GitHub
02/04/2023, 12:22 AMx):
• [ X ] Confirmed this is the right place to raise the issue - only issues related to the Dockerization of the Pact Broker should be raised here. Issues related to the Pact Broker application itself should be raised in the Pact Broker project.
• [ X ] Upgraded to the latest Pact Broker Docker image OR
• [ X ] Checked the </CHANGELOG.md|CHANGELOG> to see if the issue I am about to raise has been fixed
• [ X ] Read the Troubleshooting page
Software versions
• pact-broker docker version: 2.105.0.0
Expected behaviour
No security vulnerabilities in the image
Actual behaviour
Two security vulnerabilities found:
(CVE-2021-38297 and CVE-2022-23806)
Steps to reproduce
Version 2.105.0.0 of pact-broker uses supercronic with version v0.1.11 which introduces the above security vulnerabilities caused by using an old version of golang (1.14.4).
These vulnerabilities are fixed in golang version 1.17.7+ and are addressed in supercronic v0.2.0 so an upgrade for supercronic to v0.2.0+ would solve it.
pact-foundation/pact-broker-dockerGitHub
02/04/2023, 12:22 AM