Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities found for grafana:10.0.3-22.04_49 #64

Open
ROCKsBot opened this issue Nov 30, 2024 · 0 comments
Open

Vulnerabilities found for grafana:10.0.3-22.04_49 #64

ROCKsBot opened this issue Nov 30, 2024 · 0 comments

Comments

@ROCKsBot
Copy link

ROCKsBot commented Nov 30, 2024

Vulnerabilities found for grafana:10.0.3-22.04_49

ID Target Severity Package
CVE-2023-37788 /usr/bin/grafana HIGH github.com/elazarl/goproxy
CVE-2023-49569 /usr/bin/grafana CRITICAL github.com/go-git/go-git/v5
CVE-2023-49568 /usr/bin/grafana HIGH github.com/go-git/go-git/v5
CVE-2024-1313 /usr/bin/grafana HIGH github.com/grafana/grafana
CVE-2024-1442 /usr/bin/grafana HIGH github.com/grafana/grafana
CVE-2024-8986 /usr/bin/grafana CRITICAL github.com/grafana/grafana-plugin-sdk-go
CVE-2023-47108 /usr/bin/grafana HIGH go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc
CVE-2023-45142 /usr/bin/grafana HIGH go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace
CVE-2024-45337 /usr/bin/grafana HIGH golang.org/x/crypto
CVE-2023-39325 /usr/bin/grafana HIGH golang.org/x/net
GHSA-m425-mq94-257g /usr/bin/grafana HIGH google.golang.org/grpc
CVE-2024-24790 /usr/bin/grafana CRITICAL stdlib
CVE-2023-39325 /usr/bin/grafana HIGH stdlib
CVE-2023-45283 /usr/bin/grafana HIGH stdlib
CVE-2023-45287 /usr/bin/grafana HIGH stdlib
CVE-2023-45288 /usr/bin/grafana HIGH stdlib
CVE-2024-34156 /usr/bin/grafana HIGH stdlib
CVE-2024-1313 /usr/bin/grafana-cli HIGH github.com/grafana/grafana
CVE-2024-1442 /usr/bin/grafana-cli HIGH github.com/grafana/grafana
CVE-2024-24790 /usr/bin/grafana-cli CRITICAL stdlib
CVE-2023-39325 /usr/bin/grafana-cli HIGH stdlib
CVE-2023-45283 /usr/bin/grafana-cli HIGH stdlib
CVE-2023-45287 /usr/bin/grafana-cli HIGH stdlib
CVE-2023-45288 /usr/bin/grafana-cli HIGH stdlib
CVE-2024-34156 /usr/bin/grafana-cli HIGH stdlib
CVE-2024-1313 /usr/bin/grafana-server HIGH github.com/grafana/grafana
CVE-2024-1442 /usr/bin/grafana-server HIGH github.com/grafana/grafana
CVE-2024-24790 /usr/bin/grafana-server CRITICAL stdlib
CVE-2023-39325 /usr/bin/grafana-server HIGH stdlib
CVE-2023-45283 /usr/bin/grafana-server HIGH stdlib
CVE-2023-45287 /usr/bin/grafana-server HIGH stdlib
CVE-2023-45288 /usr/bin/grafana-server HIGH stdlib
CVE-2024-34156 /usr/bin/grafana-server HIGH stdlib
CVE-2024-24790 /usr/bin/wire-v0.5.0 CRITICAL stdlib
CVE-2023-39325 /usr/bin/wire-v0.5.0 HIGH stdlib
CVE-2023-45283 /usr/bin/wire-v0.5.0 HIGH stdlib
CVE-2023-45287 /usr/bin/wire-v0.5.0 HIGH stdlib
CVE-2023-45288 /usr/bin/wire-v0.5.0 HIGH stdlib
CVE-2024-34156 /usr/bin/wire-v0.5.0 HIGH stdlib

Affected tracks:

  • 10.0-22.04_beta
  • 10.0-22.04_candidate
  • 10.0-22.04_edge
  • 10.0-22.04_stable
  • 10.0.3-22.04_beta
  • 10.0.3-22.04_candidate
  • 10.0.3-22.04_edge
  • 10.0.3-22.04_stable

Details: https://github.com/canonical/oci-factory/actions/runs/12307936207

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant