hipages / php-fpm_exporter

A prometheus exporter for PHP-FPM.
Apache License 2.0
592 stars 119 forks source link

libcrypto and libssl CVEs #186

Closed BrianKopp closed 2 years ago

BrianKopp commented 2 years ago

The latest docker image (2.0.3) currently contains Critical and High CVEs (CVE-2021-3711) and (CVE-2021-3712) in libcrypto and libssl. These should be fixed in the latest version of the base image alpine.

https://nvd.nist.gov/vuln/detail/CVE-2021-3711

https://nvd.nist.gov/vuln/detail/CVE-2021-3712

estahn commented 2 years ago

@BrianKopp Thanks for reporting this.

estahn commented 2 years ago

@BrianKopp This should be fixed in https://github.com/hipages/php-fpm_exporter/releases/tag/v2.0.4