Skip to content

synopsis security scanning is reporting these vulnerabilities with telegraf executable #7981

@matts19

Description

@matts19

Supposedly /usr/bin/telegraf binary is including the vulnerable versions of github, etcd and moby.

At first these looked like false positives since I thought it had nothing to do with them, but I found that these may be input plugins whereby telegraf might have taken code from these products.

For example this is a docker (moby) input plugin and it is old enough to have vulnerabilities: https://github.com/influxdata/telegraf/tree/release-1.7/plugins/inputs/docker

I'd be great to have them updated to the latest versions or clarify them as some vulnerabilities have a high CVSSv3 score.

Firefox_Screenshot_2020-08-13T20-33-42 015Z

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions