/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-q87q-m7jv-rffq

Published

Last updated

https://images.chainguard.dev/security/CGA-q87q-m7jv-rffq
Package

vault-fips-1.14

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2024-2660
  • GHSA-j2rp-gmqv-frhv

Severity

6.8

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-2660

Updates

Status

Fix not planned

Impact

Version 1.14 is end of life and will not receive more updates - marking CVE fix-not-planned. EOL date for vault 1.14 was 2024-06-10.

Status

Under investigation

Status

Fixed

Fixed version

1.14.11-r0

Status

Fix not planned

Impact

The vulnerability is fixed in version 1.16 of Vault. This package is locked to version 1.14.


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing