jmx_exporter 0.17.2 is available

25 views
Skip to first unread message

Fabian Stäber

unread,
Sep 21, 2022, 6:26:23 PM9/21/22
to prometheus-announce
Hello everyone,

We just released jmx_exporter 0.17.2.

This is a minor release updating the snakeyaml dependency from 1.31 to 1.32, because version 1.31 is vulnerable to CVE-2022-38752.

Note that jmx_exporter uses snakeyaml only to parse its config file. That means unless you have untrusted 3rd parties write your jmx_exporter config the CVE does not apply. However, if you have automated security scanners complaining about the vulnerable snakeyaml version this update will help.

As always, the jmx_exporter binaries are available on Maven central:

Sounds like a deja vu? Yes, we had the same on 10 September when we updated snakeyaml from 1.30 to 1.31 because of CVE-2022-25857.

Fabian
Reply all
Reply to author
Forward
0 new messages