This image is reported as affected by CVE-2024-24790 #733
Replies: 3 comments 5 replies
-
@pranjalthakur98 this image does not ship any Go binaries. Therefore it cannot be affected by CVE-2024-24790: no Go-based servers are started as part of this image. |
Beta Was this translation helpful? Give feedback.
-
@pranjalthakur98 RabbitMQ is not a Go-based tool, so I do not see how your claim can be true. The title is therefore making a bold claim without providing any evidence of a vulnerability in RabbitMQ. CVE-2024-24790 details in the NIST database further confirm that the issue is in the Go IP/socket implementation, so any Go tooling involved at build time would not affect this image or RabbitMQ. Please post some evidence or this won't be taken seriously. |
Beta Was this translation helpful? Give feedback.
-
@tianon @yosifkit while we don't have any details or proof here to work with, as a general question, This is not the first "issue report" to stem from an automated scan and it won't be the last, so I'd like to understand how official images in general approach this problem. |
Beta Was this translation helpful? Give feedback.
-
We are using Rabbitmq as a base image to develop application on the top of it but we are tagged with a critical vulnerability of Go (golang) [CVE-2024-24790]. This is stopping us from using it.
Can this vulnerability could be fixed ?
We could see this is only with 4.* version of rabbitmq image with ubuntu OS.
Beta Was this translation helpful? Give feedback.
All reactions