/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-fqm4-cr4p-7gr5

Published

Last updated

https://images.chainguard.dev/security/CGA-fqm4-cr4p-7gr5
Package

gitlab-runner-17.9

Repository

Chainguard

Latest Update
Not affected
Aliases
  • CVE-2024-36623
  • GHSA-gh5c-3h97-2f3q

Severity

8.1

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-36623

Updates

Status

Not affected

Justification

Component not present

Impact

The GHSA-gh5c-3h97-2f3q vulnerability was incorrectly marked as affecting versions earlier than 26.0.0. The issue was actually addressed in version 25.0.4 and later. The GHSA entry has been updated to reflect the correct version: GHSA-gh5c-3h97-2f3q.

Status

Under investigation

Status

Pending upstream fix

Impact

gitlab-runner-17.9.1 uses Docker 25.0.6, as seen here: https://gitlab.com/gitlab-org/gitlab-runner/-/blob/v17.9.1/go.mod?ref_type=tags#L31 The fixed version to remediate this CVE is 26.0.0; however, breaking changes between these major versions require upstream maintainers to implement compatibility.


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing