-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Closed
Description
Preflight Checklist
- I agree to follow the Code of Conduct that this project adheres to.
- I have searched the issue tracker for an issue that matches the one I want to file, without success.
- I am not looking for support or already pursued the available support channels without success.
Version
v2.40.0
Storage Type
Kubernetes
Installation Type
Official container image
Expected Behavior
Vulnerability-free docker image
Actual Behavior
CVE-2024-24790 has been published against the go stdlib net/netip and is found by trivy in docker image v2.40:
Steps To Reproduce
trivy image --ignore-unfixed --exit-code 1 --severity CRITICAL ghcr.io/dexidp/dex:v2.40.0
Additional Information
No response
Configuration
No response
Logs
No response
Metadata
Metadata
Assignees
Labels
No labels