albertodonato / query-exporter

Export Prometheus metrics from SQL queries
GNU General Public License v3.0
436 stars 101 forks source link

Security Vulnerability CVE2023-4911 detected by scanners #163

Closed dmitridou closed 8 months ago

dmitridou commented 10 months ago

In the latest docker image (2.9.0) a security scanner has identified a vulnerability CVE2023-4911 described here: https://access.redhat.com/security/cve/cve-2023-4911

Could you please let me know if you are planning releasing an updated image?

albertodonato commented 10 months ago

Can you please provide a link to the report from the security scanner? Also, I've published 2.9.1 which has been rebuilt from latest dependencies. Can you confirm the issue is solved?

dmitridou commented 10 months ago

Alberto, Thank you for fixing the image, I will update our local instance and wait for the next scanner results. Unfortunately, we are talking about internal security scans, whose results aren't available for access from outside of the network. I will keep you posted on the outcome. Thanks again.

Dmitri

On Sat, Oct 28, 2023 at 10:46 AM Alberto Donato @.***> wrote:

Can you please provide a link to the report from the security scanner? Also, I've published 2.9.1 which has been rebuilt from latest dependencies. Can you confirm the issue is solved?

— Reply to this email directly, view it on GitHub https://github.com/albertodonato/query-exporter/issues/163#issuecomment-1783835314, or unsubscribe https://github.com/notifications/unsubscribe-auth/ALX7XUD6WYYP74KBDRI72LTYBULEVAVCNFSM6AAAAAA6PZ36J6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMYTOOBTHAZTKMZRGQ . You are receiving this because you authored the thread.Message ID: @.***>

albertodonato commented 8 months ago

I'm closing this as it should be fixed. Please reopen with new info if it's still happening.