Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

High Software vulnerability issue in thanos because of busybox #4167

Closed
hariyada opened this issue May 4, 2021 · 4 comments · Fixed by #4171
Closed

High Software vulnerability issue in thanos because of busybox #4167

hariyada opened this issue May 4, 2021 · 4 comments · Fixed by #4171
Assignees

Comments

@hariyada
Copy link

hariyada commented May 4, 2021

Hi All,

Thanos latest version is having high software vulnerability issue because of busy-box which was come as part of black duck binary software analysis

issue reported : https://nvd.nist.gov/vuln/detail/CVE-2021-28831

note: prometheus also faced it and fixed it like this prometheus/graphite_exporter#154

@wiardvanrij
Copy link
Member

Thank you for reporting! I'll look into this

@wiardvanrij wiardvanrij self-assigned this May 4, 2021
@wiardvanrij
Copy link
Member

Actually, I've been pointed that we already use the latest. In the build the sha in the Makefile is used. However I guess it's fine to update the base as-well. :D

@hariyada
Copy link
Author

hariyada commented May 5, 2021

@wiardvanrij thank you very much, any idea when will be the new version available?

@wiardvanrij
Copy link
Member

@wiardvanrij thank you very much, any idea when will be the new version available?

I actually edited something that as no effect basically :D - The hash was already updated in our Makefile. The latest Thanos releases already have the latest busybox version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants