Security tool identified vulnerabilities for libcurl in the Foglight installation; the following files are reported:
Path : [FMS_HOME]/postgresql/lib/libcurl.so
Installed version : 7.70.0
Fixed version : 8.4.0
Path : [FMS_HOME]/postgresql/lib/libcurl.so.4
Installed version : 7.70.0
Fixed version : 8.4.0
Path : [FMS_HOME]/postgresql/lib/libcurl.so.4.6.0
Installed version : 7.70.0
Fixed version : 8.4.0
CVE-2023-38545
https://nvd.nist.gov/vuln/detail/cve-2023-38545
RESOLUTION 1
Upgrade to Foglight 8.0 or higher.
The files belong to the embedded PostgreSQL repository database version 10.14. For Foglight 8.0.0 the embedded PostgreSQL database was updated to version 16.4 and the reported files no longer included.
The Foglight upgrade process should automatically update the embedded PostgreSQL database.
RESOLUTION 2
If using an external repository instead of the embedded PostgreSQL repository, the directory for the PostgreSQL binaries [FMS_HOME]/postgresql can be archived as a backup and then deleted from the Foglight installation path.