Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Two risks found in image oneagent deployed with dynatrace-operator #3945

Closed
kapsonic opened this issue Oct 17, 2024 · 1 comment
Closed

Two risks found in image oneagent deployed with dynatrace-operator #3945

kapsonic opened this issue Oct 17, 2024 · 1 comment
Labels
support request request for further assistance with an issue

Comments

@kapsonic
Copy link

We use a CVE scanner to scan all the images of our environment.
For oneagent with tag latest, we found two CVE reported on date 14 Oct 24.

  • CVE-2024-48958: execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
  • CVE-2024-48957: execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

Is the component impacted by these CVEs?
Are there any fix available or any recommendation for these.

@luhi-DT luhi-DT added the support request request for further assistance with an issue label Oct 18, 2024
Copy link
Contributor

Thank you for opening a Dynatrace Operator Issue. We've identified and tagged the issue as a "Support request".

Dynatrace responds to requests like these via Dynatrace ONE support rather than Github. This helps our team respond as quickly as possible using the support team's tools and procedures.

Thanks for your help!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
support request request for further assistance with an issue
Projects
None yet
Development

No branches or pull requests

2 participants