caddy-docker icon indicating copy to clipboard operation
caddy-docker copied to clipboard

Current 2.8.4 image contain critical security vulnerability

Open shahar-davidson opened this issue 8 months ago • 4 comments

As of today, the latest Caddy 2.8.4 for Alpine contains a security vulnerability that is ranked as Critical: CVE-2024-24790⁠ (published on June 4, 2024)

This vulnerability appears to have been fixed already in the latest golang:1.22 for Alpine image.

Therefore, caddy image needs to be recreated with the latest Golang image (1.22.4 or later)

image

shahar-davidson avatar Jun 19 '24 09:06 shahar-davidson