gpp_maybe Security update for golang prometheus
SUSE-SLE-Module-Basesystem-15-SP4-2023-3888


This update for Golang Prometheus fixes the following issues: golang-github-prometheus-alertmanager: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. golang-github-prometheus-node_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

  • Release Date
    Sep 28 2023
  • References
    Bugzilla: 1213880
    CVEs: CVE-2023-29409
  • Type
    security
  • Severity
    important

cloud_download Downloads

Basesystem Module 15.4 aarch64
Basesystem Module 15.4 ppc64le
Basesystem Module 15.4 s390x
Basesystem Module 15.4 x86_64