Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

hashicorp/consul CVE-2018-19653 CVE-2020-7219 CVE-2020-13250 CVE-2020-28053 #9198

Closed
sergiodj opened this issue Apr 26, 2021 · 2 comments · Fixed by #9238
Closed

hashicorp/consul CVE-2018-19653 CVE-2020-7219 CVE-2020-13250 CVE-2020-28053 #9198

sergiodj opened this issue Apr 26, 2021 · 2 comments · Fixed by #9238
Labels
area/consul bug unexpected problem or unintended behavior security raise security concerns or improve the security of Telegraf

Comments

@sergiodj
Copy link

Security scanning revealed that the version of https://github.com/hashicorp/consul being used by telegraf is affected by the following CVEs:

https://nvd.nist.gov/vuln/detail/CVE-2018-19653
https://nvd.nist.gov/vuln/detail/CVE-2020-7219
https://nvd.nist.gov/vuln/detail/CVE-2020-13250
https://nvd.nist.gov/vuln/detail/CVE-2020-28053

Based on the details provided by all of them, it seems that it should be enough to update the dependency to either one of the following versions: 1.6.10, 1.7.10, and 1.8.6.

@sergiodj sergiodj added the bug unexpected problem or unintended behavior label Apr 26, 2021
@ssoroka ssoroka added the security raise security concerns or improve the security of Telegraf label Apr 27, 2021
@sergiodj
Copy link
Author

sergiodj commented May 7, 2021

Thanks a lot for fixing this!

Would it be possible to cut a new release containing these fixes, please? This was I can update the Ubuntu telegraf package right away :-). Thanks in advance!

@reimda
Copy link
Contributor

reimda commented May 7, 2021

Thanks a lot for fixing this!

Would it be possible to cut a new release containing these fixes, please? This was I can update the Ubuntu telegraf package right away :-). Thanks in advance!

We're planning to include them in 1.18.3, coming out around May 19. Until then you can use the package in the nightly builds: https://github.com/influxdata/telegraf/#nightly-builds

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/consul bug unexpected problem or unintended behavior security raise security concerns or improve the security of Telegraf
Projects
None yet
3 participants