yq icon indicating copy to clipboard operation
yq copied to clipboard

Rebuild Alpine-based image to address CVE-2024-6119

Open psmolkin opened this issue 4 months ago • 0 comments

The latest version of yq image contains the following vulnerabilities: CVE-2024-6119:

  • libssl3 < 3.3.2-r0
  • libcrypto3 < 3.3.2-r0

Version of yq: (4.44.3) Operating system: Alpine 3.20 Installed via: docker

Additional context The latest Alpine 3.20 build already includes the patched versions of the affected libraries, so only a rebuild is required.

psmolkin avatar Oct 01 '24 07:10 psmolkin