—
GO-2022-0305
Instance config inline secret exposure in Grafana in github.com/grafana/agent
Quick fix
GO-2022-0305 — github.com/grafana/agent: upgrade to the fixed version with the command below.
go get github.com/grafana/agent@v0.21.2Details
Instance config inline secret exposure in Grafana in github.com/grafana/agent
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/agent
Introduced in:
0.14.0Fixed in: 0.21.2Fix
go get github.com/grafana/agent@v0.21.2References
- https://github.com/grafana/agent/security/advisories/GHSA-9c4x-5hgq-q3wh[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2021-41090[ADVISORY]
- https://github.com/grafana/agent/commit/a5479755e946e5c7cddb793ee9adda8f5692ba11[FIX]
- https://github.com/grafana/agent/commit/af7fb01e31fe2d389e5f1c36b399ddc46b412b21[FIX]
- https://github.com/grafana/agent/pull/1152[FIX]
- https://github.com/grafana/agent/releases/tag/v0.20.1[WEB]
- https://github.com/grafana/agent/releases/tag/v0.21.2[WEB]
- https://security.netapp.com/advisory/ntap-20211229-0004[WEB]