-
Notifications
You must be signed in to change notification settings - Fork 303
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVEs found in Grafana/Oncall:v1.5.1 #4387
Comments
Tested on image 1.5.3 and CVEs are still present. What action needs to be taken for someone to upgrade the pip packages for this? |
Hey @joeyorlando what would it take to have the maintainers update dependencies in your next release? Looks like all these CVEs are present in your newer versions since I initially posted this issue. |
hey @justinhauer thanks for bringing this to the team's attention! we'll take a look at this soon 🙂 |
Thank you @joeyorlando, and the other onCall contributors for all the excellent work you do! You are appreciated 🙂 |
@justinhauer do you mind running the scan you ran against the latest version (v1.6.2 as of this writing). Some of these should be fixed: Additionally, #4495 should address the I'll go ahead and mark this issue as closed once #4495 is merged, but feel free to open a new issue if they're several HIGH/CRITICAL CVEs once the version containing that change is published |
@joeyorlando I will scan again tomorrow, if more high or critical CVEs are found I'll put in a new issue since this one is closed. Thanks! |
@joeyorlando there are still High CVEs unresolved in the 1.7.0 release: |
@justinhauer this will be patched in #4516, thanks for pointing this out! |
What went wrong?
What happened:
Scan Results:
Target
image.tar (alpine 3.18.3)
No Vulnerabilities found
No Misconfigurations found
Target
Python
Vulnerabilities (15)
PyMySQL
cryptography
cryptography
cryptography
cryptography
cryptography
cryptography
cryptography
cryptography
cryptography
idna
pip
sqlparse
uWSGI
uWSGI
No Misconfigurations found
What did you expect to happen:
How do we reproduce it?
Grafana OnCall Version
v1.5.1
Product Area
Other
Grafana OnCall Platform?
Other
User's Browser?
No response
Anything else to add?
Please consider security being top of mind. Please run pip upgrade on dependencies so vulnerable libraries are remediated in your next release.
The text was updated successfully, but these errors were encountered: