Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

prometheus/prometheus CVE-2019-3826 #9199

Closed
sergiodj opened this issue Apr 26, 2021 · 3 comments
Closed

prometheus/prometheus CVE-2019-3826 #9199

sergiodj opened this issue Apr 26, 2021 · 3 comments
Labels
area/prometheus bug unexpected problem or unintended behavior

Comments

@sergiodj
Copy link

The prometheus/prometheus module used by telegraf is affected by:

https://nvd.nist.gov/vuln/detail/CVE-2019-3826

An update to version 2.7.1 or later should address the issue.

@sergiodj sergiodj added the bug unexpected problem or unintended behavior label Apr 26, 2021
@ivorybilled
Copy link
Contributor

ivorybilled commented Apr 27, 2021

Hi, thank you for the issues! looks like we're already using a later version per #8795, which says that we had upgraded to v2.21.0. If you have further concerns or that doesn't look right currently, do let us know. thanks!

@sergiodj
Copy link
Author

Thanks for the reply, @jagularr.

I confess I'm not an expert in Golang, but when I look at go.mod I see:

github.com/prometheus/prometheus v1.8.2-0.20200911110723-e83ef207b6c2

Doesn't this mean that telegraf is using prometheus v1.8.2, and not 2.7.1?

TIA!

@sergiodj
Copy link
Author

Ah, I've found prometheus/prometheus#7991 (comment), which explains why prometheus' tags are versioned differently.

I now see that the version of prometheus being used by telegraf is indeed higher than 2.7.1. I'm closing this bug, then. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/prometheus bug unexpected problem or unintended behavior
Projects
None yet
Development

No branches or pull requests

2 participants