Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open security vulnerabilities on the latest fluent-bit version #9808

Open
mansingcollis opened this issue Jan 8, 2025 · 1 comment
Open

Comments

@mansingcollis
Copy link

There are a few vulnerabilities detected against the latest version i.e. with the Trivy Scan Tool. The list is as below. Do you have any plans to remediate in the immediate future, please?
High: CVE-2024-26462 (Library: libgssapi-krb5-2, libk5crypto3, libkrb5-3, libkrb5support0)
High: CVE-2023-2953
Critical: CVE-2023-45853

Thanks.

@patrick-stephens
Copy link
Contributor

patrick-stephens commented Jan 8, 2025

All of these are marked as won't fix and from the base image. Fluent Bit cannot resolve them and the upstream maintainers have indicated they will not fix them for whatever reason. I would have a look at the analysis for them to check the impact and mitigation.

If it is an issue for you I would suggest building from source and disabling the relevant plugins that need those libraries along with removing them from the base image.

Please also reach out for security issues via the policy: https://github.com/fluent/fluent-bit/security/policy

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants