Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Latest release v0.13.0 has CVE-2021-3538 (score 9.8) from dependency github.com/satori/go.uuid v1.2.0 #617

Closed
srlobo opened this issue Feb 28, 2022 · 3 comments

Comments

@srlobo
Copy link
Contributor

srlobo commented Feb 28, 2022

Hi

mysqld_exporter showed up in a security scan because it contains github.com/satori/go.uuid@v1.2.0

https://nvd.nist.gov/vuln/detail/CVE-2021-3538

github.com/satori/go.uuid is used in collector/slave_hosts.go.

Would it be possible to make a patch release on docker hub containing an updated version of this module?

@srlobo srlobo changed the title Latest release v0.13.0 has CVE-2021-3538 (score 79.8) from dependency github.com/satori/go.uuid v1.2.0 Latest release v0.13.0 has CVE-2021-3538 (score 9.8) from dependency github.com/satori/go.uuid v1.2.0 Feb 28, 2022
@SuperQ
Copy link
Member

SuperQ commented Feb 28, 2022

It looks like the vulnerability is for generating UUIDs from that library. This collector only uses the library to parse UUID from MySQL. Therefore this collector / version is not vulnerable to CVE-2021-3538.

Please do not report results from vulnerability scanners without actively verifying that there is a vulnerability. These version-based scanners often produce false-positives.

@SuperQ SuperQ closed this as completed Feb 28, 2022
@srlobo
Copy link
Contributor Author

srlobo commented Feb 28, 2022

Ok, but it's not a good idea to link to unmaintained code anyway (as told in the project discussion): satori/go.uuid#73 (comment)

They're suggesting change to https://github.com/gofrs/uuid

@SuperQ
Copy link
Member

SuperQ commented Feb 28, 2022

PRs welcome.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants