Skip to content

templated/CVE-2026-41179 - #248

Open
dyeddala wants to merge 1 commit into
google:mainfrom
dyeddala:feature/CVE-2026-41179
Open

templated/CVE-2026-41179#248
dyeddala wants to merge 1 commit into
google:mainfrom
dyeddala:feature/CVE-2026-41179

Conversation

@dyeddala

Copy link
Copy Markdown

Please review the PR.

@robert-doyensec

Copy link
Copy Markdown

Hi @dyeddala , please include a vulnerable and safe version both in the same docker compose file, along with a proof of concept (curl command or similar) in the README.md that demonstrates the expected responses for vulnerable and safe versions. There's no need to include instructions to create the docker compose file in the README, only instructions for how to run the vulnerable and safe versions using the docker-compose.yml file that already exists.

When I tested the docker compose file in the README.md file, it resulted in both services being shown as vulnerable, so it looks like it needs tweaking. For the vulnerable version, please use the one closest to the patched version (it might be 1.73.4). I think, but am not sure, that the --rc-no-auth CLI argument is why both are being reported as vulnerable from your plugin.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants