redpanda-data / kminion

KMinion is a feature-rich Prometheus exporter for Apache Kafka written in Go. It is lightweight and highly configurable so that it will meet your requirements.
MIT License
601 stars 123 forks source link

CVEs in kminion:v2.2.8 #265

Open rd-michel opened 3 weeks ago

rd-michel commented 3 weeks ago

What scanner and version reported the CVE?

$ gke security posture latest today

What CVE was reported in the scanner findings?

Vulnerability CVE-2023-42363 for busybox/1.36.1-r5 (alpine) Vulnerability CVE-2023-42364 for busybox/1.36.1-r5 (alpine) Vulnerability CVE-2023-42365 for busybox/1.36.1-r5 (alpine) Vulnerability CVE-2023-42366 for busybox/1.36.1-r5 (alpine) Vulnerability CVE-2024-2511 for openssl/3.1.4-r5 (alpine) Vulnerability CVE-2024-4603 for openssl/3.1.4-r5 (alpine) Vulnerability CVE-2024-4741 for openssl/3.1.4-r5 (alpine) Vulnerability CVE-2024-5535 for openssl/3.1.4-r5 (alpine)

What versions of kminion did you test with?

docker.io/redpandadata/kminion:v2.2.8