go.woodpecker-ci.org/[email protected] has vulnerabilities — update to latest
Update to >= 2.7.0 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2024-41122 | Woodpecker's custom environment variables allow to alter execution flow of plugins | 2.7.0 |
| high | CVE-2024-41121 | Woodpecker's custom workspace allow to overwrite plugin entrypoint executable | 2.7.0 |
| unknown | CVE-2024-41122 | Woodpecker's custom environment variables allow to alter execution flow of plugins in go.woodpecker-ci.org/woodpecker | 2.7.0 |
| unknown | CVE-2024-41121 | Woodpecker's custom workspace allow to overwrite plugin entrypoint executable in go.woodpecker-ci.org/woodpecker | 2.7.0 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/go.woodpecker-ci.org/woodpeckerLast updated · 2023-11-09T06:08:25Z