You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi,
we have detected that your project may be vulnerable to Integer Overflow or Wraparound in the function of parse_required_member in the file of lib/cmetrics/src/external/protobuf-c.c . It shares similarities to a recent CVE disclosure CVE-2022-48468 in the https://github.com/protobuf-c/protobuf-c. The source vulnerability information is as follows:
Please report security issues via the policy: https://github.com/fluent/fluent-bit/security/policy
This looks to be a medium level CVE related to the version of protobuf-c used by cmetrics so needs an update to cmetrics to resolve I think then pulled in here.
Hi @Crispy-fried-chicken, yes, we have verified that this bug has been fixed upstream and a PR that updates the relevant files in cmetrics would be welcome.
Thank you for taking the time to report this issue.
Hi,
we have detected that your project may be vulnerable to Integer Overflow or Wraparound in the function of
parse_required_member
in the file oflib/cmetrics/src/external/protobuf-c.c
. It shares similarities to a recent CVE disclosure CVE-2022-48468 in the https://github.com/protobuf-c/protobuf-c.The source vulnerability information is as follows:
Would you help to check if this bug is true? If it's true, I'd like to open a PR for that if necessary. Thank you for your effort and patience!
The text was updated successfully, but these errors were encountered: