-
Notifications
You must be signed in to change notification settings - Fork 513
Closed
Labels
CVECommon Vulnerabilities and ExposuresCommon Vulnerabilities and ExposuresbugSomething isn't workingSomething isn't workingsecurity
Description
Upgrade bazel build to use the latest libcurl version v8.4.0 (to be released on Oct 11, 2023) for below two security vulnerabilities:
CVE-2023-38545, a high severity flaw that affects both the libcurl library and the curl tool, and
CVE-2023-38546, a low severity bug that only affects libcurl.
Release announcement: curl/curl#12026
Changes required:
bazel: upgrade version here -
opentelemetry-cpp/bazel/repository.bzl
Line 151 in 18a27df
| "https://curl.haxx.se/download/curl-7.73.0.tar.gz", |
For CMake, we don't use sticky version for libcurl, and rely on package manager (apt-get, vcpkg) so hopefully no changes be required.
Thanks @ThomsonTan for bringing this up. Please add if I missed something.
marcalff and ThomsonTan
Metadata
Metadata
Assignees
Labels
CVECommon Vulnerabilities and ExposuresCommon Vulnerabilities and ExposuresbugSomething isn't workingSomething isn't workingsecurity