Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability CVE-2023-45288 in dependency golang.org/x/net - v0.17.0 #1906

Open
amardeep2006 opened this issue Apr 12, 2024 · 0 comments
Open

Comments

@amardeep2006
Copy link

Please note that the Consul Template issue tracker is reserved
for bug reports and enhancements. For general usage questions,
please use the Consul Community Portal or the Consul mailing list:

https://discuss.hashicorp.com/c/consul
https://groups.google.com/forum/#!forum/consul-tool

Please try to simplify the issue as much as possible and include all the
details to replicate it. The shorter and simpler the bug is to reproduce the
quicker it can be addressed. Thanks.

Consul Template version

0.37.4
Run consul-template -v to show the version. If you are not
running the latest version, please upgrade before submitting an
issue.

Configuration

# Copy-paste your configuration files here. Only include what is necessary or
# what you've changed from defaults. Include all referenced configurations.
# Copy-paste your Consul Template template here
# Include sample data you reference in the template from Consul or Vault here.

Command

# Place your Consul Template command here

Debug output

Provide a link to a GitHub Gist containing the complete debug
output by running with -log-level=trace.

Expected behavior

What should have happened?
We scan the consul-template via Sysdig and it has failed the security scan and suggests to bump it to
golang.org/x/net - v0.24.0

Actual behavior

What actually happened?
consul-template scan failed due to dependency golang.org/x/net - v0.17.0 .

Steps to reproduce

References

Are there any other GitHub issues (open or closed) that should
be linked here? For example:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant