Status
Impact
This vulnerability requires upgrading protobuf from 2.28.0 to 3.7.2. However, parseable depends on prometheus 0.13, which only supports protobuf 2.x. The newer prometheus 0.14.0+ supports protobuf 3.x, but parseable has not yet upgraded to this version. This fix is blocked until upstream parseable upgrades to prometheus 0.14.0 or later.
Status