Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Curl 7.69 < 8.4.0 Heap Buffer Overflow vulnerability #234

Open
lions1988 opened this issue Mar 11, 2024 · 2 comments
Open

Curl 7.69 < 8.4.0 Heap Buffer Overflow vulnerability #234

lions1988 opened this issue Mar 11, 2024 · 2 comments

Comments

@lions1988
Copy link

Hey team

Our Nesssus scanners detected the following vulnerability on our self-hosted ClearML
Curl 7.69 < 8.4.0 Heap Buffer Overflow

ClearML versions: WebApp: 1.14.0-431 • Server: 1.14.0-431 • API: 2.28
Nessus plugin: https://www.tenable.com/plugins/nessus/182875
CVE: https://nvd.nist.gov/vuln/detail/CVE-2023-38545

I can assume these issues are coming from the base OS image, I have seen this on the following containers:

apiserver
fileserver
elastic
async_delete

Please advice
Thank you

@ainoam
Copy link
Collaborator

ainoam commented Mar 11, 2024

Thanks for pointing this out @lions1988.

The base images for the upcoming server release of v1.15.0 will include the patched version for curl to fix this issue.

@pollfly
Copy link
Contributor

pollfly commented Mar 28, 2024

Hey @lions1988! Just letting you know that this issue has been resolved in the recently released v1.15.0. Let us know if there are any issues :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants