Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multiple High CVEs addressed in cpe:2.3:a:postgresql:postgresql, Version: 10.21 #21188

Open
mikebou opened this issue Nov 29, 2023 · 1 comment

Comments

@mikebou
Copy link

mikebou commented Nov 29, 2023

Our security team is flagging the current Datadog agent build for 3 High Severity CVEs that have been addressed in the cpe:2.3:a:postgresql:postgresql, Version: 10.19 library.

Our corporate policy is to address High and Critical CVEs within 90 days of a released fix.

    CVE-2022-1552, Severity: HIGH, Source: https://nvd.nist.gov/vuln/detail/CVE-2022-1552
        CVSS score: 8.8, CVSS exploitability score: 2.8
        Fixed version: 10.21
        Grace period expired 
    CVE-2022-2625, Severity: HIGH, Source: https://nvd.nist.gov/vuln/detail/CVE-2022-2625
        CVSS score: 8, CVSS exploitability score: 2.1
        Fixed version: 10.22
        Grace period expired
    CVE-2023-32305, Severity: HIGH, Source: https://nvd.nist.gov/vuln/detail/CVE-2023-32305
        CVSS score: 8.8, CVSS exploitability score: 2.8
        Fixed version: 10.23
        Grace period expired

Please update the agent with at least 10.23 to address these resolved CVEs.

@cvirtucio
Copy link

version 7.50 of the datadog-agent doesn't include the postgres binary that those three CVEs mention. so if you use the install script, setting DD_AGENT_MAJOR_VERSION=7 and DD_AGENT_MINOR_VERSION=50 should do it, e.g.:

DD_AGENT_MAJOR_VERSION=7 DD_AGENT_MINOR_VERSION=50 ~/install_script_agent7.sh

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants