Skip to content

Update to go1.22.3 due to CVE #5681

Closed
Closed
@MisterMX

Description

What happened?

go1.22.3 fixes two critical security issues regarding the DNS resolution and code compilation on Darwin. See golang/go#67119 and golang/go#66754.

CVE: GHSA-5fq7-4mxc-535h

Google Group Announcement: https://groups.google.com/g/golang-announce/c/wkkO4P9stm0

How can we reproduce it?

n.a.

What environment did it happen in?

All Crossplane versions running go < 1.21.10 and go < 1.22.3.

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions