CVEs in golang binaries

Description

There are several CVEs in golang binaries:
pt-k8s-debug-collector, pt-mongodb-summary ,pt-mongodb-query-digest and pt-mongodb-index-check

Environment

None

Activity

Show:

Sveta Smirnova December 28, 2022 at 10:36 PM

Hi

thank you for the report. But Go tools are not tracked in Github for Percona Toolkit. They need to be built with Go 1.19.1 or higher in order to avoid vulnerability in golang.org/x/net. Module version in go.mod and go.sum is correct.

So I only updated version for golang.org/x/text

Done

Details

Assignee

Reporter

Priority

Affects versions

Fix versions

Needs QA

Yes

Story Points

Smart Checklist

Created December 22, 2022 at 9:22 AM
Updated February 29, 2024 at 8:43 PM
Resolved January 3, 2023 at 5:13 PM