Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security: CVE-2023-49569 - go-git/v5 - kube-prometheus-stack-grafana #2329

Open
mfreeman451 opened this issue Jan 11, 2024 · 0 comments
Open
Labels

Comments

@mfreeman451
Copy link

What happened?

It looks like grafana in the kube-prometheus-stack-grafana deployment has been built with a vulnerable version of the go-git/v5 library.

Specifically usr/share/grafana/bin/grafana (gobinary)

CVE-2023-49569 in github.com/go-git/go-git/v5
Severity: CRITICAL

Resource: monitoring/Deployment/kube-prometheus-stack-grafana

Installed Version: v5.4.2

Fixed Version: 5.11.0

Did you expect to see some different?

How to reproduce it (as minimally and precisely as possible):

❯ trivy image docker.io/grafana/grafana:10.2.2

Environment

  • Prometheus Operator version:

N/A

  • Kubernetes version information:

Client Version: v1.29.0
Kustomize Version: v5.0.4-0.20230601165947-6ce0bf390ce3
Server Version: v1.28.4-eks-8cb36c9

  • Kubernetes cluster kind:

EKS

  • Manifests:

NA

  • Prometheus Operator Logs:

NA

  • Prometheus Logs:

NA

Anything else we need to know?:

Screenshot 2024-01-11 at 10 28 33 AM
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant