You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We have created a Windows container and we installed the SumoLogic collector v0.108.0-1649 inside.
During the container scan using Trivy, it shows it has vulnerabilities. How can I mitigate the findings?
Thank you for the issue report. The software does indeed import mholt/archiver, it is used in the "jobreceiver" module.
We'll be upgrading or replacing this dependency to resolve this issue. In the mean time, you can simply avoid the jobreceiver module in your open-telemetry configuration to mitigate any risk associated with this CVE.
Hello,
We have created a Windows container and we installed the SumoLogic collector v0.108.0-1649 inside.
During the container scan using Trivy, it shows it has vulnerabilities. How can I mitigate the findings?
https://avd.aquasec.com/nvd/cve-2024-0406
https://avd.aquasec.com/nvd/cve-2024-34156
https://avd.aquasec.com/nvd/cve-2024-34155
https://avd.aquasec.com/nvd/cve-2024-34158
Steps to reproduce
The text was updated successfully, but these errors were encountered: