Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE vulnerabilities found for golang-runtime:1.20.4 (usr/local/bin/kube-rbac-proxy) #274

Closed
lin1161 opened this issue Dec 22, 2023 · 3 comments

Comments

@lin1161
Copy link

lin1161 commented Dec 22, 2023

Hi,
Protecode scan reported the vulnerabilities for kube-rbac-proxy image, I used v14.0.2, and I checked, seems you do not upgrade golang version in the later versions. Do you have a plan to upgrade the golang version?
image

@ibihim
Copy link
Collaborator

ibihim commented Jan 15, 2024

Yes, I am currently working on a bigger update, which would contain the newest K8s version.

It would be super helpful, if you would write out those CVEs, such that I can copy paste them easily. A link would be even better 😄

The CVEs have no direct impact on the kube-rbac-proxy users, except for CVE-2023-39326, which is medium. I will proceed with preparing the bigger update to the newest K8s version.

For the BDSA one, I didn't find an entry on google:

No results found for "BDSA-2023-3257

@ibihim
Copy link
Collaborator

ibihim commented Feb 2, 2024

I am waiting for someone to review my PR, if it doesn't get a review by Tuesday, I will merge it anyway.

@ibihim
Copy link
Collaborator

ibihim commented Feb 7, 2024

#276, should solve it.

@ibihim ibihim closed this as completed Mar 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants