fluent / fluentd-kubernetes-daemonset

Fluentd daemonset for Kubernetes and it Docker image
Apache License 2.0
1.27k stars 981 forks source link

security vulnerabilities detected in Fluentd v1.15.3 using Prisma tool #1412

Closed latan9 closed 1 year ago

latan9 commented 1 year ago

Dear Elastic team, Many security vulnerabilities have been detected using Prisma tool. Please let us know how these vulnerabilities can be resolved. Below Fluentd version is being used: Fluentd : 1.15.3 Please find below the vulnerability having high severity: CVE-2021-46848 CVE-2022-42898 CVE-2020-36327 CVE-2021-43809 CVE-2021-33621 CVE-2021-43809 Please let us know the fix for above vulnerabilities.

latan9 commented 1 year ago

Please look in to the issue.

latan9 commented 1 year ago

Dear Team, If possible could you please look into this issue and provide some details on this CVE. We are stuck to release opensource Fluentd at customer end. It would be great if you provide some solution or details for customer feedback.

ashie commented 1 year ago

Although I think most of them aren't affected (because most of them aren't used in actual), some of them are unsure. So I'm now working on updating the image: https://github.com/fluent/fluentd-kubernetes-daemonset/pull/1413

ashie commented 1 year ago

I've updated the image.

latan9 commented 1 year ago

Although I think most of them aren't affected (because most of them aren't used in actual), some of them are unsure. So I'm now working on updating the image: #1413

Thank you for your support. Please let us know if the updated image can be used instead of the previous one as I checked the image has been updated. image