Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

gogo protobuf CVE-2021-3121 (< 1.3.2) #9181

Closed
sergiodj opened this issue Apr 23, 2021 · 4 comments · Fixed by #9190
Closed

gogo protobuf CVE-2021-3121 (< 1.3.2) #9181

sergiodj opened this issue Apr 23, 2021 · 4 comments · Fixed by #9190
Assignees
Labels
bug unexpected problem or unintended behavior

Comments

@sergiodj
Copy link

The gogo protobuf module in the version that is being used by telegraf (1.3.1) has a CVE:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3121

The vulnerability has been fixed in version 1.3.2. Please consider bumping the version of this dependency. Thanks!

@sergiodj sergiodj added the bug unexpected problem or unintended behavior label Apr 23, 2021
@helenosheaa
Copy link
Member

Thanks for opening this issue, I'll look into upgrading the dependency!

@sergiodj
Copy link
Author

Thanks @helenosheaa!

@Emeka-MSFT
Copy link

@helenosheaa , the go.sum file contains references to the older protobuf versions.

Does this mean that Telegraf depends on components that required/use the older/vulnerable versions?

If this is correct, then would these Telegraf dependencies need to be updated as well?

@Emeka-MSFT
Copy link

Opened #10581

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug unexpected problem or unintended behavior
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants