Skip to content

Vulnerability in telegraf dependency #9657

@gracewehner

Description

@gracewehner

I have a docker image using the linux arm64 telegraf executable and am using trivy to scan this image for vulnerabilities.

I am seeing this CVE for the telegraf dependency github.com/apache/thrift:
telegraf-vuln

I checked that this still exists in the latest telegraf version 1.19.3. The thrift vulnerability is fixed in 0.14.0. Please consider bumping the version of this dependency. Thanks!

Metadata

Metadata

Assignees

Labels

bugunexpected problem or unintended behaviordependenciesPull requests that update a dependency file

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions