Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities found for prometheus:2.47.2-22.04_98 #93

Open
ROCKsBot opened this issue Dec 2, 2024 · 0 comments
Open

Vulnerabilities found for prometheus:2.47.2-22.04_98 #93

ROCKsBot opened this issue Dec 2, 2024 · 0 comments

Comments

@ROCKsBot
Copy link

ROCKsBot commented Dec 2, 2024

Vulnerabilities found for prometheus:2.47.2-22.04_98

ID Target Severity Package
CVE-2024-41110 /usr/bin/prometheus CRITICAL github.com/docker/docker
CVE-2023-45142 /usr/bin/prometheus HIGH go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
CVE-2024-45337 /usr/bin/prometheus HIGH golang.org/x/crypto
CVE-2023-39325 /usr/bin/prometheus HIGH golang.org/x/net
GHSA-m425-mq94-257g /usr/bin/prometheus HIGH google.golang.org/grpc
CVE-2024-24790 /usr/bin/prometheus CRITICAL stdlib
CVE-2023-45288 /usr/bin/prometheus HIGH stdlib
CVE-2024-34156 /usr/bin/prometheus HIGH stdlib
CVE-2024-41110 /usr/bin/promtool CRITICAL github.com/docker/docker
CVE-2023-45142 /usr/bin/promtool HIGH go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
CVE-2024-45337 /usr/bin/promtool HIGH golang.org/x/crypto
CVE-2023-39325 /usr/bin/promtool HIGH golang.org/x/net
GHSA-m425-mq94-257g /usr/bin/promtool HIGH google.golang.org/grpc
CVE-2024-24790 /usr/bin/promtool CRITICAL stdlib
CVE-2023-45288 /usr/bin/promtool HIGH stdlib
CVE-2024-34156 /usr/bin/promtool HIGH stdlib

Affected tracks:

  • 2.47-22.04_beta
  • 2.47-22.04_candidate
  • 2.47-22.04_edge
  • 2.47-22.04_stable
  • 2.47.2-22.04_beta
  • 2.47.2-22.04_candidate
  • 2.47.2-22.04_edge
  • 2.47.2-22.04_stable

Details: https://github.com/canonical/oci-factory/actions/runs/12307936207

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant