Skip to content
This repository was archived by the owner on Jul 18, 2025. It is now read-only.

Conversation

atomist[bot]
Copy link
Contributor

@atomist atomist bot commented Jun 23, 2022

This pull request updates package pcre2 from version 10.36-r0 to 10.36-r1 in order to fix vulnerability CVE-2022-1587.


CVE-2022-1587

Severity CRITICAL - CVSS 9.1

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.


File changed:

 [atomist:generated]
 [atomist-skill:atomist/docker-vulnerability-policy]

Signed-off-by: Atomist Bot <[email protected]>
@atomist atomist bot added auto-merge-method:merge Auto-merge with merge commit auto-merge:on-approve Auto-merge on review approvals auto-branch-delete:on-close Delete branch when pull request gets closed labels Jun 23, 2022
@atomist
Copy link
Contributor Author

atomist bot commented Jun 23, 2022

Vulnerabilities
Comparison

🚨 Adds 1 critical and 5 high severity vulnerabilities compared with unstable

💡 Rebase branch atomist/fix-cve-2022-1587/docker/dockerfile to include latest changes from branch main to increase accuracy of vulnerability report


More details are available in the vulnerability report

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge:on-approve Auto-merge on review approvals auto-merge-method:merge Auto-merge with merge commit

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant