-
Type:
Task
-
Resolution: Fixed
-
Priority:
Major - P3
-
Affects Version/s: None
-
Component/s: kerberos
BinSkim (a Microsoft binary analyzer) has identified that kerberos.js is missing Spectre mitigation and control flow guard flags.
Spectre mitigation docs: https://learn.microsoft.com/en-us/cpp/build/reference/qspectre?view=msvc-170
Control flow guard docs: https://learn.microsoft.com/en-us/cpp/build/reference/guard-enable-guard-checks?view=msvc-170
This issue affects the compliance of Visual Studio Code downstream and the general security of the binary, and is a continuation of https://github.com/mongodb-js/kerberos/pull/158.
- causes
-
MONGOSH-1881 Bump kerberos to latest
-
- Backlog
-