft.com/cbl-mariner/base/nodejs:18

Could you please provide an estimated timeline for the fix?

@rafik43 rafik43 added the question Further information is requested label Dec 11, 2024
@jperrin
Copy link
Contributor

jperrin commented Dec 14, 2024

When was the last time you pulled a new version of the container?

This CVE was patched in ce9f875 and the updated container was published a few days ago. I suspect this is just a timing issue.

@rafik43
Copy link
Author

rafik43 commented Dec 16, 2024

I just pulled latest image and I still see the vulnerability.

Image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants