Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

PRISMA-2023-0056 Reported from Twistlock #20605

Open
dpericaxon opened this issue Feb 13, 2024 · 2 comments
Open

PRISMA-2023-0056 Reported from Twistlock #20605

dpericaxon opened this issue Feb 13, 2024 · 2 comments

Comments

@dpericaxon
Copy link

Hello, we ran a twistlock scan and got this finding:

CVE: PRISMA-2023-0056
Image: hashicorp/consul:1.17.2
Description: The github.com/sirupsen/logrus module of all versions is vulnerable to denial of service. Logging more than 64kb of data in a single entry without newlines causes the log writer function to hang indefinitely.
Distro: alpine-3.18.5
Package: github.com/sirupsen/logrus v1.9.0
Package Path: /bin/consul
Info: sirupsen/logrus#1370

I think its coming from here: https://github.com/hashicorp/consul/blob/main/go.mod#L250

Are there plans to bump this dependency?

@sarah-oloumi
Copy link

Its been sometime and this is still being detected in v1.19.x of consul. I wanted to see if there are any updates on this?

@tian-ma
Copy link

tian-ma commented Dec 27, 2024

The PR #21932 is not merged. I don't know who to contact to help push this

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants