You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your feature request related to a problem? Please describe.
The current grafana loki docker image seems to be affected by Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability. It's tested with Loki version main-4eb45cc branch main revision 4eb45cc
Thanks, @vlad-diachenko - It seems that PR #13835 updated the go library of azidentity to the fixed version. I've re-tested and pulled the main-tag: version 2.9.10, branch HEAD, revision 7664eda. I can not see any findings for this image-tag (main-tag from docker-hub - updated at Aug 9, 2024 at 8:33 pm) in my vulnerability image scanner.
Great! Thanks a lot 🥇. If somebody from the team can confirm, myself (or you) can close this issue as successfully resolved afterwards, CC'd @DylanGuedes
Is your feature request related to a problem? Please describe.
The current grafana loki docker image seems to be affected by Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability. It's tested with Loki version
main-4eb45cc
branchmain
revision 4eb45ccDescribe the solution you'd like
azidentity
tov1.6.0
or aboveDetails from Image-Scan
The text was updated successfully, but these errors were encountered: