—
GO-2022-1132
Grafana's default installation of `synthetic-monitoring-agent` exposes sensitive information in github.com/grafana/synthetic-monitoring-agent
Quick fix
GO-2022-1132 — github.com/grafana/synthetic-monitoring-agent: upgrade to the fixed version with the command below.
go get github.com/grafana/synthetic-monitoring-agent@v0.12.0Details
Grafana's default installation of `synthetic-monitoring-agent` exposes sensitive information in github.com/grafana/synthetic-monitoring-agent
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/synthetic-monitoring-agent
Introduced in:
0Fixed in: 0.12.0Fix
go get github.com/grafana/synthetic-monitoring-agent@v0.12.0References
- https://github.com/grafana/synthetic-monitoring-agent/security/advisories/GHSA-9j4f-f249-q5w8[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2022-46156[ADVISORY]
- https://github.com/grafana/synthetic-monitoring-agent/commit/d8dc7f9c1c641881cbcf0a09e178b90ebf0f0228[FIX]
- https://github.com/grafana/synthetic-monitoring-agent/pull/373[FIX]
- https://github.com/grafana/synthetic-monitoring-agent/pull/374[FIX]
- https://github.com/grafana/synthetic-monitoring-agent/pull/375[FIX]
- https://github.com/grafana/synthetic-monitoring-agent/releases/tag/v0.12.0[WEB]