postgres_exporter icon indicating copy to clipboard operation
postgres_exporter copied to clipboard

Require a new Release to resolve vulnerabilities

Open drushtant17 opened this issue 1 year ago • 5 comments

Hi Team, below are the CVE's vulnerable for postgres_exporter image.

  1. CVE-2023-48795 : Vulnerable library - golang.org/x/crypto with a version v0.14.0
  2. CVE-2024-24786 : Vulnerable library - google.golang.org/protobuf with a version v1.31.0
  3. CVE-2023-45288 : Vulnerable library - golang.org/x/net with a version v0.17.0

We can see upgraded versions for these libraries in master branch, so we require a release. The last version was released on 6 November 2023. Since then there are no updates. Can someone please take a look at it. Please consider a JIRA from our end - https://jira.cloudera.com/browse/DSE-36793

drushtant17 avatar May 15 '24 11:05 drushtant17

Please also update to a golang version without CVE https://nvd.nist.gov/vuln/detail/CVE-2024-24790 or https://github.com/golang/go/issues/67680

JohnFrampton avatar Jun 26 '24 07:06 JohnFrampton

I would also very much appreciate a bugfix update :-)

JohnFrampton avatar Jul 08 '24 08:07 JohnFrampton

Can someone please take look on this issue and provide the updates. We would like to know the release date of next version

drushtant17 avatar Jul 09 '24 06:07 drushtant17

Hi, any news here? Would be really great to have patch release with vulnerability fixes.

zagr0 avatar Sep 26 '24 18:09 zagr0

Hi there! Any news?

n-rodriguez avatar Oct 22 '24 22:10 n-rodriguez

Bumping, we need this too please and don't want to build it our own.

jonasbadstuebner avatar Oct 29 '24 15:10 jonasbadstuebner

any news about this issue ?

l00ptr avatar Nov 08 '24 13:11 l00ptr

#1088 will prepare a new release. Looks like the libraries have been updated in go.mod beyond what was originally reported here so I believe the new release will include the fixes.

sysadmind avatar Nov 10 '24 20:11 sysadmind

v0.16.0 has been released

sysadmind avatar Nov 10 '24 21:11 sysadmind

@sysadmind what about the other PRs that have been waiting for months?

n-rodriguez avatar Nov 11 '24 08:11 n-rodriguez