/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-qw57-j898-5h79

Published

Last updated

https://images.chainguard.dev/security/CGA-qw57-j898-5h79
Package

vitess-20.0

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2024-53257
  • GHSA-7mwh-q3xm-qh6p

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-53257

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

This vulnerability detection relates to the parent package (vitess), and is fixed in v20.4. The vitess project creates multiple release tags for each release in GitHub. For example, v20.4 and v20.0.4. Vitess uses v20.0.4 for the image / product version, but uses v20.4 for the published Go binary. There are no code differences between these release tags: https://github.com/vitessio/vitess/compare/v0.20.4...v20.0.4. The GH Advisory DB favors the version used by the published Go binary: https://github.com/advisories/GHSA-7mwh-q3xm-qh6p. Also confirmed by upstream in the following issue: https://github.com/vitessio/vitess/issues/17547.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing