/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-c2wh-53rg-q695

Published

Last updated

https://images.chainguard.dev/security/CGA-c2wh-53rg-q695
Package

gitlab-runner-fips-17.8

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2024-36623
  • GHSA-gh5c-3h97-2f3q

Severity

8.1

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-36623

Updates

Status

Pending upstream fix

Impact

gitlab-runner-fips-17.8.3 uses Docker 25.0.6, as seen here: https://gitlab.com/gitlab-org/gitlab-runner/-/blob/v17.8.3/go.mod?ref_type=tags#L31 The fixed version to remediate this CVE is 26.0.0; however, breaking changes between these major versions require upstream maintainers to implement compatibility.

Status

Pending upstream fix

Impact

Updating this package leads to build errors due to the use of removed types. Upstream maintainers will have to make code changes to resolve this CVE.

Status

Under investigation


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing