Skip to content

hashicorp/consul CVE-2018-19653 CVE-2020-7219 CVE-2020-13250 CVE-2020-28053 #9198

Closed
@sergiodj

Description

Security scanning revealed that the version of https://github.com/hashicorp/consul being used by telegraf is affected by the following CVEs:

https://nvd.nist.gov/vuln/detail/CVE-2018-19653
https://nvd.nist.gov/vuln/detail/CVE-2020-7219
https://nvd.nist.gov/vuln/detail/CVE-2020-13250
https://nvd.nist.gov/vuln/detail/CVE-2020-28053

Based on the details provided by all of them, it seems that it should be enough to update the dependency to either one of the following versions: 1.6.10, 1.7.10, and 1.8.6.

Metadata

Assignees

No one assigned

    Labels

    area/consulbugunexpected problem or unintended behaviorsecurityraise security concerns or improve the security of Telegraf

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions