/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-4ww6-mc53-65xg

Published

Last updated

https://images.chainguard.dev/security/CGA-4ww6-mc53-65xg
Package

crane

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2024-41110
  • GHSA-v23v-6jw2-98fq

Severity

9.9

Critical

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-41110

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

This affects docker authorization plugins which are not included in crane.

Status

Pending upstream fix

Impact

Upstream have yet to release a patch to fix this. We attempted upgrading the docker dependency to the fixed version, but the application does not compile, so we will need to wait for a fix from upstream.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing