CVE-2023-45288 on 3.5.14 #18168
-
Hi! I'm unfamiliar with posting to this forum, so please bear with me if there are rules that I fail to follow 🙏 I am looking to address CVE-2023-45288 for my organization that is discovered by Snyk when scanning etcd 3.5.13. My understanding (from #17703) was that However, when I try to use etcd 3.5.14 using the bitnami/etcd or the coreos/etcd docker images, snyk continues to find version 0.17.0 When I download the actual binary release from the Am I missing anything here? Please help. Thanks. |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 21 replies
-
Hi @henrybear327, I'm hoping you might be able to help me confirm if this is just an error on my side, or if the CVE is still open? It looks like the patch was only made to the main Thank you so much in advance. |
Beta Was this translation helpful? Give feedback.
-
@ahrtr I think I need to address 2 issues (and I am on it now)
Based on the grep log I indeed missed other
|
Beta Was this translation helpful? Give feedback.
Initial PR for release branch 3.5 regarding CI and dependency updates is up for review!