Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

0.114.0-sumo-0 has CVE Vulnerabilities #1734

Open
lreed-mdsol opened this issue Mar 6, 2025 · 0 comments
Open

0.114.0-sumo-0 has CVE Vulnerabilities #1734

lreed-mdsol opened this issue Mar 6, 2025 · 0 comments

Comments

@lreed-mdsol
Copy link

We recently updated to the latest sumologic-otel-collector:0.114.0-sumo-0

According to Prisma there are a few significant CVE Vulnerabilities

Scan results for: image public.ecr.aws/sumologic/sumologic-otel-collector:0.114.0-sumo-0 sha256:2f4650f08b1c253fe1239ad849937bcfe608d48a0b4a413c85bafe0ee3c5e42e
Vulnerabilities
+----------------+----------+------+-------------------------------+---------+-----------------+-----------+------------+----------------------------------------------------+
|      CVE       | SEVERITY | CVSS |            PACKAGE            | VERSION |     STATUS      | PUBLISHED | DISCOVERED |                    DESCRIPTION                     |
+----------------+----------+------+-------------------------------+---------+-----------------+-----------+------------+----------------------------------------------------+
| CVE-2024-45337 | critical | 9.10 | golang.org/x/crypto/ssh       | v0.29.0 | fixed in 0.31.0 | 84 days   | < 1 hour   | Applications and libraries which misuse            |
|                |          |      |                               |         | 85 days ago     |           |            | connection.serverAuthenticate (via callback field  |
|                |          |      |                               |         |                 |           |            | ServerConfig.PublicKeyCallback) may be susceptible |
|                |          |      |                               |         |                 |           |            | to an aut...                                       |
+----------------+----------+------+-------------------------------+---------+-----------------+-----------+------------+----------------------------------------------------+
| CVE-2024-45338 | high     | 0.00 | golang.org/x/net/html         | v0.31.0 | fixed in 0.33.0 | 78 days   | < 1 hour   | An attacker can craft an input to the Parse        |
|                |          |      |                               |         | 78 days ago     |           |            | functions that would be processed non-linearly     |
|                |          |      |                               |         |                 |           |            | with respect to its length, resulting in extremely |
|                |          |      |                               |         |                 |           |            | slow par...                                        |
+----------------+----------+------+-------------------------------+---------+-----------------+-----------+------------+----------------------------------------------------+

If possible can we get an update to those Go Libs?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant