Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade logrus in branch/v12 and branch/v13 #36194

Closed
programmerq opened this issue Jan 2, 2024 · 0 comments
Closed

Upgrade logrus in branch/v12 and branch/v13 #36194

programmerq opened this issue Jan 2, 2024 · 0 comments
Labels

Comments

@programmerq
Copy link
Contributor

PRISMA-2023-0056 sirupsen/logrus#1370

The teleport 12.x and 13.x binaries all have github.com/sirupsen/logrus v1.9.0, which means that vulnerability scanners will list PRISMA-2023-0056.

CVE			PACKAGE NAME			SEVERITY	ACTIONABLE	PACKAGE VERSION	PATH			LAYER		FIXED IN VERSION
PRISMA-2023-0056	github.com/sirupsen/logrus	Medium		TRUE		v1.9.0		/usr/local/bin/tbot	Unidentified	fixed in v1.9.3

Current latest patch releases, at the time the issue was opened: 13.4.14, 12.4.32

Starting in Teleport 14.0.0, the logrus version is v1.9.3, so branch/v14 is not affected.

I do not know whether PRISMA-2023-0056 really impacts Teleport, but it does trigger some security scans. I couldn't find a CVE that corresponds to this identifier, so it may only be caught by some scanners.

@programmerq programmerq added the bug label Jan 2, 2024
zmb3 added a commit that referenced this issue Jan 2, 2024
Addresses PRISMA-2023-0056

Updates #36194
zmb3 added a commit that referenced this issue Jan 2, 2024
Addresses PRISMA-2023-0056

Updates #36194
github-merge-queue bot pushed a commit that referenced this issue Jan 2, 2024
Addresses PRISMA-2023-0056

Updates #36194
github-merge-queue bot pushed a commit that referenced this issue Jan 3, 2024
Addresses PRISMA-2023-0056

Updates #36194
@zmb3 zmb3 closed this as completed Jan 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants