/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-m5rq-3mg6-wqqf

Published

Last updated

https://images.chainguard.dev/security/CGA-m5rq-3mg6-wqqf
Package

gitlab-runner-17.11

Repository

Chainguard

Latest Update
Not affected
Aliases
  • CVE-2024-36623
  • GHSA-gh5c-3h97-2f3q

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-36623

Updates

Status

Not affected

Justification

Component not present

Impact

github.com/docker/docker v25.0.6+incompatible was incorrectly flagged due to a vulnerability-component mismatch; this version matches the v25.0.6 upstream release: https://github.com/moby/moby/releases/tag/v25.0.6 which includes the fix for GHSA-gh5c-3h97-2f3q: https://github.com/moby/moby/commit/8e3bcf19748838b30e34d612832d1dc9d90363b8 The +incompatible suffix is a Go module artifact and does not affect vulnerability status.

Status

Affected

Impact

Unable to use govulncheck to triage this advisory because the vulnerability was not found in the Go vuln DB. Treating as a true positive since we can't confirm this is a false positive.

Status

Under investigation

Status

Pending upstream fix

Impact

Upgrading the github.com/docker/docker dependency to >= v26 resulting build failure: "undefined: types.ContainerStartOptions".


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing