Skip to content

CVE fixes #684

Open
Open
@vivekkumarchaurasia123

Description

@vivekkumarchaurasia123

What happened?:
Can anyone please upgrade Prometheus adapter to fix following CVE's

CVE-2013-4235 | MEDIUM
CVE-2016-20013 | HIGH
CVE-2016-2781 | MEDIUM
CVE-2017-11164 | HIGH
CVE-2022-3219 | LOW
CVE-2022-41409 | HIGH
CVE-2023-26604 | HIGH
CVE-2023-29383 | LOW
CVE-2023-45918 | MEDIUM
CVE-2023-50495 | MEDIUM
CVE-2023-7008 | MEDIUM
CVE-2024-2236 | MEDIUM
CVE-2024-34155 | MEDIUM
CVE-2024-34156 | HIGH
CVE-2024-34158 | HIGH
CVE-2024-45338 | HIGH
CVE-2024-45337 | HIGH

What did you expect to happen?:
Fix the CVE

Please provide the prometheus-adapter config:
NA

Please provide the HPA resource used for autoscaling:
NA

Please provide the HPA status:

Please provide the prometheus-adapter logs with -v=6 around the time the issue happened:
NA

Anything else we need to know?:

Environment:

  • prometheus-adapter version:
  • prometheus version:
  • Kubernetes version (use kubectl version):
  • Cloud provider or hardware configuration:
  • Other info:

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugCategorizes issue or PR as related to a bug.needs-triageIndicates an issue or PR lacks a `triage/foo` label and requires one.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions