Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade-metrics-collector #457

Conversation

AlexsandroRotundo
Copy link
Contributor

@AlexsandroRotundo AlexsandroRotundo commented Mar 20, 2024

The vulnerable Python version (2.7.12) is used by the MCAC (metric collector for apache cassandra).

The CVE in the MCAC has been resolved in the following PR:
datastax/metric-collector-for-apache-cassandra#99
that completely removes the affected Python Version.

So when the new cass-management-api will be released I hope will integrate also the mitigation of the CVEs related to Python
(CVE-2022-48565 CVE-2019-9948 CVE-2019-9636 CVE-2019-10160 CVE-2018-1000802 CVE-2017-1000158 CVE-2016-9063 CVE-2016-0718)

Fixes #458

Copy link

No linked issues found. Please add the corresponding issues in the pull request description.
Use GitHub automation to close the issue when a PR is merged

Copy link
Contributor

@emerkle826 emerkle826 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for the PR. Normally we like to also include an entry in the Changelog, but I'll take care of that before the next release.

@emerkle826 emerkle826 merged commit c7f66fd into k8ssandra:master Mar 20, 2024
69 of 98 checks passed
@AlexsandroRotundo AlexsandroRotundo deleted the upgrade-metrics-collector-version branch March 21, 2024 09:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Upgrade MCAC to v0.3.5
3 participants