Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-12257

Observability: fix CVE-2023-45288 if necessary

XMLWordPrintable

    Description of problem:

    Need to ensure that CVE-2023-45288 is patched for all Observability images:

    upgrade go pkg golang.org/x/net to v0.23.0 or above

    Observability Repos:

    https://github.com/stolostron/multicluster-observability-operator

    https://github.com/stolostron/observatorium-operator/ 

    https://github.com/stolostron/observatorium 

    https://github.com/stolostron/thanos-receive-controller 

    https://github.com/stolostron/thanos 

    https://github.com/stolostron/kube-rbac-proxy - already at v0.26.0

    https://github.com/stolostron/kube-state-metrics 

    https://github.com/stolostron/prometheus - already at v0.24.0

    https://github.com/stolostron/prometheus-operator 

    https://github.com/stolostron/prometheus-alertmanager 

    https://github.com/stolostron/node-exporter - already at v0.23.0

    https://github.com/stolostron/grafana 

    Version-Release number of selected component (if applicable):

    How reproducible:

    Steps to Reproduce:

    1.  
    2.  
    3. ...

    Actual results:

    Expected results:

    Additional info:

            smeduri1@redhat.com Subbarao Meduri
            smeduri1@redhat.com Subbarao Meduri
            Xiang Yin Xiang Yin
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: