Skip to content

[chore]: Upgrading go version to v1.21.11#37534

Merged
mx-psi merged 2 commits into
open-telemetry:mainfrom
MovieStoreGuy:msg/chore-upgrade-min-go-version
Jan 28, 2025
Merged

[chore]: Upgrading go version to v1.21.11#37534
mx-psi merged 2 commits into
open-telemetry:mainfrom
MovieStoreGuy:msg/chore-upgrade-min-go-version

Conversation

@MovieStoreGuy

Copy link
Copy Markdown
Contributor

Description

Vulnerability #1: GO-2025-3420
Sensitive headers incorrectly sent after cross-domain redirect in net/http
More info: https://pkg.go.dev/vuln/GO-2025-3420
Standard library
Found in: net/http@go1.22.8
Fixed in: net/http@go1.22.11
Example traces found:
Error: #1: codeowners.go:212:55: githubgen.codeownersGenerator.getGithubMembers calls github.OrganizationsService.ListMembers, which eventually calls http.Client.Do

Vulnerability #2: GO-2025-3373
Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509
More info: https://pkg.go.dev/vuln/GO-2025-3373
Standard library
Found in: crypto/x509@go1.22.8
Fixed in: crypto/x509@go1.22.11
Example traces found:

Related: open-telemetry/opentelemetry-collector#12197

@MovieStoreGuy MovieStoreGuy requested a review from a team as a code owner January 28, 2025 08:16
@MovieStoreGuy MovieStoreGuy added the Skip Changelog PRs that do not require a CHANGELOG.md entry label Jan 28, 2025
@mx-psi mx-psi merged commit eeb4eb9 into open-telemetry:main Jan 28, 2025
@github-actions github-actions Bot added this to the next release milestone Jan 28, 2025
zeck-ops pushed a commit to zeck-ops/opentelemetry-collector-contrib that referenced this pull request Apr 23, 2025
#### Description

Vulnerability open-telemetry#1: GO-2025-3420
Sensitive headers incorrectly sent after cross-domain redirect in
net/http
  More info: https://pkg.go.dev/vuln/GO-2025-3420
  Standard library
    Found in: net/http@go1.22.8
    Fixed in: net/http@go1.22.11
    Example traces found:
Error: open-telemetry#1: codeowners.go:212:55:
githubgen.codeownersGenerator.getGithubMembers calls
github.OrganizationsService.ListMembers, which eventually calls
http.Client.Do

Vulnerability open-telemetry#2:
GO-[20](https://github.com/open-telemetry/opentelemetry-collector-contrib/actions/runs/13003223509/job/36265594395?pr=37492#step:6:21)25-3373
Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509
  More info: https://pkg.go.dev/vuln/GO-2025-3373
  Standard library
Found in:
crypto/x509@go1.[22](https://github.com/open-telemetry/opentelemetry-collector-contrib/actions/runs/13003223509/job/36265594395?pr=37492#step:6:23).8
    Fixed in: crypto/x509@go1.22.11
    Example traces found:

Related:
open-telemetry/opentelemetry-collector#12197
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Skip Changelog PRs that do not require a CHANGELOG.md entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants