github prometheus/jmx_exporter parent-0.17.2
0.17.2 / 2022-09-22

latest releases: 1.0.1, 1.0.0, 0.20.0...
2 years ago

Minor release updating the snakeyaml dependency from 1.31 to 1.32, because version 1.31 is vulnerable to CVE-2022-38752.

Note that jmx_exporter uses snakeyaml only to parse its config file. That means unless you have untrusted 3rd parties write your jmx_exporter config the CVE does not apply. However, if you have automated security scanners complaining about the vulnerable snakeyaml version this update will help.

As always, the jmx_exporter binaries are available on Maven central:

Sounds like a deja vu? Yes, we had the same on 10 September when we updated snakeyaml from 1.30 to 1.31 because of CVE-2022-25857.

Don't miss a new jmx_exporter release

NewReleases is sending notifications on new releases.