/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-8w9v-vm2p-m7q9

Published

Last updated

https://images.chainguard.dev/security/CGA-8w9v-vm2p-m7q9
Package

gitlab-runner-17.3

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2024-41110
  • GHSA-v23v-6jw2-98fq

Severity

9.9

Critical

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-41110

Updates

Status

Fix not planned

Impact

This package is no longer supported upstream and has reached its end of life on '2024-11-21'.

Status

Under investigation

Status

Fixed

Fixed version

17.3.3-r1

Status

Pending upstream fix

Impact

Also present in previous gitlab-runner-17.2 and new scan reveals that this CVE is still present. Upstream merge request https://gitlab.com/gitlab-org/gitlab-runner/-/merge_requests/4925 details the issues stating that the only current path to remediating this CVE is to bump major version of go to >=v25.0.6 and required a lot of changes. This upstream merge request has been merged and is part of the 17.4 release - see https://gitlab.com/gitlab-org/gitlab-runner/-/commits/v17.4.0?search=CVE-2024-41110. I could not find any plans to backport this to 17.3.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing