tomkerkhove / promitor

Bringing Azure Monitor metrics where you need them.
https://promitor.io
MIT License
248 stars 91 forks source link

CVE's asp.net for both resource-discovery and scraper #2380

Closed dpericaxon closed 9 months ago

dpericaxon commented 10 months ago

Report

It looks like there are 2 CVE's related to the Distro mariner-mariner-2.0 and package asp.net-core 7.0.8 where there appears to be a fix for them recently released. Links to the fix is below.

https://nvd.nist.gov/vuln/detail/CVE-2023-38180

https://nvd.nist.gov/vuln/detail/CVE-2023-35391

Vulnerability Information

No response

Affected Component(s)

Resource Discovery, Scraper

Affected Version(s)

All

Vulnerability Migitation

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35391

Vulnerability Fix

No response

Contact Details

No response

cb-axon commented 9 months ago

It should also be noted that CVE-2023-38180 is on CISA's Known Exploited Vulnerabilities List, with a Due date of August 30, 2023 - https://www.cisa.gov/news-events/alerts/2023/08/09/cisa-adds-one-known-exploited-vulnerability-catalog

tomkerkhove commented 9 months ago

New images are pushed, notes go up next week

tomkerkhove commented 9 months ago

Release is done: