-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Closed
Milestone
Description
Bug Report
Describe the bug
The following published vulnerabilities applicable to c-ares library can be fixed by upgrading c-ares library in fluent-bit project from 1.19.0 to 1.19.1:
https://nvd.nist.gov/vuln/detail/CVE-2023-31130
https://nvd.nist.gov/vuln/detail/CVE-2023-32067
https://nvd.nist.gov/vuln/detail/CVE-2023-31147
https://nvd.nist.gov/vuln/detail/CVE-2023-31124
To Reproduce
4 CVE vulnerabilities present in fluent-bit version 2.1.5.
See https://github.com/fluent/fluent-bit/blob/v2.1.5/cmake/libraries.cmake#L22
Expected behaviour
Future fluent-bit version 2.1.6 contains c-ares library 1.19.1 which fixes above mentioned vulnerabilities.
SvenScheurer
Metadata
Metadata
Assignees
Labels
No labels