Skip to content

Require a new Release to resolve vulnerabilities #1034

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
drushtant17 opened this issue May 15, 2024 · 10 comments
Closed

Require a new Release to resolve vulnerabilities #1034

drushtant17 opened this issue May 15, 2024 · 10 comments

Comments

@drushtant17
Copy link

Hi Team, below are the CVE's vulnerable for postgres_exporter image.

  1. CVE-2023-48795 :
    Vulnerable library - golang.org/x/crypto with a version v0.14.0
  2. CVE-2024-24786 :
    Vulnerable library - google.golang.org/protobuf with a version v1.31.0
  3. CVE-2023-45288 :
    Vulnerable library - golang.org/x/net with a version v0.17.0

We can see upgraded versions for these libraries in master branch, so we require a release.
The last version was released on 6 November 2023. Since then there are no updates.
Can someone please take a look at it.
Please consider a JIRA from our end - https://jira.cloudera.com/browse/DSE-36793

@JohnFrampton
Copy link

Please also update to a golang version without CVE https://nvd.nist.gov/vuln/detail/CVE-2024-24790 or golang/go#67680

@JohnFrampton
Copy link

JohnFrampton commented Jul 8, 2024

I would also very much appreciate a bugfix update :-)

@drushtant17
Copy link
Author

Can someone please take look on this issue and provide the updates.
We would like to know the release date of next version

@zagr0
Copy link

zagr0 commented Sep 26, 2024

Hi, any news here? Would be really great to have patch release with vulnerability fixes.

@n-rodriguez
Copy link
Contributor

Hi there! Any news?

@jonasbadstuebner
Copy link

Bumping, we need this too please and don't want to build it our own.

@l00ptr
Copy link

l00ptr commented Nov 8, 2024

any news about this issue ?

@sysadmind
Copy link
Contributor

#1088 will prepare a new release. Looks like the libraries have been updated in go.mod beyond what was originally reported here so I believe the new release will include the fixes.

@sysadmind
Copy link
Contributor

v0.16.0 has been released

@n-rodriguez
Copy link
Contributor

@sysadmind what about the other PRs that have been waiting for months?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants