Skip to content

Jaeger binaries were compiled with an older Go version which has security vulnerabilities #3514

Closed
@apm-opentt

Description

Describe the bug
Our company's internal security scan tool has found security vulnerabilities in the latest Jaeger binaries. May I request Jaeger team to uplift the Go compiler version on your build machines to the latest when building the next Jaeger release?
Here is the vulnerabilities detected:
https://nvd.nist.gov/vuln/detail/CVE-2021-41772

To Reproduce
Steps to reproduce the behavior:

  1. Use internal scanning tool to scan Go binaries

Expected behavior
No security vulnerabilities.

Screenshots

Version (please complete the following information):

  • OS: [Linux]
  • Jaeger version: [1.30.0]
  • Deployment: [Kubernetes]

What troubleshooting steps did you try?

Additional context

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions