-
Notifications
You must be signed in to change notification settings - Fork 3.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix CVE-2024-6104 - github.com/hashicorp/go-retryablehttp #13335
Comments
Thanks, @vlad-diachenko - It seems that PR #13835 updated the go library of Great! Thanks a lot 🥇. If somebody from the team can confirm, myself (or you) can close this issue as successfully resolved afterwards, CC'd @DylanGuedes |
Hey @rgoltz Trivy results for the latest image
Huge thanks @rgoltz |
Is your feature request related to a problem? Please describe.
The current grafana loki docker image seems to be affected by go-retryablehttp can leak basic auth credentials to log files Vulnerability. It's tested with Loki version
main-4eb45cc
branchmain
revision 4eb45ccDescribe the solution you'd like
go-retryablehttp
tov0.7.7
or aboveDetails from Image-Scan
The text was updated successfully, but these errors were encountered: