You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Critical CVE-2021-36159 in tempo-distributed (tempo-memcached) version
Critical
zalegrala
published
GHSA-fx6q-qhch-hxgpJan 18, 2024
Package
apk-tools
(cpe:/o:alpine:alpine_linux:3.10)
Affected versions
2.10.4-r2
Patched versions
2.10.7-r0
Description
Summary
I've recently deployed the tempo-distributed in my GKE but GCP flagged 1 critical CVE on it in the tempo-memcached StatefulSet. The CVE-2021-36159 is regarding the apk-tools package and its flagged with a 9.1 CRITICAL base score.
Summary
I've recently deployed the tempo-distributed in my GKE but GCP flagged 1 critical CVE on it in the tempo-memcached StatefulSet. The CVE-2021-36159 is regarding the apk-tools package and its flagged with a 9.1 CRITICAL base score.
CVE documentation:
https://nvd.nist.gov/vuln/detail/CVE-2021-36159#range-9922715
Affected version
2.10.4-r2
Fixed version
2.10.7-r0