vault-fips-1.17
Chainguard
1.17.4-r0
9.9
CVSS V3
Status
Fixed version
1.17.4-r0Status
Impact
The main Vault code depends on github.com/hashicorp/go-secure-stdlib/plugincontainer, which in its latest version still relies on a vulnerable version of github.com/docker/docker. A new release of hashicorp/go-secure-stdlib/plugincontainer incorporating the changes from PR https://github.com/hashicorp/go-secure-stdlib/pull/125 is needed.
Status