-
Notifications
You must be signed in to change notification settings - Fork 484
Open
Description
Hi team,
I got the following dependency from Twistlock scan:
CVE: PRISMA-2023-0056
Description: The github.com/sirupsen/logrus module of all versions is vulnerable to denial of service. Logging more than 64kb of data in a single entry without newlines causes the log writer function to hang indefinitely.
Vulnerability link: sirupsen/logrus#1370
Image: kapacitor:1.7.5
ID: sha256:35a44c142f039870ab89373fb64c5e1f41c60875ecdffae765e02ca83d6aa6ac
Type: go
Package: github.com/sirupsen/logrus
Package path: /usr/bin/kapacitord
Package version: v1.8.1
Impacted versions: <v1.9.3
I think its coming from here: https://github.com/influxdata/kapacitor/blob/master/go.mod#L226
Are there plans to fix this dependency?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels