Skip to content

Commit

Permalink
CVE-2023-48795: metrics-server...temporal
Browse files Browse the repository at this point in the history
Signed-off-by: Philippe Deslauriers <[email protected]>
  • Loading branch information
pdeslaur committed Dec 22, 2023
1 parent 78a1258 commit 11490d3
Show file tree
Hide file tree
Showing 4 changed files with 38 additions and 2 deletions.
9 changes: 9 additions & 0 deletions metrics-server.advisories.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -166,3 +166,12 @@ advisories:
type: pending-upstream-fix
data:
note: Pending upstream fix, this fix will require some code changes due to the usage of one year old Kubernetes dependencies (e.g. k8s.io/[email protected]). These dependencies need to be updated to upgrade the vulnerable otel dependencies. In addition, the latest stable release of the metrics-server project was triggered on June.

- id: CVE-2023-48795
aliases:
- GHSA-45x7-px36-x8w8
events:
- timestamp: 2023-12-22T15:01:54Z
type: fixed
data:
fixed-version: 0.6.4-r9
11 changes: 10 additions & 1 deletion prometheus-mongodb-exporter.advisories.yaml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
schema-version: 2.0.1
schema-version: 2.0.2

package:
name: prometheus-mongodb-exporter
Expand Down Expand Up @@ -41,3 +41,12 @@ advisories:
data:
type: vulnerable-code-not-included-in-package
note: Only affects Windows

- id: CVE-2023-48795
aliases:
- GHSA-45x7-px36-x8w8
events:
- timestamp: 2023-12-22T15:02:11Z
type: fixed
data:
fixed-version: 0.40.0-r2
9 changes: 9 additions & 0 deletions temporal-server.advisories.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -37,3 +37,12 @@ advisories:
data:
note: |
We faced issues with "[email protected]/internal/transform/metricdata.go:108:18:undefined: metricdata.ExponentialHistogram" when upgrading otlpmetricgrpc to v0.46.0. It has some strict dependencies in the source code common/telemetry using an old version and thus this fix will require some code changes in upstream.
- id: CVE-2023-48795
aliases:
- GHSA-45x7-px36-x8w8
events:
- timestamp: 2023-12-22T15:02:24Z
type: fixed
data:
fixed-version: 1.22.3-r3
11 changes: 10 additions & 1 deletion temporal.advisories.yaml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
schema-version: 2.0.1
schema-version: 2.0.2

package:
name: temporal
Expand Down Expand Up @@ -50,3 +50,12 @@ advisories:
data:
note: |
We faced issues with "[email protected]/internal/transform/metricdata.go:108:18:undefined: metricdata.ExponentialHistogram" when upgrading otlpmetricgrpc to v0.46.0. It has some strict dependencies in the source code common/telemetry using an old version and thus this fix will require some code changes in upstream.
- id: CVE-2023-48795
aliases:
- GHSA-45x7-px36-x8w8
events:
- timestamp: 2023-12-22T15:02:35Z
type: fixed
data:
fixed-version: 0.10.7-r3

0 comments on commit 11490d3

Please sign in to comment.