Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch agent-runtime-7.x and main Curl for CVE-2024-7264 #883

Closed
cthorn42 opened this issue Jul 31, 2024 · 2 comments
Closed

Patch agent-runtime-7.x and main Curl for CVE-2024-7264 #883

cthorn42 opened this issue Jul 31, 2024 · 2 comments
Labels
bug Something isn't working triaged Jira issue has been created for this

Comments

@cthorn42
Copy link
Collaborator

cthorn42 commented Jul 31, 2024

We use a patched Curl 7 in the agent-runtime-7.x, and a recent CVE for Curl, https://curl.se/docs/CVE-2024-7264.html, affects our curl 7.88.1 for agent-runtime-7.x.
We should track down and apply this patch.

This also affects curl < 8.9.1 and we're at 8.7.1. We should update curl to latest in agent-runtime-main

@cthorn42 cthorn42 added the triaged Jira issue has been created for this label Jul 31, 2024
Copy link

Migrated issue to PA-6878

@cthorn42 cthorn42 changed the title Bump agent-runtime-7.x's Curl for CVE-2024-7264 Patch agent-runtime-7.x's Curl for CVE-2024-7264 Jul 31, 2024
@joshcooper joshcooper added the bug Something isn't working label Jul 31, 2024
@joshcooper joshcooper changed the title Patch agent-runtime-7.x's Curl for CVE-2024-7264 Patch agent-runtime-7.x and main Curl for CVE-2024-7264 Aug 2, 2024
@joshcooper
Copy link
Contributor

agent-runtime-7.x was fixed in #898

agent-runtime-main was already fixed when we moved to curl 8.9.1, so no changes were required to this repo.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working triaged Jira issue has been created for this
Projects
None yet
Development

No branches or pull requests

2 participants