MongoDB Tools affected by 3 Go stdlib vulnerabilities

XMLWordPrintableJSON

    • Type: Question
    • Resolution: Unresolved
    • Priority: Major - P3
    • None
    • Affects Version/s: None
    • Component/s: None
    • None
    • Tools and Replicator
    • 268

      Our scanning indicates that the MongoDB Tools are affected by 3 (as of this writing) vulnerabilities in the Go stdlib:

      These have been confirmed with govulncheck.

      I see the tools are compiled using Go 1.21, which is no longer supported since Go 1.23 was released (2 months ago).  Thus, you will need to upgrade Go to 1.22.7+, or 1.23.1+ to resolve these vulnerabilities.

              Assignee:
              Unassigned
              Reporter:
              Ben Foster
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: