Skip to content

(CVE) Request upgrade c-ares library to 1.19.1 #7595

@giancorderoortiz

Description

@giancorderoortiz

Bug Report

Describe the bug
The following published vulnerabilities applicable to c-ares library can be fixed by upgrading c-ares library in fluent-bit project from 1.19.0 to 1.19.1:

https://nvd.nist.gov/vuln/detail/CVE-2023-31130
https://nvd.nist.gov/vuln/detail/CVE-2023-32067
https://nvd.nist.gov/vuln/detail/CVE-2023-31147
https://nvd.nist.gov/vuln/detail/CVE-2023-31124

To Reproduce

4 CVE vulnerabilities present in fluent-bit version 2.1.5.
See https://github.com/fluent/fluent-bit/blob/v2.1.5/cmake/libraries.cmake#L22

Expected behaviour

Future fluent-bit version 2.1.6 contains c-ares library 1.19.1 which fixes above mentioned vulnerabilities.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions