Status
Impact
Affected Go 1.20.x version cannot be updated to fix version due to upstream version pinning: https://github.com/newrelic/newrelic-fluent-bit-output/blob/cc6bcc1e735a8812dd2eab8022a575b44f8366c8/go.mod#L3 which directs to the following conversation: https://github.com/golang/go/issues/62130#issuecomment-1687335898 The upstream project explicitly requires Go 1.20 and cannot be built with newer Go versions that contain the fix.
Status
Impact
Govulncheck found vulnerable symbols in Go binaries at the following locations: in newrelic-fluent-bit-output-2.4.0-r2.apk, at fluent-bit/bin/out_newrelic.so, fluent-bit/bin/out_newrelic.so.
Status