-
Notifications
You must be signed in to change notification settings - Fork 2.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security Vulnerabilities in Alertmanager v0.27.0 #4167
Comments
Here are some new ones, also appearing to be unfixed in v0.27.0 as well as v0.28.0-rc.0.
|
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
We see these Vulnerabilities from AquaScan results for prometheus/alertmanager:v0.27.0
Name Resource Custom Severity Severity Score Fix Version
CVE-2023-42366 busybox medium 5.5 None
CVE-2023-42364 busybox medium 5.5 None
CVE-2023-42363 busybox medium 5.5 None
CVE-2023-42365 busybox medium 5.5 None
GHSA-mh55-gqvf-xfwm github.com/rs/cors medium 0 1.11.0
CVE-2023-45288 golang.org/x/net high 7.5 0.23.0
CVE-2023-45288 golang.org/x/net high 7.5 0.23.0
CVE-2024-24786 google.golang.org/protobuf high 7.5 1.33.0
CVE-2024-24786 google.golang.org/protobuf high 7.5 1.33.0
Alertmanager version:
Alertmanager v0.27.0
Prometheus version:
Prometheus version v3.0.1
Prometheus-operator-v0.79.0
Please let us know if there is a plan to address these in upcoming versions
The text was updated successfully, but these errors were encountered: