Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

hashicorp/consul CVE-2021-32574 #9559

Closed
sergiodj opened this issue Jul 29, 2021 · 2 comments · Fixed by #9565
Closed

hashicorp/consul CVE-2021-32574 #9559

sergiodj opened this issue Jul 29, 2021 · 2 comments · Fixed by #9565
Labels
area/consul bug unexpected problem or unintended behavior

Comments

@sergiodj
Copy link

Security scanning revealed that telegraf may be affected by https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32574. This CVE affects HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0; telegraf uses:

github.com/hashicorp/consul/api v1.8.1

I'm not entirely sure whether the CVE affects the api component as well, but I thought I'd report the bug anyway. According to the CVE note, it has been fixed in hashicorp/consul version 1.8.14.

@sergiodj sergiodj added the bug unexpected problem or unintended behavior label Jul 29, 2021
@srebhan
Copy link
Member

srebhan commented Jul 30, 2021

Should we update to v1.8.1 or rather to v1.9.1 directly? @reimda what do you think?

@helenosheaa
Copy link
Member

We are currently on hashicorp/consul/api v1.8.1, it's not clear if the CVEs from hashicorp/consul relates to the api component. I've put in a PR for us to move to v1.9.1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/consul bug unexpected problem or unintended behavior
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants