Skip to content

Conversation

nandajavarma
Copy link
Contributor

Description

The docker-compose version has two critical CVEs that are currently fixed by this upgrade:

CVE-2024-41110 - Docker/Moby authorization bypass
CVE-2024-45337 - golang.org/x/crypto SSH authorization bypass

Related Issue(s)

Part of CORE-4865

How to test

Documentation

/hold

@nandajavarma nandajavarma requested a review from a team as a code owner August 25, 2025 11:41
@nandajavarma nandajavarma force-pushed the nvn/upgrade-docker branch 3 times, most recently from 7fcd9c2 to 0eb7a94 Compare August 25, 2025 13:13
@nandajavarma nandajavarma enabled auto-merge (squash) August 25, 2025 15:59
@nandajavarma nandajavarma merged commit 2f2db9c into main Aug 25, 2025
4 checks passed
@nandajavarma nandajavarma deleted the nvn/upgrade-docker branch August 25, 2025 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants