Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities found for mimir:2.6.0-22.04_106 #42

Open
ROCKsBot opened this issue Dec 1, 2024 · 0 comments
Open

Vulnerabilities found for mimir:2.6.0-22.04_106 #42

ROCKsBot opened this issue Dec 1, 2024 · 0 comments

Comments

@ROCKsBot
Copy link

ROCKsBot commented Dec 1, 2024

Vulnerabilities found for mimir:2.6.0-22.04_106

ID Target Severity Package
CVE-2022-41723 /usr/bin/metaconvert HIGH golang.org/x/net
CVE-2023-39325 /usr/bin/metaconvert HIGH golang.org/x/net
GHSA-m425-mq94-257g /usr/bin/metaconvert HIGH google.golang.org/grpc
CVE-2024-24790 /usr/bin/metaconvert CRITICAL stdlib
CVE-2023-45288 /usr/bin/metaconvert HIGH stdlib
CVE-2024-34156 /usr/bin/metaconvert HIGH stdlib
CVE-2023-45142 /usr/bin/mimir HIGH go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
CVE-2022-41723 /usr/bin/mimir HIGH golang.org/x/net
CVE-2023-39325 /usr/bin/mimir HIGH golang.org/x/net
GHSA-m425-mq94-257g /usr/bin/mimir HIGH google.golang.org/grpc
CVE-2024-24790 /usr/bin/mimir CRITICAL stdlib
CVE-2023-45288 /usr/bin/mimir HIGH stdlib
CVE-2024-34156 /usr/bin/mimir HIGH stdlib
CVE-2023-45142 /usr/bin/mimirtool HIGH go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
CVE-2022-41723 /usr/bin/mimirtool HIGH golang.org/x/net
CVE-2023-39325 /usr/bin/mimirtool HIGH golang.org/x/net
GHSA-m425-mq94-257g /usr/bin/mimirtool HIGH google.golang.org/grpc
CVE-2024-24790 /usr/bin/mimirtool CRITICAL stdlib
CVE-2023-45288 /usr/bin/mimirtool HIGH stdlib
CVE-2024-34156 /usr/bin/mimirtool HIGH stdlib
CVE-2022-41723 /usr/bin/query-tee HIGH golang.org/x/net
CVE-2023-39325 /usr/bin/query-tee HIGH golang.org/x/net
GHSA-m425-mq94-257g /usr/bin/query-tee HIGH google.golang.org/grpc
CVE-2024-24790 /usr/bin/query-tee CRITICAL stdlib
CVE-2023-45288 /usr/bin/query-tee HIGH stdlib
CVE-2024-34156 /usr/bin/query-tee HIGH stdlib

Affected tracks:

  • 2.6-22.04_beta
  • 2.6-22.04_candidate
  • 2.6-22.04_edge
  • 2.6-22.04_stable
  • 2.6.0-22.04_beta
  • 2.6.0-22.04_candidate
  • 2.6.0-22.04_edge
  • 2.6.0-22.04_stable

Details: https://github.com/canonical/oci-factory/actions/runs/12101122973

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant