redpanda-data / kminion

KMinion is a feature-rich Prometheus exporter for Apache Kafka written in Go. It is lightweight and highly configurable so that it will meet your requirements.
MIT License
610 stars 122 forks source link

Critical CVE #169

Closed nise-wg2 closed 1 year ago

nise-wg2 commented 1 year ago

Kminion: v2.2.0 ENV VERSION=sha-2a62a9d24ca6579cc5dcf30c4f56215430162fd4

Contains critical security CVE-2022-40674, libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c., refer to https://avd.aquasec.com/nvd/2022/cve-2022-40674/

Also visible from https://quay.io/repository/cloudhut/kminion?tab=tags.

kenta2097 commented 1 year ago

Hi @weeco

We are really interested in using your Kafka exporter but we can't due to the vulnerabilities in the image as breaks our security policy.

https://quay.io/repository/cloudhut/kminion/manifest/sha256:216c5383168b60f0797dbeb06bd6601d41ed52eb970d597492f3b1fbf944c7bd?tab=vulnerabilities

Could it be possible to have a look? seems all vulnerabilities can be solved by updating the libraries.

Regards, Alberto M