-
Bug
-
Resolution: Won't Do
-
Major
-
ACM 2.7.7
-
1
-
False
-
None
-
False
-
-
-
Critical
-
No
Description of problem:
Need to ensure that CVE-2023-45288 is patched for all App/Cluster LC images:
upgrade go pkg golang.org/x/net to v0.23.0 or above
Observability Repos:
https://github.com/stolostron/multicluster-observability-operator
https://github.com/stolostron/observatorium-operator/
https://github.com/stolostron/observatorium
https://github.com/stolostron/thanos-receive-controller
https://github.com/stolostron/thanos
https://github.com/stolostron/kube-rbac-proxy
https://github.com/stolostron/kube-state-metrics
https://github.com/stolostron/prometheus
https://github.com/stolostron/prometheus-operator
https://github.com/stolostron/prometheus-alertmanager
https://github.com/stolostron/node-exporter
https://github.com/stolostron/grafana
https://github.com/stolostron/kube-thanos
Version-Release number of selected component (if applicable):
How reproducible:
Steps to Reproduce:
- ...
Actual results:
Expected results:
Additional info:
- clones
-
ACM-12260 [release-2.8] Observability: fix CVE-2023-45288 if necessary
- Closed