MongoDB Tools affected by 3 Go stdlib vulnerabilities

XMLWordPrintableJSON

    • Type: Question
    • Resolution: Unresolved
    • Priority: Major - P3
    • None
    • Affects Version/s: None
    • Component/s: None
    • None
    • Tools and Replicator
    • 525

      Our scanning indicates that the MongoDB Tools are affected by 3 (as of this writing) vulnerabilities in the Go stdlib:

      These have been confirmed with govulncheck.

      I see the tools are compiled using Go 1.21, which is no longer supported since Go 1.23 was released (2 months ago).  Thus, you will need to upgrade Go to 1.22.7+, or 1.23.1+ to resolve these vulnerabilities.

            Assignee:
            Unassigned
            Reporter:
            Ben Foster
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated: