SUSE-SU-2022:2139-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2139-1
SUSE-SU-2022:2139-1
Summary: Security update for golang-github-prometheus-alertmanager
Details: This update for golang-github-prometheus-alertmanager fixes the following issues: Update golang-github-prometheus-alertmanager from version 0.21.0 to version 0.23.0 (bsc#1196338, jsc#SLE-24077) - CVE-2022-21698: Denial of service using InstrumentHandlerCounter - Update vendor tarball with prometheus/client_golang 1.11.1 - Update required Go version to 1.16 - Use %autosetup macro - Update to version 0.23.0: * Release 0.23.0 * Release 0.23.0-rc.0 * amtool: Detect version drift and warn users (#2672) * Add ability to skip TLS verification for amtool (#2663) * Fix empty isEqual in amtool. (#2668) * Fix main tests (#2670) * cli: add new template render command (#2538) * OpsGenie: refer to alert instead of incident (#2609) * Docs: target_match and source_match are DEPRECATED (#2665) * Fix test not waiting for cluster member to be ready - Add go_modules to _service. - Added hardening to systemd service(s) with a modified prometheus-alertmanager.service (bsc#1181400)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222139-1/, https://bugzilla.suse.com/1181400, https://bugzilla.suse.com/1196338, https://www.suse.com/security/cve/CVE-2022-21698
Affected packages
Package
Name: golang-github-prometheus-alertmanager
Purl: pkg:rpm/suse/golang-github-prometheus-alertmanager&distro=SUSE%20Manager%20Client%20Tools%2015
Affected ranges
Type: ECOSYSTEM
Events:
