<#88 Security vulnerabilities introduced by superc...
# pact-broker
g
#88 Security vulnerabilities introduced by supercronic Issue created by mohammed-ezzedine Pre issue-raising checklist I have already (please mark the applicable with an
x
): • [ X ] Confirmed this is the right place to raise the issue - only issues related to the Dockerization of the Pact Broker should be raised here. Issues related to the Pact Broker application itself should be raised in the Pact Broker project. • [ X ] Upgraded to the latest Pact Broker Docker image OR • [ X ] Checked the </CHANGELOG.md|CHANGELOG> to see if the issue I am about to raise has been fixed • [ X ] Read the Troubleshooting page Software versions • pact-broker docker version: 2.105.0.0 Expected behaviour No security vulnerabilities in the image Actual behaviour Two security vulnerabilities found: (CVE-2021-38297 and CVE-2022-23806) Steps to reproduce Version 2.105.0.0 of pact-broker uses supercronic with version v0.1.11 which introduces the above security vulnerabilities caused by using an old version of golang (1.14.4). These vulnerabilities are fixed in golang version 1.17.7+ and are addressed in supercronic v0.2.0 so an upgrade for supercronic to v0.2.0+ would solve it. pact-foundation/pact-broker-docker