Skip to content

Commit 823a6d7

Browse files
committed
pkg-vulnerabilities: add upper bound for prometheus
The current prometheus is not using the vulnerable library any longer, but I can't easily find out when that happened, so mark today's version as fixed.
1 parent 9a54dae commit 823a6d7

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

doc/pkg-vulnerabilities

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# $NetBSD: pkg-vulnerabilities,v 1.143 2024/02/27 13:37:50 tm Exp $
1+
# $NetBSD: pkg-vulnerabilities,v 1.144 2024/03/03 12:55:49 wiz Exp $
22
#
33
#FORMAT 1.0.0
44
#
@@ -21538,7 +21538,7 @@ php{56,72,73,74,80}-nextcloud<21.0.3 information-disclosure https://nvd.nist.gov
2153821538
php{56,72,73,74,80}-nextcloud<21.0.3 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2021-32680
2153921539
php{56,72,73,74,80}-nextcloud<21.0.3 remote-security-bypass https://nvd.nist.gov/vuln/detail/CVE-2021-32678
2154021540
php{56,72,73,74,80}-nextcloud<21.0.3 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2021-32679
21541-
prometheus-[0-9]* insufficiently-random-numbers https://nvd.nist.gov/vuln/detail/CVE-2021-3538
21541+
prometheus<2.50.1 insufficiently-random-numbers https://nvd.nist.gov/vuln/detail/CVE-2021-3538
2154221542
grafana-[0-9]* insufficiently-random-numbers https://nvd.nist.gov/vuln/detail/CVE-2021-3538
2154321543
apache-ant<1.9.16 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2021-36373
2154421544
apache-ant>=1.10<1.10.11 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2021-36373

0 commit comments

Comments
 (0)