-
Notifications
You must be signed in to change notification settings - Fork 486
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
opentelemetry-operator/autoinstrumentation-java having Snake yaml vulnerability #1313
Comments
@Ripurwar80 in which Java auto-instrumentation image is the vulnerability? We have just published 1.21.0 https://github.com/open-telemetry/opentelemetry-operator/pkgs/container/opentelemetry-operator%2Fautoinstrumentation-java does it fixe the issue? |
CVE-2022-28391 busybox /bin/busybox high 8.8 None |
It seems that the vulnerability comes from the busybox base image. The busybox is used in java and dotnet auto-instrumentation images. |
@Ripurwar80 but could you please check if image https://github.com/open-telemetry/opentelemetry-operator/pkgs/container/opentelemetry-operator%2Fautoinstrumentation-java/59535006?tag=1.21.0 has been fixed? |
@Ripurwar80 is this still an issue? |
I actually think this is still a problem, but #1600 has more solutions proposed. |
Name Resource Resource Path Severity Score Fix Version
CVE-2022-41854 snakeyaml /javaagent.jar medium 6.5 None
The text was updated successfully, but these errors were encountered: