/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-mvh3-v8v8-6jpj

Published

Last updated

https://images.chainguard.dev/security/CGA-mvh3-v8v8-6jpj
Package

juicefs-1.3

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2018-1099
  • GHSA-wf43-55jj-vwq8

Severity

5.5

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2018-1099

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

JuiceFS only uses etcd client libraries (go.etcd.io/etcd/client/v3) for connecting to external etcd clusters. This vulnerability affects etcd server components, which are not present in JuiceFS. Static analysis confirms no etcd server symbols exist in the binary, and govulncheck produces no findings. This CVE does not apply to JuiceFS client-only usage.

Status

Pending upstream fix

Impact

This package must be removed from upstream dependencies. Upstream already consumes the fixed version, and trying to bump the vulnerable version will cause build failures due to duplication.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing