-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
High Severity Vulnerability: CVE-2024-21538 in hydrogen-alpine #2170
Comments
EDIT: Ah, I suppose the Node.js team need to release a patch version to update the bundled npm version, which will then trigger a release of the node image... I'll reach out to them. |
@gnowland do you now when patch version will be released? |
@gnowland do you have ticket we can follow -> I mean from context of your message "I'll reach out to them". Thank you |
sorry for the delay, npm v10.9.2 was released with Node.js v23.4.0 on Tuesday (2024-12-10). |
CVE ID: GHSA-3xgq-45jj-v275
Severity: High
Affected Module: hydrogen-alpine
Description: The vulnerability allows an attacker to exploit an insecure configuration or flaw in the container to gain unauthorized access, escalate privileges, or execute arbitrary code remotely.
Recommendations:
Upgrade to the latest version of hydrogen-alpine where the issue has been fixed.
Patch the vulnerability by updating affected components in the container (e.g., dependencies).
References:
GHSA-3xgq-45jj-v275
Related advisory or patch from the maintainers, if any.
The text was updated successfully, but these errors were encountered: