/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-h7pq-89xm-w934

Published

Last updated

https://images.chainguard.dev/security/CGA-h7pq-89xm-w934
Package

opentelemetry-collector-fips

Repository

Chainguard

Latest Update
Fixed
Fixed Version

0.105.0-r0

Aliases
  • GHSA-xr7q-jx4m-x55m

Severity

Unknown

References

  • https://github.com/advisories/GHSA-xr7q-jx4m-x55m

Updates

Status

Fixed

Fixed version

0.105.0-r0

Status

Pending upstream fix

Impact

The current package version v0.104.0 contains the vulnerable code. Even if there is a new v0.105.0 release without this vulnerable code, it requires upstream changes from some of the third-party dependencies such 'https://github.com/open-telemetry/opentelemetry-collector-releases' and 'https://github.com/open-telemetry/opentelemetry-collector-contrib' to build the binaries.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing