DirectorySecurity Advisories
Sign In
Security Advisories

CGA-72p7-7qwm-2pw4

Published

Last updated

https://images.chainguard.dev/security/CGA-72p7-7qwm-2pw4
Package

crossplane

Latest Update
Fixed
Fixed Version

1.17.2-r0

Aliases
  • GHSA-7h65-4p22-39j6

Severity

9.8

Critical

CVSS V3

Summary

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

Description

A critical vulnerability was reported in the versions of golang that Crossplane depends on. Details of the golang vulnerability are included below. Crossplane does not directly use the vulnerable functions from the net/netip package, but the version of golang libraries, runtime, and build tools have still been updated as part of this security advisory nonetheless.

Critical Vulnerabilities Vulnerability: CVE-2024-24790, golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses Description: The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

Affected versions: 1.17.1,1.16.2,1.15.5

See screenshot for more details Screenshot from 2024-09-18 17-36-37

Fixed versions: 1.17.2,1.16.3,1.15.6

Release notes:

References

  • https://github.com/advisories/GHSA-7h65-4p22-39j6

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images