-
Notifications
You must be signed in to change notification settings - Fork 766
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
The launchpad extension has critical security vulnerabilities in the latest images #896
Comments
Ack. Thank you for sharing this. We will work on updating the golang package. |
Any update on this ? is there any deadline ? |
sorry for the delay, hopefully I should have a tentative timeline to share by end of next week. |
Hi. I am another person and team being completely paralyzed here. When giving timeline phrases... could you use exact dates and please avoid "this week" or "next week" phrases. I'm not trying to be a jerk, but I'm getting pinged twice a day on "what is the update?". Thank you for your consideration. |
@amitkh-msft I'm in the same boat. These images are being blocked by our security team and they are critical for our developers. |
(Posted 3 weeks ago) Hi. We are desperately looking for an update. We are looking to shift to postgres now because of the lack of response. I'm not trying to be nasty. I'm conveying the reality of our security department will not allow vulnerable images. |
@amitkh-msft are there any updates on the timeline? We have the same problem that several people have already described here: one of our products needs to use the mssql server image which contains the vulnerabilities stated above. |
Hi. It's coming up on 2 MONTHS since being reported. Please, can we get an update? |
Hi, I have the same problem. For our company the image is blocked by security scanners. How long will it take to fix this critical issue? |
i have stopped using mssql database, thanks to @amitkh-msft |
4 1/2 MONTHS later...we still have no update? This is embarrassing Microsoft. |
The latest image of mssql/server:2022-latest contains a file at
/opt/mssql-extensibility/bin/launchpad
which appears to be built with a very old version ofgolang
and generates a large number of critical CVE's for all of your published images.exact sha256
as of Aug 27, 2024
Details
Please rebuild the launchpad extension with a newer version of golang and publish an updated version of 2022 and 2019.
Related to
The text was updated successfully, but these errors were encountered: