grafana / loki

Like Prometheus, but for logs.
https://grafana.com/loki
GNU Affero General Public License v3.0
22.71k stars 3.3k forks source link

Fix CVE-2024-35255 - github.com/Azure/azure-sdk-for-go/sdk/azidentity #13334

Open rgoltz opened 5 days ago

rgoltz commented 5 days ago

Is your feature request related to a problem? Please describe. The current grafana loki docker image seems to be affected by Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability. It's tested with Loki version main-4eb45cc branch main revision 4eb45cc58

Describe the solution you'd like

Details from Image-Scan
Vulnerability ID https://nvd.nist.gov/vuln/detail/CVE-2024-35255
GitHub Advisory https://github.com/advisories/GHSA-m5vv-6r4h-3vj9
CWE https://cwe.mitre.org/data/definitions/362.html
Severity Medium
Fix available Yes
Installed version v1.5.2
Fix available v1.6.0
Package Manager GOBINARY
File paths usr/bin/loki