postgres-operator icon indicating copy to clipboard operation
postgres-operator copied to clipboard

Spilo version is old, CVEs need to be mitigated

Open kingsixty opened this issue 5 months ago • 0 comments

The latest Spilo version is spilo-16:3.3-p1. spilo-16 was built built 6 months ago.

The minor versions of postgres managed by this image have the following CVEs:

CVE-2024-10979 CVE-2024-10978 CVE-2024-10977

What are the plans for providing updates to spilo 16?

More info, from Nessus scanning: https://www.tenable.com/plugins/nessus/211655 The version of PostgreSQL installed on the remote host is 12 prior to 12.21, 13 prior to 13.17, 14 prior to 14.14, 15 prior to 15.9, 16 prior to 16.5, or 17 prior to 17.1. As such, it is potentially affected by multiple vulnerabilities...

kingsixty avatar Jun 09 '25 17:06 kingsixty