From 769bc2bef266f614bb03b88bf84fd8e15bde6684 Mon Sep 17 00:00:00 2001 From: rancher-security-bot <119513217+rancher-security-bot@users.noreply.github.com> Date: Thu, 12 Dec 2024 20:07:00 +0000 Subject: [PATCH] Update 2024-12-12 --- docs/csv/report-harvester-master-cves.csv | 16 +- docs/csv/report-harvester-master-stats.csv | 26 +- docs/csv/report-harvester-v1.3-head-cves.csv | 4 - docs/csv/report-harvester-v1.3-head-stats.csv | 8 +- docs/csv/report-harvester-v1.3.2-cves.csv | 4 - docs/csv/report-harvester-v1.3.2-stats.csv | 8 +- docs/csv/report-harvester-v1.4-head-cves.csv | 13 +- docs/csv/report-harvester-v1.4-head-stats.csv | 20 +- docs/csv/report-harvester-v1.4.0-cves.csv | 13 +- docs/csv/report-harvester-v1.4.0-stats.csv | 20 +- docs/csv/report-rancher-v2.10-head-cves.csv | 29 +- docs/csv/report-rancher-v2.10-head-stats.csv | 48 +-- docs/csv/report-rancher-v2.10.0-cves.csv | 29 +- docs/csv/report-rancher-v2.10.0-stats.csv | 46 +- docs/csv/report-rancher-v2.8-head-cves.csv | 47 +- docs/csv/report-rancher-v2.8-head-stats.csv | 34 +- docs/csv/report-rancher-v2.8.10-cves.csv | 47 +- docs/csv/report-rancher-v2.8.10-stats.csv | 34 +- docs/csv/report-rancher-v2.9-head-cves.csv | 32 +- docs/csv/report-rancher-v2.9-head-stats.csv | 52 +-- docs/csv/report-rancher-v2.9.4-cves.csv | 24 +- docs/csv/report-rancher-v2.9.4-stats.csv | 42 +- docs/csv/report-rke2-v1.28-cves.csv | 2 +- docs/csv/report-rke2-v1.28-stats.csv | 4 +- docs/csv/report-rke2-v1.29-cves.csv | 2 +- docs/csv/report-rke2-v1.29-stats.csv | 4 +- docs/csv/report-rke2-v1.30-cves.csv | 2 +- docs/csv/report-rke2-v1.30-stats.csv | 4 +- docs/csv/report-rke2-v1.31-cves.csv | 2 +- docs/csv/report-rke2-v1.31-stats.csv | 4 +- docs/harvester-master.html | 160 +------ docs/harvester-v1.3-head.html | 40 -- docs/harvester-v1.3.2.html | 40 -- docs/harvester-v1.4-head.html | 130 +----- docs/harvester-v1.4.0.html | 130 +----- docs/rancher-v2.10-head.html | 290 +++++-------- docs/rancher-v2.10.0.html | 290 ++++--------- docs/rancher-v2.8-head.html | 404 ++++++++++-------- docs/rancher-v2.8.10.html | 404 ++++++++++-------- docs/rancher-v2.9-head.html | 320 +++++--------- docs/rancher-v2.9.4.html | 240 ++++------- docs/rke2-v1.28.html | 20 +- docs/rke2-v1.29.html | 20 +- docs/rke2-v1.30.html | 20 +- docs/rke2-v1.31.html | 20 +- 45 files changed, 1189 insertions(+), 1959 deletions(-) diff --git a/docs/csv/report-harvester-master-cves.csv b/docs/csv/report-harvester-master-cves.csv index dcd0604..ef4e0c9 100644 --- a/docs/csv/report-harvester-master-cves.csv +++ b/docs/csv/report-harvester-master-cves.csv @@ -51,13 +51,10 @@ longhornio/longhorn-share-manager:v1.7.2,harvester/master,libglib-2_0-0,2.78.6-1 longhornio/longhorn-ui:v1.7.2,harvester/master,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,longhornio/longhorn-ui:v1.7.2 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, longhornio/support-bundle-kit:v0.0.45,harvester/master,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,longhornio/support-bundle-kit:v0.0.45 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, longhornio/support-bundle-kit:v0.0.45,harvester/master,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/yq,"1.22.7, 1.23.1",false,affected, -rancher/fleet-agent:v0.10.2,harvester/master,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetagent,0.31.0,false,affected, rancher/fleet:v0.10.2,harvester/master,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/fleet:v0.10.2,harvester/master,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/fleet:v0.10.2,harvester/master,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/fleet:v0.10.2,harvester/master,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, -rancher/fleet:v0.10.2,harvester/master,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleet,0.31.0,false,affected, -rancher/fleet:v0.10.2,harvester/master,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetcontroller,0.31.0,false,affected, rancher/gitjob:v0.9.8,harvester/master,git-core,2.35.3-150300.10.39.1,suse linux enterprise server,SUSE-SU-2024:2656-1,HIGH,,rancher/gitjob:v0.9.8 (suse linux enterprise server 15.5),2.35.3-150300.10.42.1,false,affected, rancher/gitjob:v0.9.8,harvester/master,glibc,2.31-150300.74.1,suse linux enterprise server,SUSE-SU-2024:1895-1,HIGH,,rancher/gitjob:v0.9.8 (suse linux enterprise server 15.5),2.31-150300.83.1,false,affected, rancher/gitjob:v0.9.8,harvester/master,krb5,1.20.1-150500.3.6.1,suse linux enterprise server,SUSE-SU-2024:2302-1,HIGH,,rancher/gitjob:v0.9.8 (suse linux enterprise server 15.5),1.20.1-150500.3.9.1,false,affected, @@ -99,6 +96,7 @@ rancher/hardened-flannel:v0.25.6-build20240910,harvester/master,libgmodule-2_0-0 rancher/hardened-flannel:v0.25.6-build20240910,harvester/master,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/master,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/master,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, +rancher/hardened-flannel:v0.25.6-build20240910,harvester/master,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/master,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/master,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,harvester/master,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, @@ -115,7 +113,6 @@ rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/master,stdlib rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/master,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/master,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/kubelet,0.31.0,false,affected, rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/master,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubelet,"1.22.7, 1.23.1",false,affected, -rancher/harvester-eventrouter:v0.3.2,harvester/master,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/eventrouter,0.31.0,false,affected, rancher/harvester-eventrouter:v0.3.2,harvester/master,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/eventrouter,"1.22.7, 1.23.1",false,affected, rancher/harvester-load-balancer-webhook:master-head,harvester/master,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2019-12274,HIGH,https://avd.aquasec.com/nvd/cve-2019-12274,usr/bin/harvester-load-balancer-webhook,"2.2.4, 1.6.27",false,affected, rancher/harvester-load-balancer-webhook:master-head,harvester/master,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-load-balancer-webhook,"2.4.18, 2.5.12, 2.6.3",false,affected, @@ -129,19 +126,16 @@ rancher/harvester-network-controller:master-head,harvester/master,libglib-2_0-0, rancher/harvester-network-controller:master-head,harvester/master,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2019-12274,HIGH,https://avd.aquasec.com/nvd/cve-2019-12274,usr/bin/harvester-network-controller,"2.2.4, 1.6.27",false,affected, rancher/harvester-network-controller:master-head,harvester/master,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-network-controller,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-network-controller:master-head,harvester/master,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-network-controller,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester-network-controller:master-head,harvester/master,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-network-controller,0.31.0,false,affected, rancher/harvester-network-controller:master-head,harvester/master,kubevirt.io/kubevirt,v0.54.0,gobinary,CVE-2023-26484,HIGH,https://avd.aquasec.com/nvd/cve-2023-26484,usr/bin/harvester-network-controller,,false,affected, rancher/harvester-network-controller:master-head,harvester/master,kubevirt.io/kubevirt,v0.54.0,gobinary,GHSA-qv98-3369-g364,HIGH,https://github.com/advisories/GHSA-qv98-3369-g364,usr/bin/harvester-network-controller,0.55.1,false,affected, rancher/harvester-network-helper:master-head,harvester/master,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2019-12274,HIGH,https://avd.aquasec.com/nvd/cve-2019-12274,usr/bin/harvester-network-helper,"2.2.4, 1.6.27",false,affected, rancher/harvester-network-helper:master-head,harvester/master,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-network-helper,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-network-helper:master-head,harvester/master,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-network-helper,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester-network-helper:master-head,harvester/master,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-network-helper,0.31.0,false,affected, rancher/harvester-network-helper:master-head,harvester/master,kubevirt.io/kubevirt,v0.54.0,gobinary,CVE-2023-26484,HIGH,https://avd.aquasec.com/nvd/cve-2023-26484,usr/bin/harvester-network-helper,,false,affected, rancher/harvester-network-helper:master-head,harvester/master,kubevirt.io/kubevirt,v0.54.0,gobinary,GHSA-qv98-3369-g364,HIGH,https://github.com/advisories/GHSA-qv98-3369-g364,usr/bin/harvester-network-helper,0.55.1,false,affected, rancher/harvester-network-webhook:master-head,harvester/master,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2019-12274,HIGH,https://avd.aquasec.com/nvd/cve-2019-12274,usr/bin/harvester-network-webhook,"2.2.4, 1.6.27",false,affected, rancher/harvester-network-webhook:master-head,harvester/master,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-network-webhook,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-network-webhook:master-head,harvester/master,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-network-webhook,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester-network-webhook:master-head,harvester/master,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-network-webhook,0.31.0,false,affected, rancher/harvester-network-webhook:master-head,harvester/master,kubevirt.io/kubevirt,v0.54.0,gobinary,CVE-2023-26484,HIGH,https://avd.aquasec.com/nvd/cve-2023-26484,usr/bin/harvester-network-webhook,,false,affected, rancher/harvester-network-webhook:master-head,harvester/master,kubevirt.io/kubevirt,v0.54.0,gobinary,GHSA-qv98-3369-g364,HIGH,https://github.com/advisories/GHSA-qv98-3369-g364,usr/bin/harvester-network-webhook,0.55.1,false,affected, rancher/harvester-networkfs-manager:main-head,harvester/master,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-networkfs-manager:main-head (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, @@ -156,12 +150,10 @@ rancher/harvester-node-manager-webhook:master-head,harvester/master,golang.org/x rancher/harvester-pcidevices:v0.4.1,harvester/master,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-pcidevices:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-pcidevices:v0.4.1,harvester/master,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/pcidevices,0.31.0,false,affected, rancher/harvester-seeder:v0.4.1,harvester/master,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-seeder:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, -rancher/harvester-seeder:v0.4.1,harvester/master,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/manager,0.31.0,false,affected, rancher/harvester-upgrade:master-head,harvester/master,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/harvester-upgrade:master-head,harvester/master,stdlib,v1.22.2,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/virtctl,"1.21.11, 1.22.4",false,affected, rancher/harvester-upgrade:master-head,harvester/master,stdlib,v1.22.2,gobinary,CVE-2024-24788,HIGH,https://avd.aquasec.com/nvd/cve-2024-24788,usr/bin/virtctl,1.22.3,false,affected, rancher/harvester-upgrade:master-head,harvester/master,stdlib,v1.22.2,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/virtctl,"1.22.7, 1.23.1",false,affected, -rancher/harvester-upgrade:master-head,harvester/master,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/upgrade-helper,0.31.0,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/master,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/master,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/master,qemu-img,8.2.6-150600.3.15.1,suse linux enterprise server,SUSE-SU-2024:3744-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),8.2.7-15061.6.coco15sp6.1,false,affected, @@ -171,9 +163,7 @@ rancher/harvester-vm-import-controller:v0.4.1,harvester/master,qemu-pr-helper,8. rancher/harvester-vm-import-controller:v0.4.1,harvester/master,qemu-tools,8.2.6-150600.3.15.1,suse linux enterprise server,SUSE-SU-2024:3744-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),8.2.7-15061.6.coco15sp6.1,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/master,qemu-tools,8.2.6-150600.3.15.1,suse linux enterprise server,SUSE-SU-2024:4094-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),8.2.7-150600.3.20.1,false,affected, rancher/harvester-webhook:master-head,harvester/master,github.com/rancher/steve,v0.0.0-20240911190153-79304d93b49b,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-webhook,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester-webhook:master-head,harvester/master,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-webhook,0.31.0,false,affected, rancher/harvester:master-head,harvester/master,github.com/rancher/steve,v0.0.0-20240911190153-79304d93b49b,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester:master-head,harvester/master,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester,0.31.0,false,affected, rancher/klipper-helm:v0.9.2-build20240828,harvester/master,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis,0.31.0,false,affected, rancher/klipper-helm:v0.9.2-build20240828,harvester/master,stdlib,v1.23.0,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis,"1.22.7, 1.23.1",false,affected, rancher/klipper-helm:v0.9.2-build20240828,harvester/master,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status,0.31.0,false,affected, @@ -753,7 +743,6 @@ rancher/rancher:v2.9.2,harvester/master,stdlib,v1.22.2,gobinary,CVE-2024-34156,H rancher/rancher:v2.9.2,harvester/master,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/bandwidth,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/master,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/cni,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/master,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/containerd,0.46.0,false,affected, -rancher/rancher:v2.9.2,harvester/master,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/containerd,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/master,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/master,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd-shim-runc-v2,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/master,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/etcdctl,0.31.0,false,affected, @@ -763,7 +752,6 @@ rancher/rancher:v2.9.2,harvester/master,stdlib,v1.22.4,gobinary,CVE-2024-34156,H rancher/rancher:v2.9.2,harvester/master,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/helm_v3,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/master,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/helm_v3,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/master,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/k3s,0.46.0,false,affected, -rancher/rancher:v2.9.2,harvester/master,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/k3s,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/master,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/k3s,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/master,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/kustomize,"1.21.11, 1.22.4",false,affected, rancher/rancher:v2.9.2,harvester/master,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kustomize,"1.22.7, 1.23.1",false,affected, @@ -773,7 +761,6 @@ rancher/rancher:v2.9.2,harvester/master,github.com/rancher/rancher,v2.9.2,gobina rancher/rancher:v2.9.2,harvester/master,github.com/rancher/rancher,v2.9.2,gobinary,CVE-2024-22036,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-22036,usr/bin/rancher,"2.7.16, 2.8.9, 2.9.3",false,affected, rancher/rancher:v2.9.2,harvester/master,github.com/rancher/rancher,v2.9.2,gobinary,CVE-2022-45157,HIGH,https://avd.aquasec.com/nvd/cve-2022-45157,usr/bin/rancher,"2.9.3, 2.8.9",false,affected, rancher/rancher:v2.9.2,harvester/master,github.com/rancher/steve,v0.0.0-20240911190153-79304d93b49b,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/rancher,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/rancher:v2.9.2,harvester/master,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/master,k8s.io/kubernetes,v1.30.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,usr/bin/rancher,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rancher:v2.9.2,harvester/master,k8s.io/kubernetes,v1.30.1,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,usr/bin/rancher,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rancher:v2.9.2,harvester/master,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher-machine,0.31.0,false,affected, @@ -788,7 +775,6 @@ rancher/rancher:v2.9.2,harvester/master,stdlib,v1.21.3,gobinary,CVE-2024-34156,H rancher/rancher:v2.9.2,harvester/master,github.com/docker/docker,v20.10.27+incompatible,gobinary,CVE-2024-41110,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-41110,usr/share/rancher/ui/assets/wins.exe,"23.0.15, 26.1.5, 27.1.1, 25.0.6",false,affected, rancher/rancher:v2.9.2,harvester/master,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/share/rancher/ui/assets/wins.exe,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.29.8-build20240910,harvester/master,golang.org/x/crypto,v0.23.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.29.9-rke2r1,harvester/master,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.29.9-rke2r1,harvester/master,github.com/docker/docker,v24.0.7+incompatible,gobinary,CVE-2024-41110,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-41110,bin/crictl,"23.0.15, 26.1.5, 27.1.1, 25.0.6",false,affected, rancher/rke2-runtime:v1.29.9-rke2r1,harvester/master,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/rke2-runtime:v1.29.9-rke2r1,harvester/master,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, diff --git a/docs/csv/report-harvester-master-stats.csv b/docs/csv/report-harvester-master-stats.csv index 04f9124..8b8460e 100644 --- a/docs/csv/report-harvester-master-stats.csv +++ b/docs/csv/report-harvester-master-stats.csv @@ -15,8 +15,8 @@ longhornio/longhorn-manager:v1.7.2,0,2,2 longhornio/longhorn-share-manager:v1.7.2,0,1,1 longhornio/longhorn-ui:v1.7.2,0,1,1 longhornio/support-bundle-kit:v0.0.45,0,2,2 -rancher/fleet-agent:v0.10.2,0,1,1 -rancher/fleet:v0.10.2,0,6,6 +rancher/fleet-agent:v0.10.2,0,0,0 +rancher/fleet:v0.10.2,0,4,4 rancher/gitjob:v0.9.8,2,12,14 rancher/hardened-addon-resizer:1.8.20-build20240910,0,0,0 rancher/hardened-calico:v3.28.1-build20240911,0,9,9 @@ -25,28 +25,28 @@ rancher/hardened-cni-plugins:v1.5.1-build20240910,0,0,0 rancher/hardened-coredns:v1.11.1-build20240910,0,4,4 rancher/hardened-dns-node-cache:1.23.1-build20240910,0,5,5 rancher/hardened-etcd:v3.5.13-k3s1-build20240910,0,2,2 -rancher/hardened-flannel:v0.25.6-build20240910,0,9,9 +rancher/hardened-flannel:v0.25.6-build20240910,0,10,10 rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,0,1,1 rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,0,13,13 rancher/hardened-multus-cni:v4.1.0-build20240910,0,0,0 rancher/harvester-cluster-repo:master,0,0,0 -rancher/harvester-eventrouter:v0.3.2,0,2,2 +rancher/harvester-eventrouter:v0.3.2,0,1,1 rancher/harvester-load-balancer-webhook:master-head,0,4,4 rancher/harvester-load-balancer:master-head,0,4,4 -rancher/harvester-network-controller:master-head,0,7,7 -rancher/harvester-network-helper:master-head,0,6,6 -rancher/harvester-network-webhook:master-head,0,6,6 +rancher/harvester-network-controller:master-head,0,6,6 +rancher/harvester-network-helper:master-head,0,5,5 +rancher/harvester-network-webhook:master-head,0,5,5 rancher/harvester-networkfs-manager:main-head,0,4,4 rancher/harvester-node-disk-manager-webhook:master-head,0,2,2 rancher/harvester-node-disk-manager:master-head,0,2,2 rancher/harvester-node-manager-webhook:master-head,0,1,1 rancher/harvester-node-manager:master-head,0,0,0 rancher/harvester-pcidevices:v0.4.1,0,2,2 -rancher/harvester-seeder:v0.4.1,0,2,2 -rancher/harvester-upgrade:master-head,1,4,5 +rancher/harvester-seeder:v0.4.1,0,1,1 +rancher/harvester-upgrade:master-head,1,3,4 rancher/harvester-vm-import-controller:v0.4.1,0,8,8 -rancher/harvester-webhook:master-head,0,2,2 -rancher/harvester:master-head,0,2,2 +rancher/harvester-webhook:master-head,0,1,1 +rancher/harvester:master-head,0,1,1 rancher/klipper-helm:v0.9.2-build20240828,0,6,6 rancher/klipper-lb:v0.4.9,0,0,0 rancher/kubectl:v1.20.2,4,43,47 @@ -75,9 +75,9 @@ rancher/mirrored-sig-storage-snapshot-controller:v6.2.1,3,24,27 rancher/mirrored-sig-storage-snapshot-validation-webhook:v6.2.2,3,23,26 rancher/nginx-ingress-controller:v1.10.4-hardened3,0,13,13 rancher/rancher-webhook:v0.5.2,0,2,2 -rancher/rancher:v2.9.2,11,43,54 +rancher/rancher:v2.9.2,11,40,51 rancher/rke2-cloud-provider:v1.29.8-build20240910,0,1,1 -rancher/rke2-runtime:v1.29.9-rke2r1,1,4,5 +rancher/rke2-runtime:v1.29.9-rke2r1,1,3,4 rancher/shell:v0.1.24,6,24,30 rancher/shell:v0.1.26,4,15,19 rancher/shell:v0.2.1,4,14,18 diff --git a/docs/csv/report-harvester-v1.3-head-cves.csv b/docs/csv/report-harvester-v1.3-head-cves.csv index 56f6302..7b364fd 100644 --- a/docs/csv/report-harvester-v1.3-head-cves.csv +++ b/docs/csv/report-harvester-v1.3-head-cves.csv @@ -299,7 +299,6 @@ rancher/hardened-multus-cni:v4.0.2-build20240612,harvester/v1.3-head,golang.org/ rancher/hardened-multus-cni:v4.0.2-build20240612,harvester/v1.3-head,google.golang.org/grpc,v1.40.0,gobinary,GHSA-m425-mq94-257g,HIGH,https://github.com/advisories/GHSA-m425-mq94-257g,usr/src/multus-cni/bin/multus,"1.56.3, 1.57.1, 1.58.3",false,affected, rancher/hardened-multus-cni:v4.0.2-build20240612,harvester/v1.3-head,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/src/multus-cni/bin/multus,"1.21.11, 1.22.4",false,affected, rancher/hardened-multus-cni:v4.0.2-build20240612,harvester/v1.3-head,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/src/multus-cni/bin/multus,"1.22.7, 1.23.1",false,affected, -rancher/harvester-eventrouter:v0.3.2,harvester/v1.3-head,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/eventrouter,0.31.0,false,affected, rancher/harvester-eventrouter:v0.3.2,harvester/v1.3-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/eventrouter,"1.22.7, 1.23.1",false,affected, rancher/harvester-load-balancer-webhook:v0.3.0,harvester/v1.3-head,github.com/rancher/apiserver,v0.0.0-20230120214941-e88c32739dc7,gobinary,CVE-2023-32192,HIGH,https://avd.aquasec.com/nvd/cve-2023-32192,usr/bin/harvester-load-balancer-webhook,0.0.0-20240207153957-4fd7d821d952,false,affected, rancher/harvester-load-balancer-webhook:v0.3.0,harvester/v1.3-head,github.com/rancher/norman,v0.0.0-20221205184727-32ef2e185b99,gobinary,CVE-2023-32193,HIGH,https://avd.aquasec.com/nvd/cve-2023-32193,usr/bin/harvester-load-balancer-webhook,0.0.0-20240207153100-3bb70b772b52,false,affected, @@ -398,11 +397,9 @@ rancher/harvester-node-manager:v0.2.1,harvester/v1.3-head,stdlib,v1.20.13,gobina rancher/harvester-node-manager:v0.2.1,harvester/v1.3-head,stdlib,v1.20.13,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-node-manager,"1.22.7, 1.23.1",false,affected, rancher/harvester-pcidevices:v0.3.3,harvester/v1.3-head,libglib-2_0-0,2.70.5-150400.3.11.1,suse linux enterprise server,SUSE-SU-2024:4078-1,HIGH,,rancher/harvester-pcidevices:v0.3.3 (suse linux enterprise server 15.5),2.70.5-150400.3.17.1,false,affected, rancher/harvester-pcidevices:v0.3.3,harvester/v1.3-head,libprotobuf-lite25_1_0,25.1-150500.12.2.2,suse linux enterprise server,SUSE-SU-2024:3747-1,HIGH,,rancher/harvester-pcidevices:v0.3.3 (suse linux enterprise server 15.5),25.1-150500.12.5.1,false,affected, -rancher/harvester-pcidevices:v0.3.3,harvester/v1.3-head,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/pcidevices,0.31.0,false,affected, rancher/harvester-pcidevices:v0.3.3,harvester/v1.3-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/pcidevices,"1.22.7, 1.23.1",false,affected, rancher/harvester-seeder:v0.3.2,harvester/v1.3-head,libglib-2_0-0,2.70.5-150400.3.11.1,suse linux enterprise server,SUSE-SU-2024:4078-1,HIGH,,rancher/harvester-seeder:v0.3.2 (suse linux enterprise server 15.5),2.70.5-150400.3.17.1,false,affected, rancher/harvester-seeder:v0.3.2,harvester/v1.3-head,libprotobuf-lite25_1_0,25.1-150500.12.2.2,suse linux enterprise server,SUSE-SU-2024:3747-1,HIGH,,rancher/harvester-seeder:v0.3.2 (suse linux enterprise server 15.5),25.1-150500.12.5.1,false,affected, -rancher/harvester-seeder:v0.3.2,harvester/v1.3-head,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/manager,0.31.0,false,affected, rancher/harvester-seeder:v0.3.2,harvester/v1.3-head,stdlib,v1.21.13,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/manager,"1.22.7, 1.23.1",false,affected, rancher/harvester-upgrade:v1.3-head,harvester/v1.3-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/harvester-upgrade:v1.3-head,harvester/v1.3-head,stdlib,v1.21.8,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/virtctl,"1.21.11, 1.22.4",false,affected, @@ -1402,7 +1399,6 @@ rancher/rke2-cloud-provider:v1.29.3-build20240515,harvester/v1.3-head,golang.org rancher/rke2-cloud-provider:v1.29.3-build20240515,harvester/v1.3-head,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/local/bin/rke2-cloud-provider,"1.21.11, 1.22.4",false,affected, rancher/rke2-cloud-provider:v1.29.3-build20240515,harvester/v1.3-head,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/rke2-cloud-provider,"1.22.7, 1.23.1",false,affected, rancher/rke2-runtime:v1.28.12-rke2r1,harvester/v1.3-head,github.com/docker/docker,v24.0.7+incompatible,gobinary,CVE-2024-41110,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-41110,bin/containerd,"23.0.15, 26.1.5, 27.1.1, 25.0.6",false,affected, -rancher/rke2-runtime:v1.28.12-rke2r1,harvester/v1.3-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.28.12-rke2r1,harvester/v1.3-head,stdlib,v1.22.3,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,bin/containerd,"1.21.11, 1.22.4",false,affected, rancher/rke2-runtime:v1.28.12-rke2r1,harvester/v1.3-head,stdlib,v1.22.3,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/containerd,"1.22.7, 1.23.1",false,affected, rancher/rke2-runtime:v1.28.12-rke2r1,harvester/v1.3-head,stdlib,v1.22.3,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,bin/containerd-shim,"1.21.11, 1.22.4",false,affected, diff --git a/docs/csv/report-harvester-v1.3-head-stats.csv b/docs/csv/report-harvester-v1.3-head-stats.csv index dcb028b..8c33ed0 100644 --- a/docs/csv/report-harvester-v1.3-head-stats.csv +++ b/docs/csv/report-harvester-v1.3-head-stats.csv @@ -26,7 +26,7 @@ rancher/hardened-k8s-metrics-server:v0.7.1-build20240401,1,3,4 rancher/hardened-kubernetes:v1.28.12-rke2r1-build20240717,0,13,13 rancher/hardened-multus-cni:v4.0.2-build20240612,2,4,6 rancher/harvester-cluster-repo:v1.3,0,0,0 -rancher/harvester-eventrouter:v0.3.2,0,2,2 +rancher/harvester-eventrouter:v0.3.2,0,1,1 rancher/harvester-load-balancer-webhook:v0.3.0,1,8,9 rancher/harvester-load-balancer:v0.3.0,1,8,9 rancher/harvester-network-controller:v0.4.1,0,12,12 @@ -35,8 +35,8 @@ rancher/harvester-network-webhook:v0.4.1,0,10,10 rancher/harvester-node-disk-manager:v0.6.4,0,4,4 rancher/harvester-node-manager-webhook:v0.2.1,1,20,21 rancher/harvester-node-manager:v0.2.1,1,19,20 -rancher/harvester-pcidevices:v0.3.3,0,4,4 -rancher/harvester-seeder:v0.3.2,0,4,4 +rancher/harvester-pcidevices:v0.3.3,0,3,3 +rancher/harvester-seeder:v0.3.2,0,3,3 rancher/harvester-upgrade:v1.3-head,1,4,5 rancher/harvester-vm-import-controller:v0.3.2,0,8,8 rancher/harvester-webhook:v1.3-head,0,1,1 @@ -68,7 +68,7 @@ rancher/mirrored-sig-storage-snapshot-validation-webhook:v6.2.2,3,23,26 rancher/rancher-webhook:v0.4.7,0,4,4 rancher/rancher:v2.8.5,32,158,190 rancher/rke2-cloud-provider:v1.29.3-build20240515,1,2,3 -rancher/rke2-runtime:v1.28.12-rke2r1,11,35,46 +rancher/rke2-runtime:v1.28.12-rke2r1,11,34,45 rancher/shell:v0.1.26,4,15,19 rancher/support-bundle-kit:v0.0.38,2,9,11 rancher/system-agent-installer-rancher:v2.8.5,1,3,4 diff --git a/docs/csv/report-harvester-v1.3.2-cves.csv b/docs/csv/report-harvester-v1.3.2-cves.csv index 7a65383..f1a4298 100644 --- a/docs/csv/report-harvester-v1.3.2-cves.csv +++ b/docs/csv/report-harvester-v1.3.2-cves.csv @@ -301,7 +301,6 @@ rancher/hardened-multus-cni:v4.0.2-build20240612,harvester/v1.3.2,stdlib,v1.21.1 rancher/hardened-multus-cni:v4.0.2-build20240612,harvester/v1.3.2,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/src/multus-cni/bin/multus,"1.22.7, 1.23.1",false,affected, rancher/harvester-cluster-repo:v1.3.2,harvester/v1.3.2,libglib-2_0-0,2.70.5-150400.3.14.1,suse linux enterprise server,SUSE-SU-2024:4078-1,HIGH,,rancher/harvester-cluster-repo:v1.3.2 (suse linux enterprise server 15.5),2.70.5-150400.3.17.1,false,affected, rancher/harvester-cluster-repo:v1.3.2,harvester/v1.3.2,libprotobuf-lite25_1_0,25.1-150500.12.2.2,suse linux enterprise server,SUSE-SU-2024:3747-1,HIGH,,rancher/harvester-cluster-repo:v1.3.2 (suse linux enterprise server 15.5),25.1-150500.12.5.1,false,affected, -rancher/harvester-eventrouter:v0.2.0,harvester/v1.3.2,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/eventrouter,0.31.0,false,affected, rancher/harvester-eventrouter:v0.2.0,harvester/v1.3.2,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/eventrouter,"1.21.11, 1.22.4",false,affected, rancher/harvester-eventrouter:v0.2.0,harvester/v1.3.2,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/eventrouter,"1.22.7, 1.23.1",false,affected, rancher/harvester-load-balancer-webhook:v0.3.0,harvester/v1.3.2,github.com/rancher/apiserver,v0.0.0-20230120214941-e88c32739dc7,gobinary,CVE-2023-32192,HIGH,https://avd.aquasec.com/nvd/cve-2023-32192,usr/bin/harvester-load-balancer-webhook,0.0.0-20240207153957-4fd7d821d952,false,affected, @@ -401,11 +400,9 @@ rancher/harvester-node-manager:v0.2.1,harvester/v1.3.2,stdlib,v1.20.13,gobinary, rancher/harvester-node-manager:v0.2.1,harvester/v1.3.2,stdlib,v1.20.13,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-node-manager,"1.22.7, 1.23.1",false,affected, rancher/harvester-pcidevices:v0.3.3,harvester/v1.3.2,libglib-2_0-0,2.70.5-150400.3.11.1,suse linux enterprise server,SUSE-SU-2024:4078-1,HIGH,,rancher/harvester-pcidevices:v0.3.3 (suse linux enterprise server 15.5),2.70.5-150400.3.17.1,false,affected, rancher/harvester-pcidevices:v0.3.3,harvester/v1.3.2,libprotobuf-lite25_1_0,25.1-150500.12.2.2,suse linux enterprise server,SUSE-SU-2024:3747-1,HIGH,,rancher/harvester-pcidevices:v0.3.3 (suse linux enterprise server 15.5),25.1-150500.12.5.1,false,affected, -rancher/harvester-pcidevices:v0.3.3,harvester/v1.3.2,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/pcidevices,0.31.0,false,affected, rancher/harvester-pcidevices:v0.3.3,harvester/v1.3.2,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/pcidevices,"1.22.7, 1.23.1",false,affected, rancher/harvester-seeder:v0.3.2,harvester/v1.3.2,libglib-2_0-0,2.70.5-150400.3.11.1,suse linux enterprise server,SUSE-SU-2024:4078-1,HIGH,,rancher/harvester-seeder:v0.3.2 (suse linux enterprise server 15.5),2.70.5-150400.3.17.1,false,affected, rancher/harvester-seeder:v0.3.2,harvester/v1.3.2,libprotobuf-lite25_1_0,25.1-150500.12.2.2,suse linux enterprise server,SUSE-SU-2024:3747-1,HIGH,,rancher/harvester-seeder:v0.3.2 (suse linux enterprise server 15.5),25.1-150500.12.5.1,false,affected, -rancher/harvester-seeder:v0.3.2,harvester/v1.3.2,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/manager,0.31.0,false,affected, rancher/harvester-seeder:v0.3.2,harvester/v1.3.2,stdlib,v1.21.13,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/manager,"1.22.7, 1.23.1",false,affected, rancher/harvester-upgrade:v1.3.2,harvester/v1.3.2,libglib-2_0-0,2.70.5-150400.3.14.1,suse linux enterprise server,SUSE-SU-2024:4078-1,HIGH,,rancher/harvester-upgrade:v1.3.2 (suse linux enterprise server 15.5),2.70.5-150400.3.17.1,false,affected, rancher/harvester-upgrade:v1.3.2,harvester/v1.3.2,libprotobuf-lite25_1_0,25.1-150500.12.2.2,suse linux enterprise server,SUSE-SU-2024:3747-1,HIGH,,rancher/harvester-upgrade:v1.3.2 (suse linux enterprise server 15.5),25.1-150500.12.5.1,false,affected, @@ -1433,7 +1430,6 @@ rancher/rke2-cloud-provider:v1.29.3-build20240515,harvester/v1.3.2,golang.org/x/ rancher/rke2-cloud-provider:v1.29.3-build20240515,harvester/v1.3.2,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/local/bin/rke2-cloud-provider,"1.21.11, 1.22.4",false,affected, rancher/rke2-cloud-provider:v1.29.3-build20240515,harvester/v1.3.2,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/rke2-cloud-provider,"1.22.7, 1.23.1",false,affected, rancher/rke2-runtime:v1.28.12-rke2r1,harvester/v1.3.2,github.com/docker/docker,v24.0.7+incompatible,gobinary,CVE-2024-41110,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-41110,bin/containerd,"23.0.15, 26.1.5, 27.1.1, 25.0.6",false,affected, -rancher/rke2-runtime:v1.28.12-rke2r1,harvester/v1.3.2,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.28.12-rke2r1,harvester/v1.3.2,stdlib,v1.22.3,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,bin/containerd,"1.21.11, 1.22.4",false,affected, rancher/rke2-runtime:v1.28.12-rke2r1,harvester/v1.3.2,stdlib,v1.22.3,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/containerd,"1.22.7, 1.23.1",false,affected, rancher/rke2-runtime:v1.28.12-rke2r1,harvester/v1.3.2,stdlib,v1.22.3,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,bin/containerd-shim,"1.21.11, 1.22.4",false,affected, diff --git a/docs/csv/report-harvester-v1.3.2-stats.csv b/docs/csv/report-harvester-v1.3.2-stats.csv index d4dae97..106c6c8 100644 --- a/docs/csv/report-harvester-v1.3.2-stats.csv +++ b/docs/csv/report-harvester-v1.3.2-stats.csv @@ -26,7 +26,7 @@ rancher/hardened-k8s-metrics-server:v0.7.1-build20240401,1,3,4 rancher/hardened-kubernetes:v1.28.12-rke2r1-build20240717,0,13,13 rancher/hardened-multus-cni:v4.0.2-build20240612,2,4,6 rancher/harvester-cluster-repo:v1.3.2,0,2,2 -rancher/harvester-eventrouter:v0.2.0,1,2,3 +rancher/harvester-eventrouter:v0.2.0,1,1,2 rancher/harvester-load-balancer-webhook:v0.3.0,1,8,9 rancher/harvester-load-balancer:v0.3.0,1,8,9 rancher/harvester-network-controller:v0.4.1,0,12,12 @@ -35,8 +35,8 @@ rancher/harvester-network-webhook:v0.4.1,0,10,10 rancher/harvester-node-disk-manager:v0.6.4,0,4,4 rancher/harvester-node-manager-webhook:v0.2.1,1,20,21 rancher/harvester-node-manager:v0.2.1,1,19,20 -rancher/harvester-pcidevices:v0.3.3,0,4,4 -rancher/harvester-seeder:v0.3.2,0,4,4 +rancher/harvester-pcidevices:v0.3.3,0,3,3 +rancher/harvester-seeder:v0.3.2,0,3,3 rancher/harvester-upgrade:v1.3.2,6,23,29 rancher/harvester-vm-import-controller:v0.3.2,0,8,8 rancher/harvester-webhook:v1.3.2,0,3,3 @@ -68,7 +68,7 @@ rancher/mirrored-sig-storage-snapshot-validation-webhook:v6.2.2,3,23,26 rancher/rancher-webhook:v0.4.7,0,4,4 rancher/rancher:v2.8.5,32,158,190 rancher/rke2-cloud-provider:v1.29.3-build20240515,1,2,3 -rancher/rke2-runtime:v1.28.12-rke2r1,11,35,46 +rancher/rke2-runtime:v1.28.12-rke2r1,11,34,45 rancher/shell:v0.1.26,4,15,19 rancher/support-bundle-kit:v0.0.38,2,9,11 rancher/system-agent-installer-rancher:v2.8.5,1,3,4 diff --git a/docs/csv/report-harvester-v1.4-head-cves.csv b/docs/csv/report-harvester-v1.4-head-cves.csv index f092fbe..42a1d21 100644 --- a/docs/csv/report-harvester-v1.4-head-cves.csv +++ b/docs/csv/report-harvester-v1.4-head-cves.csv @@ -53,13 +53,10 @@ longhornio/longhorn-share-manager:v1.7.2,harvester/v1.4-head,libglib-2_0-0,2.78. longhornio/longhorn-ui:v1.7.2,harvester/v1.4-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,longhornio/longhorn-ui:v1.7.2 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, longhornio/support-bundle-kit:v0.0.45,harvester/v1.4-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,longhornio/support-bundle-kit:v0.0.45 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, longhornio/support-bundle-kit:v0.0.45,harvester/v1.4-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/yq,"1.22.7, 1.23.1",false,affected, -rancher/fleet-agent:v0.10.2,harvester/v1.4-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetagent,0.31.0,false,affected, rancher/fleet:v0.10.2,harvester/v1.4-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/fleet:v0.10.2,harvester/v1.4-head,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/fleet:v0.10.2,harvester/v1.4-head,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/fleet:v0.10.2,harvester/v1.4-head,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, -rancher/fleet:v0.10.2,harvester/v1.4-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleet,0.31.0,false,affected, -rancher/fleet:v0.10.2,harvester/v1.4-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetcontroller,0.31.0,false,affected, rancher/gitjob:v0.9.8,harvester/v1.4-head,git-core,2.35.3-150300.10.39.1,suse linux enterprise server,SUSE-SU-2024:2656-1,HIGH,,rancher/gitjob:v0.9.8 (suse linux enterprise server 15.5),2.35.3-150300.10.42.1,false,affected, rancher/gitjob:v0.9.8,harvester/v1.4-head,glibc,2.31-150300.74.1,suse linux enterprise server,SUSE-SU-2024:1895-1,HIGH,,rancher/gitjob:v0.9.8 (suse linux enterprise server 15.5),2.31-150300.83.1,false,affected, rancher/gitjob:v0.9.8,harvester/v1.4-head,krb5,1.20.1-150500.3.6.1,suse linux enterprise server,SUSE-SU-2024:2302-1,HIGH,,rancher/gitjob:v0.9.8 (suse linux enterprise server 15.5),1.20.1-150500.3.9.1,false,affected, @@ -101,6 +98,7 @@ rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4-head,libgmodule-2_ rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4-head,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4-head,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, +rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4-head,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,harvester/v1.4-head,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, @@ -117,7 +115,6 @@ rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/v1.4-head,std rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/v1.4-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/v1.4-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/kubelet,0.31.0,false,affected, rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/v1.4-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubelet,"1.22.7, 1.23.1",false,affected, -rancher/harvester-eventrouter:v0.3.2,harvester/v1.4-head,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/eventrouter,0.31.0,false,affected, rancher/harvester-eventrouter:v0.3.2,harvester/v1.4-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/eventrouter,"1.22.7, 1.23.1",false,affected, rancher/harvester-load-balancer-webhook:v0.4.3,harvester/v1.4-head,github.com/rancher/apiserver,v0.0.0-20230120214941-e88c32739dc7,gobinary,CVE-2023-32192,HIGH,https://avd.aquasec.com/nvd/cve-2023-32192,usr/bin/harvester-load-balancer-webhook,0.0.0-20240207153957-4fd7d821d952,false,affected, rancher/harvester-load-balancer-webhook:v0.4.3,harvester/v1.4-head,github.com/rancher/norman,v0.0.0-20221205184727-32ef2e185b99,gobinary,CVE-2023-32193,HIGH,https://avd.aquasec.com/nvd/cve-2023-32193,usr/bin/harvester-load-balancer-webhook,0.0.0-20240207153100-3bb70b772b52,false,affected, @@ -181,12 +178,10 @@ rancher/harvester-node-manager:v0.3.3,harvester/v1.4-head,openssl-3,3.1.4-150600 rancher/harvester-pcidevices:v0.4.1,harvester/v1.4-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-pcidevices:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-pcidevices:v0.4.1,harvester/v1.4-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/pcidevices,0.31.0,false,affected, rancher/harvester-seeder:v0.4.1,harvester/v1.4-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-seeder:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, -rancher/harvester-seeder:v0.4.1,harvester/v1.4-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/manager,0.31.0,false,affected, rancher/harvester-upgrade:v1.4-head,harvester/v1.4-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/harvester-upgrade:v1.4-head,harvester/v1.4-head,stdlib,v1.22.2,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/virtctl,"1.21.11, 1.22.4",false,affected, rancher/harvester-upgrade:v1.4-head,harvester/v1.4-head,stdlib,v1.22.2,gobinary,CVE-2024-24788,HIGH,https://avd.aquasec.com/nvd/cve-2024-24788,usr/bin/virtctl,1.22.3,false,affected, rancher/harvester-upgrade:v1.4-head,harvester/v1.4-head,stdlib,v1.22.2,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/virtctl,"1.22.7, 1.23.1",false,affected, -rancher/harvester-upgrade:v1.4-head,harvester/v1.4-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/upgrade-helper,0.31.0,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4-head,qemu-img,8.2.6-150600.3.15.1,suse linux enterprise server,SUSE-SU-2024:3744-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),8.2.7-15061.6.coco15sp6.1,false,affected, @@ -196,9 +191,7 @@ rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4-head,qemu-pr-helper rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4-head,qemu-tools,8.2.6-150600.3.15.1,suse linux enterprise server,SUSE-SU-2024:3744-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),8.2.7-15061.6.coco15sp6.1,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4-head,qemu-tools,8.2.6-150600.3.15.1,suse linux enterprise server,SUSE-SU-2024:4094-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),8.2.7-150600.3.20.1,false,affected, rancher/harvester-webhook:v1.4-head,harvester/v1.4-head,github.com/rancher/steve,v0.0.0-20240911190153-79304d93b49b,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-webhook,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester-webhook:v1.4-head,harvester/v1.4-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-webhook,0.31.0,false,affected, rancher/harvester:v1.4-head,harvester/v1.4-head,github.com/rancher/steve,v0.0.0-20240911190153-79304d93b49b,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester:v1.4-head,harvester/v1.4-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester,0.31.0,false,affected, rancher/klipper-helm:v0.9.2-build20240828,harvester/v1.4-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis,0.31.0,false,affected, rancher/klipper-helm:v0.9.2-build20240828,harvester/v1.4-head,stdlib,v1.23.0,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis,"1.22.7, 1.23.1",false,affected, rancher/klipper-helm:v0.9.2-build20240828,harvester/v1.4-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status,0.31.0,false,affected, @@ -778,7 +771,6 @@ rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.22.2,gobinary,CVE-2024-3415 rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/bandwidth,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/cni,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/containerd,0.46.0,false,affected, -rancher/rancher:v2.9.2,harvester/v1.4-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/containerd,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd-shim-runc-v2,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/etcdctl,0.31.0,false,affected, @@ -788,7 +780,6 @@ rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.22.4,gobinary,CVE-2024-3415 rancher/rancher:v2.9.2,harvester/v1.4-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/helm_v3,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/helm_v3,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/k3s,0.46.0,false,affected, -rancher/rancher:v2.9.2,harvester/v1.4-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/k3s,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/k3s,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/kustomize,"1.21.11, 1.22.4",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kustomize,"1.22.7, 1.23.1",false,affected, @@ -798,7 +789,6 @@ rancher/rancher:v2.9.2,harvester/v1.4-head,github.com/rancher/rancher,v2.9.2,gob rancher/rancher:v2.9.2,harvester/v1.4-head,github.com/rancher/rancher,v2.9.2,gobinary,CVE-2024-22036,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-22036,usr/bin/rancher,"2.7.16, 2.8.9, 2.9.3",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,github.com/rancher/rancher,v2.9.2,gobinary,CVE-2022-45157,HIGH,https://avd.aquasec.com/nvd/cve-2022-45157,usr/bin/rancher,"2.9.3, 2.8.9",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,github.com/rancher/steve,v0.0.0-20240911190153-79304d93b49b,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/rancher,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/rancher:v2.9.2,harvester/v1.4-head,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,k8s.io/kubernetes,v1.30.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,usr/bin/rancher,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,k8s.io/kubernetes,v1.30.1,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,usr/bin/rancher,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher-machine,0.31.0,false,affected, @@ -813,7 +803,6 @@ rancher/rancher:v2.9.2,harvester/v1.4-head,stdlib,v1.21.3,gobinary,CVE-2024-3415 rancher/rancher:v2.9.2,harvester/v1.4-head,github.com/docker/docker,v20.10.27+incompatible,gobinary,CVE-2024-41110,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-41110,usr/share/rancher/ui/assets/wins.exe,"23.0.15, 26.1.5, 27.1.1, 25.0.6",false,affected, rancher/rancher:v2.9.2,harvester/v1.4-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/share/rancher/ui/assets/wins.exe,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.29.8-build20240910,harvester/v1.4-head,golang.org/x/crypto,v0.23.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.29.9-rke2r1,harvester/v1.4-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.29.9-rke2r1,harvester/v1.4-head,github.com/docker/docker,v24.0.7+incompatible,gobinary,CVE-2024-41110,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-41110,bin/crictl,"23.0.15, 26.1.5, 27.1.1, 25.0.6",false,affected, rancher/rke2-runtime:v1.29.9-rke2r1,harvester/v1.4-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/rke2-runtime:v1.29.9-rke2r1,harvester/v1.4-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, diff --git a/docs/csv/report-harvester-v1.4-head-stats.csv b/docs/csv/report-harvester-v1.4-head-stats.csv index 5eeaf08..82f9eb5 100644 --- a/docs/csv/report-harvester-v1.4-head-stats.csv +++ b/docs/csv/report-harvester-v1.4-head-stats.csv @@ -15,8 +15,8 @@ longhornio/longhorn-manager:v1.7.2,0,2,2 longhornio/longhorn-share-manager:v1.7.2,0,1,1 longhornio/longhorn-ui:v1.7.2,0,1,1 longhornio/support-bundle-kit:v0.0.45,0,2,2 -rancher/fleet-agent:v0.10.2,0,1,1 -rancher/fleet:v0.10.2,0,6,6 +rancher/fleet-agent:v0.10.2,0,0,0 +rancher/fleet:v0.10.2,0,4,4 rancher/gitjob:v0.9.8,2,12,14 rancher/hardened-addon-resizer:1.8.20-build20240910,0,0,0 rancher/hardened-calico:v3.28.1-build20240911,0,9,9 @@ -25,12 +25,12 @@ rancher/hardened-cni-plugins:v1.5.1-build20240910,0,0,0 rancher/hardened-coredns:v1.11.1-build20240910,0,4,4 rancher/hardened-dns-node-cache:1.23.1-build20240910,0,5,5 rancher/hardened-etcd:v3.5.13-k3s1-build20240910,0,2,2 -rancher/hardened-flannel:v0.25.6-build20240910,0,9,9 +rancher/hardened-flannel:v0.25.6-build20240910,0,10,10 rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,0,1,1 rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,0,13,13 rancher/hardened-multus-cni:v4.1.0-build20240910,0,0,0 rancher/harvester-cluster-repo:v1.4,0,0,0 -rancher/harvester-eventrouter:v0.3.2,0,2,2 +rancher/harvester-eventrouter:v0.3.2,0,1,1 rancher/harvester-load-balancer-webhook:v0.4.3,0,7,7 rancher/harvester-load-balancer:v0.4.3,0,7,7 rancher/harvester-network-controller:v0.5.5,0,10,10 @@ -42,11 +42,11 @@ rancher/harvester-node-disk-manager:v0.7.7,0,2,2 rancher/harvester-node-manager-webhook:v0.3.3,0,5,5 rancher/harvester-node-manager:v0.3.3,0,4,4 rancher/harvester-pcidevices:v0.4.1,0,2,2 -rancher/harvester-seeder:v0.4.1,0,2,2 -rancher/harvester-upgrade:v1.4-head,1,4,5 +rancher/harvester-seeder:v0.4.1,0,1,1 +rancher/harvester-upgrade:v1.4-head,1,3,4 rancher/harvester-vm-import-controller:v0.4.1,0,8,8 -rancher/harvester-webhook:v1.4-head,0,2,2 -rancher/harvester:v1.4-head,0,2,2 +rancher/harvester-webhook:v1.4-head,0,1,1 +rancher/harvester:v1.4-head,0,1,1 rancher/klipper-helm:v0.9.2-build20240828,0,6,6 rancher/klipper-lb:v0.4.9,0,0,0 rancher/kubectl:v1.20.2,4,43,47 @@ -75,9 +75,9 @@ rancher/mirrored-sig-storage-snapshot-controller:v6.2.1,3,24,27 rancher/mirrored-sig-storage-snapshot-validation-webhook:v6.2.2,3,23,26 rancher/nginx-ingress-controller:v1.10.4-hardened3,0,13,13 rancher/rancher-webhook:v0.5.2,0,2,2 -rancher/rancher:v2.9.2,11,43,54 +rancher/rancher:v2.9.2,11,40,51 rancher/rke2-cloud-provider:v1.29.8-build20240910,0,1,1 -rancher/rke2-runtime:v1.29.9-rke2r1,1,4,5 +rancher/rke2-runtime:v1.29.9-rke2r1,1,3,4 rancher/shell:v0.1.24,6,24,30 rancher/shell:v0.1.26,4,15,19 rancher/shell:v0.2.1,4,14,18 diff --git a/docs/csv/report-harvester-v1.4.0-cves.csv b/docs/csv/report-harvester-v1.4.0-cves.csv index 8ed4340..f77fb7c 100644 --- a/docs/csv/report-harvester-v1.4.0-cves.csv +++ b/docs/csv/report-harvester-v1.4.0-cves.csv @@ -53,13 +53,10 @@ longhornio/longhorn-share-manager:v1.7.2,harvester/v1.4.0,libglib-2_0-0,2.78.6-1 longhornio/longhorn-ui:v1.7.2,harvester/v1.4.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,longhornio/longhorn-ui:v1.7.2 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, longhornio/support-bundle-kit:v0.0.45,harvester/v1.4.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,longhornio/support-bundle-kit:v0.0.45 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, longhornio/support-bundle-kit:v0.0.45,harvester/v1.4.0,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/yq,"1.22.7, 1.23.1",false,affected, -rancher/fleet-agent:v0.10.2,harvester/v1.4.0,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetagent,0.31.0,false,affected, rancher/fleet:v0.10.2,harvester/v1.4.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/fleet:v0.10.2,harvester/v1.4.0,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/fleet:v0.10.2,harvester/v1.4.0,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/fleet:v0.10.2,harvester/v1.4.0,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/fleet:v0.10.2 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, -rancher/fleet:v0.10.2,harvester/v1.4.0,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleet,0.31.0,false,affected, -rancher/fleet:v0.10.2,harvester/v1.4.0,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetcontroller,0.31.0,false,affected, rancher/gitjob:v0.9.8,harvester/v1.4.0,git-core,2.35.3-150300.10.39.1,suse linux enterprise server,SUSE-SU-2024:2656-1,HIGH,,rancher/gitjob:v0.9.8 (suse linux enterprise server 15.5),2.35.3-150300.10.42.1,false,affected, rancher/gitjob:v0.9.8,harvester/v1.4.0,glibc,2.31-150300.74.1,suse linux enterprise server,SUSE-SU-2024:1895-1,HIGH,,rancher/gitjob:v0.9.8 (suse linux enterprise server 15.5),2.31-150300.83.1,false,affected, rancher/gitjob:v0.9.8,harvester/v1.4.0,krb5,1.20.1-150500.3.6.1,suse linux enterprise server,SUSE-SU-2024:2302-1,HIGH,,rancher/gitjob:v0.9.8 (suse linux enterprise server 15.5),1.20.1-150500.3.9.1,false,affected, @@ -101,6 +98,7 @@ rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4.0,libgmodule-2_0-0 rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4.0,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4.0,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4.0,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, +rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4.0,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4.0,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,harvester/v1.4.0,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,harvester/v1.4.0,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, @@ -118,7 +116,6 @@ rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/v1.4.0,stdlib rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/v1.4.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/kubelet,0.31.0,false,affected, rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,harvester/v1.4.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubelet,"1.22.7, 1.23.1",false,affected, rancher/harvester-cluster-repo:v1.4.0,harvester/v1.4.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-cluster-repo:v1.4.0 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, -rancher/harvester-eventrouter:v0.3.2,harvester/v1.4.0,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/eventrouter,0.31.0,false,affected, rancher/harvester-eventrouter:v0.3.2,harvester/v1.4.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/eventrouter,"1.22.7, 1.23.1",false,affected, rancher/harvester-load-balancer-webhook:v0.4.3,harvester/v1.4.0,github.com/rancher/apiserver,v0.0.0-20230120214941-e88c32739dc7,gobinary,CVE-2023-32192,HIGH,https://avd.aquasec.com/nvd/cve-2023-32192,usr/bin/harvester-load-balancer-webhook,0.0.0-20240207153957-4fd7d821d952,false,affected, rancher/harvester-load-balancer-webhook:v0.4.3,harvester/v1.4.0,github.com/rancher/norman,v0.0.0-20221205184727-32ef2e185b99,gobinary,CVE-2023-32193,HIGH,https://avd.aquasec.com/nvd/cve-2023-32193,usr/bin/harvester-load-balancer-webhook,0.0.0-20240207153100-3bb70b772b52,false,affected, @@ -182,7 +179,6 @@ rancher/harvester-node-manager:v0.3.3,harvester/v1.4.0,openssl-3,3.1.4-150600.5. rancher/harvester-pcidevices:v0.4.1,harvester/v1.4.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-pcidevices:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-pcidevices:v0.4.1,harvester/v1.4.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/pcidevices,0.31.0,false,affected, rancher/harvester-seeder:v0.4.1,harvester/v1.4.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-seeder:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, -rancher/harvester-seeder:v0.4.1,harvester/v1.4.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/manager,0.31.0,false,affected, rancher/harvester-upgrade:v1.4.0,harvester/v1.4.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-upgrade:v1.4.0 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-upgrade:v1.4.0,harvester/v1.4.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/harvester-upgrade:v1.4.0,harvester/v1.4.0,stdlib,v1.22.2,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/virtctl,"1.21.11, 1.22.4",false,affected, @@ -190,7 +186,6 @@ rancher/harvester-upgrade:v1.4.0,harvester/v1.4.0,stdlib,v1.22.2,gobinary,CVE-20 rancher/harvester-upgrade:v1.4.0,harvester/v1.4.0,stdlib,v1.22.2,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/virtctl,"1.22.7, 1.23.1",false,affected, rancher/harvester-upgrade:v1.4.0,harvester/v1.4.0,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.42.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/wharfie,0.46.0,false,affected, rancher/harvester-upgrade:v1.4.0,harvester/v1.4.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/wharfie,0.31.0,false,affected, -rancher/harvester-upgrade:v1.4.0,harvester/v1.4.0,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/upgrade-helper,0.31.0,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4.0,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4.0,qemu-img,8.2.6-150600.3.15.1,suse linux enterprise server,SUSE-SU-2024:3744-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),8.2.7-15061.6.coco15sp6.1,false,affected, @@ -201,10 +196,8 @@ rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4.0,qemu-tools,8.2.6- rancher/harvester-vm-import-controller:v0.4.1,harvester/v1.4.0,qemu-tools,8.2.6-150600.3.15.1,suse linux enterprise server,SUSE-SU-2024:4094-1,HIGH,,rancher/harvester-vm-import-controller:v0.4.1 (suse linux enterprise server 15.6),8.2.7-150600.3.20.1,false,affected, rancher/harvester-webhook:v1.4.0,harvester/v1.4.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester-webhook:v1.4.0 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester-webhook:v1.4.0,harvester/v1.4.0,github.com/rancher/steve,v0.0.0-20240911190153-79304d93b49b,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-webhook,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester-webhook:v1.4.0,harvester/v1.4.0,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-webhook,0.31.0,false,affected, rancher/harvester:v1.4.0,harvester/v1.4.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/harvester:v1.4.0 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/harvester:v1.4.0,harvester/v1.4.0,github.com/rancher/steve,v0.0.0-20240911190153-79304d93b49b,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester:v1.4.0,harvester/v1.4.0,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester,0.31.0,false,affected, rancher/klipper-helm:v0.9.2-build20240828,harvester/v1.4.0,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis,0.31.0,false,affected, rancher/klipper-helm:v0.9.2-build20240828,harvester/v1.4.0,stdlib,v1.23.0,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis,"1.22.7, 1.23.1",false,affected, rancher/klipper-helm:v0.9.2-build20240828,harvester/v1.4.0,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status,0.31.0,false,affected, @@ -784,7 +777,6 @@ rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.22.2,gobinary,CVE-2024-34156,H rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/bandwidth,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/cni,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/containerd,0.46.0,false,affected, -rancher/rancher:v2.9.2,harvester/v1.4.0,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/containerd,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd-shim-runc-v2,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/etcdctl,0.31.0,false,affected, @@ -794,7 +786,6 @@ rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.22.4,gobinary,CVE-2024-34156,H rancher/rancher:v2.9.2,harvester/v1.4.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/helm_v3,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/helm_v3,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/k3s,0.46.0,false,affected, -rancher/rancher:v2.9.2,harvester/v1.4.0,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/k3s,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/k3s,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/kustomize,"1.21.11, 1.22.4",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kustomize,"1.22.7, 1.23.1",false,affected, @@ -804,7 +795,6 @@ rancher/rancher:v2.9.2,harvester/v1.4.0,github.com/rancher/rancher,v2.9.2,gobina rancher/rancher:v2.9.2,harvester/v1.4.0,github.com/rancher/rancher,v2.9.2,gobinary,CVE-2024-22036,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-22036,usr/bin/rancher,"2.7.16, 2.8.9, 2.9.3",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,github.com/rancher/rancher,v2.9.2,gobinary,CVE-2022-45157,HIGH,https://avd.aquasec.com/nvd/cve-2022-45157,usr/bin/rancher,"2.9.3, 2.8.9",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,github.com/rancher/steve,v0.0.0-20240911190153-79304d93b49b,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/rancher,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/rancher:v2.9.2,harvester/v1.4.0,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher,0.31.0,false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,k8s.io/kubernetes,v1.30.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,usr/bin/rancher,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,k8s.io/kubernetes,v1.30.1,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,usr/bin/rancher,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher-machine,0.31.0,false,affected, @@ -819,7 +809,6 @@ rancher/rancher:v2.9.2,harvester/v1.4.0,stdlib,v1.21.3,gobinary,CVE-2024-34156,H rancher/rancher:v2.9.2,harvester/v1.4.0,github.com/docker/docker,v20.10.27+incompatible,gobinary,CVE-2024-41110,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-41110,usr/share/rancher/ui/assets/wins.exe,"23.0.15, 26.1.5, 27.1.1, 25.0.6",false,affected, rancher/rancher:v2.9.2,harvester/v1.4.0,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/share/rancher/ui/assets/wins.exe,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.29.8-build20240910,harvester/v1.4.0,golang.org/x/crypto,v0.23.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.29.9-rke2r1,harvester/v1.4.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.29.9-rke2r1,harvester/v1.4.0,github.com/docker/docker,v24.0.7+incompatible,gobinary,CVE-2024-41110,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-41110,bin/crictl,"23.0.15, 26.1.5, 27.1.1, 25.0.6",false,affected, rancher/rke2-runtime:v1.29.9-rke2r1,harvester/v1.4.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/rke2-runtime:v1.29.9-rke2r1,harvester/v1.4.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, diff --git a/docs/csv/report-harvester-v1.4.0-stats.csv b/docs/csv/report-harvester-v1.4.0-stats.csv index ea4e312..2689d09 100644 --- a/docs/csv/report-harvester-v1.4.0-stats.csv +++ b/docs/csv/report-harvester-v1.4.0-stats.csv @@ -15,8 +15,8 @@ longhornio/longhorn-manager:v1.7.2,0,2,2 longhornio/longhorn-share-manager:v1.7.2,0,1,1 longhornio/longhorn-ui:v1.7.2,0,1,1 longhornio/support-bundle-kit:v0.0.45,0,2,2 -rancher/fleet-agent:v0.10.2,0,1,1 -rancher/fleet:v0.10.2,0,6,6 +rancher/fleet-agent:v0.10.2,0,0,0 +rancher/fleet:v0.10.2,0,4,4 rancher/gitjob:v0.9.8,2,12,14 rancher/hardened-addon-resizer:1.8.20-build20240910,0,0,0 rancher/hardened-calico:v3.28.1-build20240911,0,9,9 @@ -25,12 +25,12 @@ rancher/hardened-cni-plugins:v1.5.1-build20240910,0,0,0 rancher/hardened-coredns:v1.11.1-build20240910,0,4,4 rancher/hardened-dns-node-cache:1.23.1-build20240910,0,5,5 rancher/hardened-etcd:v3.5.13-k3s1-build20240910,0,2,2 -rancher/hardened-flannel:v0.25.6-build20240910,0,9,9 +rancher/hardened-flannel:v0.25.6-build20240910,0,10,10 rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,0,1,1 rancher/hardened-kubernetes:v1.29.9-rke2r1-build20240912,0,13,13 rancher/hardened-multus-cni:v4.1.0-build20240910,0,0,0 rancher/harvester-cluster-repo:v1.4.0,0,1,1 -rancher/harvester-eventrouter:v0.3.2,0,2,2 +rancher/harvester-eventrouter:v0.3.2,0,1,1 rancher/harvester-load-balancer-webhook:v0.4.3,0,7,7 rancher/harvester-load-balancer:v0.4.3,0,7,7 rancher/harvester-network-controller:v0.5.5,0,10,10 @@ -42,11 +42,11 @@ rancher/harvester-node-disk-manager:v0.7.7,0,2,2 rancher/harvester-node-manager-webhook:v0.3.3,0,5,5 rancher/harvester-node-manager:v0.3.3,0,4,4 rancher/harvester-pcidevices:v0.4.1,0,2,2 -rancher/harvester-seeder:v0.4.1,0,2,2 -rancher/harvester-upgrade:v1.4.0,1,7,8 +rancher/harvester-seeder:v0.4.1,0,1,1 +rancher/harvester-upgrade:v1.4.0,1,6,7 rancher/harvester-vm-import-controller:v0.4.1,0,8,8 -rancher/harvester-webhook:v1.4.0,0,3,3 -rancher/harvester:v1.4.0,0,3,3 +rancher/harvester-webhook:v1.4.0,0,2,2 +rancher/harvester:v1.4.0,0,2,2 rancher/klipper-helm:v0.9.2-build20240828,0,6,6 rancher/klipper-lb:v0.4.9,0,0,0 rancher/kubectl:v1.20.2,4,43,47 @@ -75,9 +75,9 @@ rancher/mirrored-sig-storage-snapshot-controller:v6.2.1,3,24,27 rancher/mirrored-sig-storage-snapshot-validation-webhook:v6.2.2,3,23,26 rancher/nginx-ingress-controller:v1.10.4-hardened3,0,13,13 rancher/rancher-webhook:v0.5.2,0,2,2 -rancher/rancher:v2.9.2,11,43,54 +rancher/rancher:v2.9.2,11,40,51 rancher/rke2-cloud-provider:v1.29.8-build20240910,0,1,1 -rancher/rke2-runtime:v1.29.9-rke2r1,1,4,5 +rancher/rke2-runtime:v1.29.9-rke2r1,1,3,4 rancher/shell:v0.1.24,6,24,30 rancher/shell:v0.1.26,4,15,19 rancher/shell:v0.2.1,4,14,18 diff --git a/docs/csv/report-rancher-v2.10-head-cves.csv b/docs/csv/report-rancher-v2.10-head-cves.csv index 0991c34..4675526 100644 --- a/docs/csv/report-rancher-v2.10-head-cves.csv +++ b/docs/csv/report-rancher-v2.10-head-cves.csv @@ -228,9 +228,6 @@ rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.10-head,stdlib,v1.21.7,gobinary,C rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.10-head,stdlib,v1.21.7,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,opt/cni/bin/vlan,"1.21.11, 1.22.4",false,affected, rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.10-head,stdlib,v1.21.7,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,opt/cni/bin/vlan,"1.21.9, 1.22.2",false,affected, rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.10-head,stdlib,v1.21.7,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,opt/cni/bin/vlan,"1.22.7, 1.23.1",false,affected, -rancher/fleet-agent:v0.11.2-rc.2,rancher/v2.10-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetagent,0.31.0,false,affected, -rancher/fleet:v0.11.2-rc.2,rancher/v2.10-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleet,0.31.0,false,affected, -rancher/fleet:v0.11.2-rc.2,rancher/v2.10-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetcontroller,0.31.0,false,affected, rancher/gke-operator:v1.10.1-rc.3,rancher/v2.10-head,golang.org/x/crypto,v0.30.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/gke-operator,0.31.0,false,affected, rancher/hardened-calico:v3.28.1-build20240911,rancher/v2.10-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-calico:v3.28.1-build20240911 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-calico:v3.28.1-build20240911,rancher/v2.10-head,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-calico:v3.28.1-build20240911 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, @@ -279,6 +276,7 @@ rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10-head,libgmodule-2_0 rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10-head,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10-head,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, +rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10-head,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10-head,glib2-tools,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, @@ -286,18 +284,21 @@ rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10-head,libgio-2_0-0,2 rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10-head,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.10-head,glib2-tools,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.10-head,libgio-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.10-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.10-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.10-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.10-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.10-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.10-head,glib2-tools,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.10-head,libgio-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.10-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.10-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.10-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.10-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.10-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,rancher/v2.10-head,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,rancher/v2.10-head,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, @@ -334,7 +335,6 @@ rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10-head,github.com/rancher/ra rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10-head,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10-head,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/harvester-cloud-provider,0.46.0,false,affected, -rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10-head,golang.org/x/crypto,v0.16.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-cloud-provider,"1.22.7, 1.23.1",false,affected, rancher/harvester-csi-driver:v0.1.7,rancher/v2.10-head,libglib-2_0-0,2.70.5-150400.3.11.1,suse linux enterprise server,SUSE-SU-2024:4078-1,HIGH,,rancher/harvester-csi-driver:v0.1.7 (suse linux enterprise server 15.5),2.70.5-150400.3.17.1,false,affected, rancher/harvester-csi-driver:v0.1.7,rancher/v2.10-head,libprotobuf-lite25_1_0,25.1-150500.12.2.2,suse linux enterprise server,SUSE-SU-2024:3747-1,HIGH,,rancher/harvester-csi-driver:v0.1.7 (suse linux enterprise server 15.5),25.1-150500.12.5.1,false,affected, @@ -468,7 +468,6 @@ rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.10-head,golang.org/x/crypto rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.10-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status,0.31.0,false,affected, rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.10-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/helm,0.31.0,false,affected, rancher/kube-api-auth:v0.2.3,rancher/v2.10-head,github.com/rancher/steve,v0.0.0-20240913181958-99e479ba0f08,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/kube-api-auth,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/kube-api-auth:v0.2.3,rancher/v2.10-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-api-auth,0.31.0,false,affected, rancher/kubectl:v1.20.2,rancher/v2.10-head,stdlib,v1.15.5,gobinary,CVE-2022-23806,CRITICAL,https://avd.aquasec.com/nvd/cve-2022-23806,bin/kubectl,"1.16.14, 1.17.7",false,affected, rancher/kubectl:v1.20.2,rancher/v2.10-head,stdlib,v1.15.5,gobinary,CVE-2023-24538,CRITICAL,https://avd.aquasec.com/nvd/cve-2023-24538,bin/kubectl,"1.19.8, 1.20.3",false,affected, rancher/kubectl:v1.20.2,rancher/v2.10-head,stdlib,v1.15.5,gobinary,CVE-2023-24540,CRITICAL,https://avd.aquasec.com/nvd/cve-2023-24540,bin/kubectl,"1.19.9, 1.20.4",false,affected, @@ -563,12 +562,9 @@ rancher/kubectl:v1.29.2,rancher/v2.10-head,stdlib,v1.21.7,gobinary,CVE-2024-2479 rancher/kubectl:v1.29.2,rancher/v2.10-head,stdlib,v1.21.7,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,bin/kubectl,"1.21.9, 1.22.2",false,affected, rancher/kubectl:v1.29.2,rancher/v2.10-head,stdlib,v1.21.7,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/kubectl:v1.31.1,rancher/v2.10-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.28,rancher/v2.10-head,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.10-head,stdlib,v1.21.4,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/local-path-provisioner,"1.21.11, 1.22.4",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.10-head,stdlib,v1.21.4,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/local-path-provisioner,"1.21.9, 1.22.2",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.10-head,stdlib,v1.21.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/local-path-provisioner,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.30,rancher/v2.10-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, -rancher/machine:v0.15.0-rancher124,rancher/v2.10-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rancher-machine,0.31.0,false,affected, rancher/mirrored-brancz-kube-rbac-proxy:v0.18.0,rancher/v2.10-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/kube-rbac-proxy,0.31.0,true,affected, rancher/mirrored-brancz-kube-rbac-proxy:v0.18.0,rancher/v2.10-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kube-rbac-proxy,"1.22.7, 1.23.1",true,affected, rancher/mirrored-calico-apiserver:v3.28.1,rancher/v2.10-head,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,code/apiserver,0.31.0,true,affected, @@ -729,6 +725,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10- rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10-head,expat-libs,2.2.9-11.ph4,photon,CVE-2023-52425,HIGH,https://avd.aquasec.com/nvd/cve-2023-52425,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-1.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10-head,expat-libs,2.2.9-11.ph4,photon,CVE-2024-28757,HIGH,https://avd.aquasec.com/nvd/cve-2024-28757,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-2.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10-head,expat-libs,2.2.9-11.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10-head,glib,2.68.4-1.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10-head,glibc,2.32-15.ph4,photon,CVE-2024-2961,HIGH,https://avd.aquasec.com/nvd/cve-2024-2961,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.32-17.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10-head,glibc-iconv,2.32-15.ph4,photon,CVE-2024-2961,HIGH,https://avd.aquasec.com/nvd/cve-2024-2961,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.32-17.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10-head,krb5,1.17-10.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),1.17-12.ph4,true,affected, @@ -758,6 +755,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10- rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10-head,glib,2.68.4-2.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10-head,krb5,1.17-10.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10-head,krb5,1.17-10.ph4,photon,CVE-2024-37370,HIGH,https://avd.aquasec.com/nvd/cve-2024-37370,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10-head,nss-libs,3.72-4.ph4,photon,CVE-2024-0743,HIGH,https://avd.aquasec.com/nvd/cve-2024-0743,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),3.72-6.ph4,true,affected, @@ -777,6 +775,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10- rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10-head,glib,2.68.4-2.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10-head,krb5,1.17-11.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10-head,krb5,1.17-11.ph4,photon,CVE-2024-37370,HIGH,https://avd.aquasec.com/nvd/cve-2024-37370,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10-head,nss-libs,3.72-5.ph4,photon,CVE-2024-0743,HIGH,https://avd.aquasec.com/nvd/cve-2024-0743,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),3.72-6.ph4,true,affected, @@ -1925,6 +1924,9 @@ rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.10-head,libglib-2_0-0,2.78. rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.10-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.10-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.10-head,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/consul,0.31.0,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.10-head,libpython3_12-1_0,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.10-head,python312,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.10-head,python312-base,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.10-head,libexpat,2.6.2-r0,alpine,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.10-head,libexpat,2.6.2-r0,alpine,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.10-head,libexpat,2.6.2-r0,alpine,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, @@ -2125,7 +2127,6 @@ rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.22.2,gobinary,CVE-2024-3 rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/bandwidth,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/cni,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/containerd,0.46.0,false,affected, -rancher/rancher:v2.10-head,rancher/v2.10-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/containerd,0.31.0,false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd-shim-runc-v2,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/etcdctl,0.31.0,false,affected, @@ -2134,12 +2135,10 @@ rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.21.10,gobinary,CVE-2024- rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/firewall,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/helm_v3,0.31.0,false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/k3s,0.46.0,false,affected, -rancher/rancher:v2.10-head,rancher/v2.10-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/k3s,0.31.0,false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/k3s,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/kustomize,"1.21.11, 1.22.4",false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kustomize,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,golang.org/x/crypto,v0.30.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher,0.31.0,false,affected, -rancher/rancher:v2.10-head,rancher/v2.10-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher-machine,0.31.0,false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/runc,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,github.com/rancher/norman,v0.0.0-20210709145327-afd06f533ca3,gobinary,CVE-2023-32193,HIGH,https://avd.aquasec.com/nvd/cve-2023-32193,usr/bin/telemetry,0.0.0-20240207153100-3bb70b772b52,false,affected, rancher/rancher:v2.10-head,rancher/v2.10-head,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/telemetry,0.31.0,false,affected, @@ -2167,21 +2166,13 @@ rancher/rke2-cloud-provider:v1.30.4-build20240910,rancher/v2.10-head,golang.org/ rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016,rancher/v2.10-head,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.31.0-build20240910,rancher/v2.10-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.31.2-0.20241016053446-0955fa330f90-build20241016,rancher/v2.10-head,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.10-head,k8s.io/kubernetes,v1.28.0-rc.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-runtime:v1.29.11-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.29.11-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-runtime:v1.30.7-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.30.7-rke2r1,rancher/v2.10-head,k8s.io/kubernetes,v1.30.0,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.30.7-rke2r1,rancher/v2.10-head,k8s.io/kubernetes,v1.30.0,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,bin/crictl,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.30.7-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-runtime:v1.31.3-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.31.3-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-upgrade:v1.28.15-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, -rancher/rke2-upgrade:v1.29.11-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, -rancher/rke2-upgrade:v1.30.7-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, -rancher/rke2-upgrade:v1.31.3-rke2r1,rancher/v2.10-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, rancher/security-scan:v0.5.2,rancher/v2.10-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-bench,0.31.0,false,affected, rancher/shell:v0.2.1,rancher/v2.10-head,curl,8.6.0-150600.2.2,suse linux enterprise server,SUSE-SU-2024:2784-1,HIGH,,rancher/shell:v0.2.1 (suse linux enterprise server 15.6),8.6.0-150600.4.3.1,false,affected, rancher/shell:v0.2.1,rancher/v2.10-head,libcurl4,8.6.0-150600.2.2,suse linux enterprise server,SUSE-SU-2024:2784-1,HIGH,,rancher/shell:v0.2.1 (suse linux enterprise server 15.6),8.6.0-150600.4.3.1,false,affected, diff --git a/docs/csv/report-rancher-v2.10-head-stats.csv b/docs/csv/report-rancher-v2.10-head-stats.csv index 61f8fa5..f4f522a 100644 --- a/docs/csv/report-rancher-v2.10-head-stats.csv +++ b/docs/csv/report-rancher-v2.10-head-stats.csv @@ -8,8 +8,8 @@ rancher/cis-operator:v1.3.4,0,0,0 rancher/eks-operator:v1.10.1-rc.2,0,0,0 rancher/flannel-cni:v0.3.0-rancher9,11,54,65 rancher/flannel-cni:v1.4.1-rancher1,11,21,32 -rancher/fleet-agent:v0.11.2-rc.2,0,1,1 -rancher/fleet:v0.11.2-rc.2,0,2,2 +rancher/fleet-agent:v0.11.2,0,0,0 +rancher/fleet:v0.11.2,0,0,0 rancher/gke-operator:v1.10.1-rc.3,0,1,1 rancher/hardened-addon-resizer:1.8.20-build20240910,0,0,0 rancher/hardened-addon-resizer:1.8.20-build20241001,0,0,0 @@ -27,10 +27,10 @@ rancher/hardened-dns-node-cache:1.23.1-build20240910,0,5,5 rancher/hardened-dns-node-cache:1.23.1-build20241008,0,5,5 rancher/hardened-etcd:v3.5.13-k3s1-build20240910,0,2,2 rancher/hardened-etcd:v3.5.16-k3s1-build20241106,0,2,2 -rancher/hardened-flannel:v0.25.6-build20240910,0,9,9 -rancher/hardened-flannel:v0.25.7-build20241008,0,6,6 -rancher/hardened-flannel:v0.26.0-build20241024,0,6,6 -rancher/hardened-flannel:v0.26.1-build20241107,0,6,6 +rancher/hardened-flannel:v0.25.6-build20240910,0,10,10 +rancher/hardened-flannel:v0.25.7-build20241008,0,7,7 +rancher/hardened-flannel:v0.26.0-build20241024,0,7,7 +rancher/hardened-flannel:v0.26.1-build20241107,0,7,7 rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,0,1,1 rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,0,1,1 rancher/hardened-kubernetes:v1.28.15-rke2r1-build20241023,0,6,6 @@ -42,7 +42,7 @@ rancher/hardened-multus-cni:v4.1.2-build20241011,0,0,0 rancher/hardened-multus-cni:v4.1.3-build20241028,0,5,5 rancher/hardened-whereabouts:v0.8.0-build20240910,0,0,0 rancher/hardened-whereabouts:v0.8.0-build20241011,0,0,0 -rancher/harvester-cloud-provider:v0.2.2,0,6,6 +rancher/harvester-cloud-provider:v0.2.2,0,5,5 rancher/harvester-csi-driver:v0.1.7,0,9,9 rancher/harvester-csi-driver:v0.2.1,0,1,1 rancher/harvester-csi-driver:v0.2.2,0,1,1 @@ -62,7 +62,7 @@ rancher/k3s-upgrade:v1.31.3-k3s1,0,0,0 rancher/klipper-helm:v0.9.2-build20240828,0,6,6 rancher/klipper-helm:v0.9.3-build20241008,0,3,3 rancher/klipper-lb:v0.4.9,0,0,0 -rancher/kube-api-auth:v0.2.3,0,2,2 +rancher/kube-api-auth:v0.2.3,0,1,1 rancher/kubectl:v1.20.2,4,43,47 rancher/kubectl:v1.23.3,4,35,39 rancher/kubectl:v1.28.14,0,1,1 @@ -70,9 +70,9 @@ rancher/kubectl:v1.29.0,1,2,3 rancher/kubectl:v1.29.2,1,2,3 rancher/kubectl:v1.30.7,0,0,0 rancher/kubectl:v1.31.1,0,1,1 -rancher/local-path-provisioner:v0.0.28,1,3,4 -rancher/local-path-provisioner:v0.0.30,0,1,1 -rancher/machine:v0.15.0-rancher124,0,1,1 +rancher/local-path-provisioner:v0.0.28,1,2,3 +rancher/local-path-provisioner:v0.0.30,0,0,0 +rancher/machine:v0.15.0-rancher124,0,0,0 rancher/mirrored-bci-busybox:15.6.24.2,0,0,0 rancher/mirrored-bci-micro:15.6.24.2,0,0,0 rancher/mirrored-brancz-kube-rbac-proxy:v0.18.0,0,2,2 @@ -138,9 +138,9 @@ rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.27.0,3,15,18 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.28.0,1,9,10 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.29.0,1,4,5 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.30.1,1,3,4 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,7,26,33 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,6,15,21 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,5,12,17 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,8,26,34 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,7,15,22 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,6,12,18 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.2.0,5,18,23 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.3.0,4,15,19 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.3.1,3,9,12 @@ -239,7 +239,7 @@ rancher/mirrored-metrics-server:v0.7.2,0,2,2 rancher/mirrored-neuvector-compliance-config:latest,0,0,0 rancher/mirrored-neuvector-controller:5.4.1,0,8,8 rancher/mirrored-neuvector-enforcer:5.4.1,0,6,6 -rancher/mirrored-neuvector-manager:5.4.1,0,0,0 +rancher/mirrored-neuvector-manager:5.4.1,0,3,3 rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,2,13,15 rancher/mirrored-neuvector-registry-adapter:0.1.3,0,2,2 rancher/mirrored-neuvector-scanner:latest,0,1,1 @@ -284,7 +284,7 @@ rancher/pushprox-proxy:v0.1.4-rc.4-rancher2-proxy,0,0,0 rancher/rancher-agent:v2.10-head,1,3,4 rancher/rancher-csp-adapter:v5.0.1,0,0,0 rancher/rancher-webhook:v0.6.1,0,0,0 -rancher/rancher:v2.10-head,5,33,38 +rancher/rancher:v2.10-head,5,30,35 rancher/rke-tools:v0.1.105,2,9,11 rancher/rke2-cloud-provider:v1.28.13-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.28.15-0.20241016053552-63bfb1936862-build20241016,0,1,1 @@ -294,14 +294,14 @@ rancher/rke2-cloud-provider:v1.30.4-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016,0,1,1 rancher/rke2-cloud-provider:v1.31.0-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.31.2-0.20241016053446-0955fa330f90-build20241016,0,1,1 -rancher/rke2-runtime:v1.28.15-rke2r1,0,3,3 -rancher/rke2-runtime:v1.29.11-rke2r1,0,2,2 -rancher/rke2-runtime:v1.30.7-rke2r1,0,4,4 -rancher/rke2-runtime:v1.31.3-rke2r1,0,2,2 -rancher/rke2-upgrade:v1.28.15-rke2r1,0,1,1 -rancher/rke2-upgrade:v1.29.11-rke2r1,0,1,1 -rancher/rke2-upgrade:v1.30.7-rke2r1,0,1,1 -rancher/rke2-upgrade:v1.31.3-rke2r1,0,1,1 +rancher/rke2-runtime:v1.28.15-rke2r1,0,2,2 +rancher/rke2-runtime:v1.29.11-rke2r1,0,1,1 +rancher/rke2-runtime:v1.30.7-rke2r1,0,3,3 +rancher/rke2-runtime:v1.31.3-rke2r1,0,1,1 +rancher/rke2-upgrade:v1.28.15-rke2r1,0,0,0 +rancher/rke2-upgrade:v1.29.11-rke2r1,0,0,0 +rancher/rke2-upgrade:v1.30.7-rke2r1,0,0,0 +rancher/rke2-upgrade:v1.31.3-rke2r1,0,0,0 rancher/security-scan:v0.5.2,0,1,1 rancher/shell:v0.2.1,4,14,18 rancher/shell:v0.3.0,2,6,8 diff --git a/docs/csv/report-rancher-v2.10.0-cves.csv b/docs/csv/report-rancher-v2.10.0-cves.csv index 2e95987..8d18194 100644 --- a/docs/csv/report-rancher-v2.10.0-cves.csv +++ b/docs/csv/report-rancher-v2.10.0-cves.csv @@ -190,10 +190,7 @@ rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.10.0,stdlib,v1.21.7,gobinary,CVE- rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.10.0,stdlib,v1.21.7,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,opt/cni/bin/vlan,"1.21.11, 1.22.4",false,affected, rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.10.0,stdlib,v1.21.7,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,opt/cni/bin/vlan,"1.21.9, 1.22.2",false,affected, rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.10.0,stdlib,v1.21.7,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,opt/cni/bin/vlan,"1.22.7, 1.23.1",false,affected, -rancher/fleet-agent:v0.11.1,rancher/v2.10.0,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetagent,0.31.0,false,affected, rancher/fleet:v0.11.1,rancher/v2.10.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/fleet:v0.11.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, -rancher/fleet:v0.11.1,rancher/v2.10.0,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleet,0.31.0,false,affected, -rancher/fleet:v0.11.1,rancher/v2.10.0,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetcontroller,0.31.0,false,affected, rancher/gke-operator:v1.10.0,rancher/v2.10.0,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/gke-operator,0.31.0,false,affected, rancher/hardened-calico:v3.28.1-build20240911,rancher/v2.10.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-calico:v3.28.1-build20240911 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-calico:v3.28.1-build20240911,rancher/v2.10.0,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-calico:v3.28.1-build20240911 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, @@ -234,6 +231,7 @@ rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10.0,libgmodule-2_0-0, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10.0,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10.0,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10.0,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, +rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10.0,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10.0,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.10.0,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10.0,glib2-tools,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, @@ -241,6 +239,7 @@ rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10.0,libgio-2_0-0,2.78 rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10.0,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10.0,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10.0,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.10.0,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,rancher/v2.10.0,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,rancher/v2.10.0,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, @@ -272,7 +271,6 @@ rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10.0,github.com/rancher/ranch rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10.0,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10.0,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10.0,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/harvester-cloud-provider,0.46.0,false,affected, -rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10.0,golang.org/x/crypto,v0.16.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.10.0,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-cloud-provider,"1.22.7, 1.23.1",false,affected, rancher/harvester-csi-driver:v0.1.7,rancher/v2.10.0,libglib-2_0-0,2.70.5-150400.3.11.1,suse linux enterprise server,SUSE-SU-2024:4078-1,HIGH,,rancher/harvester-csi-driver:v0.1.7 (suse linux enterprise server 15.5),2.70.5-150400.3.17.1,false,affected, rancher/harvester-csi-driver:v0.1.7,rancher/v2.10.0,libprotobuf-lite25_1_0,25.1-150500.12.2.2,suse linux enterprise server,SUSE-SU-2024:3747-1,HIGH,,rancher/harvester-csi-driver:v0.1.7 (suse linux enterprise server 15.5),25.1-150500.12.5.1,false,affected, @@ -404,7 +402,6 @@ rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.10.0,golang.org/x/crypto,v0 rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.10.0,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status,0.31.0,false,affected, rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.10.0,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/helm,0.31.0,false,affected, rancher/kube-api-auth:v0.2.3,rancher/v2.10.0,github.com/rancher/steve,v0.0.0-20240913181958-99e479ba0f08,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/kube-api-auth,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/kube-api-auth:v0.2.3,rancher/v2.10.0,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-api-auth,0.31.0,false,affected, rancher/kubectl:v1.20.2,rancher/v2.10.0,stdlib,v1.15.5,gobinary,CVE-2022-23806,CRITICAL,https://avd.aquasec.com/nvd/cve-2022-23806,bin/kubectl,"1.16.14, 1.17.7",false,affected, rancher/kubectl:v1.20.2,rancher/v2.10.0,stdlib,v1.15.5,gobinary,CVE-2023-24538,CRITICAL,https://avd.aquasec.com/nvd/cve-2023-24538,bin/kubectl,"1.19.8, 1.20.3",false,affected, rancher/kubectl:v1.20.2,rancher/v2.10.0,stdlib,v1.15.5,gobinary,CVE-2023-24540,CRITICAL,https://avd.aquasec.com/nvd/cve-2023-24540,bin/kubectl,"1.19.9, 1.20.4",false,affected, @@ -499,13 +496,10 @@ rancher/kubectl:v1.29.2,rancher/v2.10.0,stdlib,v1.21.7,gobinary,CVE-2024-24790,C rancher/kubectl:v1.29.2,rancher/v2.10.0,stdlib,v1.21.7,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,bin/kubectl,"1.21.9, 1.22.2",false,affected, rancher/kubectl:v1.29.2,rancher/v2.10.0,stdlib,v1.21.7,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/kubectl:v1.31.1,rancher/v2.10.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.28,rancher/v2.10.0,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.10.0,stdlib,v1.21.4,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/local-path-provisioner,"1.21.11, 1.22.4",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.10.0,stdlib,v1.21.4,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/local-path-provisioner,"1.21.9, 1.22.2",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.10.0,stdlib,v1.21.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/local-path-provisioner,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.30,rancher/v2.10.0,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/machine:v0.15.0-rancher122,rancher/v2.10.0,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/machine:v0.15.0-rancher122 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, -rancher/machine:v0.15.0-rancher122,rancher/v2.10.0,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rancher-machine,0.31.0,false,affected, rancher/mirrored-brancz-kube-rbac-proxy:v0.18.0,rancher/v2.10.0,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/kube-rbac-proxy,0.31.0,true,affected, rancher/mirrored-brancz-kube-rbac-proxy:v0.18.0,rancher/v2.10.0,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kube-rbac-proxy,"1.22.7, 1.23.1",true,affected, rancher/mirrored-calico-apiserver:v3.28.1,rancher/v2.10.0,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,code/apiserver,0.31.0,true,affected, @@ -653,6 +647,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10. rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10.0,expat-libs,2.2.9-11.ph4,photon,CVE-2023-52425,HIGH,https://avd.aquasec.com/nvd/cve-2023-52425,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-1.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10.0,expat-libs,2.2.9-11.ph4,photon,CVE-2024-28757,HIGH,https://avd.aquasec.com/nvd/cve-2024-28757,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-2.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10.0,expat-libs,2.2.9-11.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10.0,glib,2.68.4-1.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10.0,glibc,2.32-15.ph4,photon,CVE-2024-2961,HIGH,https://avd.aquasec.com/nvd/cve-2024-2961,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.32-17.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10.0,glibc-iconv,2.32-15.ph4,photon,CVE-2024-2961,HIGH,https://avd.aquasec.com/nvd/cve-2024-2961,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.32-17.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.10.0,krb5,1.17-10.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),1.17-12.ph4,true,affected, @@ -682,6 +677,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10. rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10.0,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10.0,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10.0,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10.0,glib,2.68.4-2.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10.0,krb5,1.17-10.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10.0,krb5,1.17-10.ph4,photon,CVE-2024-37370,HIGH,https://avd.aquasec.com/nvd/cve-2024-37370,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.10.0,nss-libs,3.72-4.ph4,photon,CVE-2024-0743,HIGH,https://avd.aquasec.com/nvd/cve-2024-0743,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),3.72-6.ph4,true,affected, @@ -701,6 +697,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10. rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10.0,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10.0,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10.0,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10.0,glib,2.68.4-2.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10.0,krb5,1.17-11.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10.0,krb5,1.17-11.ph4,photon,CVE-2024-37370,HIGH,https://avd.aquasec.com/nvd/cve-2024-37370,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.10.0,nss-libs,3.72-5.ph4,photon,CVE-2024-0743,HIGH,https://avd.aquasec.com/nvd/cve-2024-0743,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),3.72-6.ph4,true,affected, @@ -2127,6 +2124,9 @@ rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.10.0,libglib-2_0-0,2.78.6-1 rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.10.0,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.10.0,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.10.0,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/consul,0.31.0,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.10.0,libpython3_12-1_0,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.10.0,python312,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.10.0,python312-base,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.10.0,libexpat,2.6.2-r0,alpine,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.10.0,libexpat,2.6.2-r0,alpine,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.10.0,libexpat,2.6.2-r0,alpine,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, @@ -2307,7 +2307,6 @@ rancher/pushprox-client:v0.1.3-rancher2-client,rancher/v2.10.0,stdlib,v1.22.3,go rancher/pushprox-client:v0.1.3-rancher2-client,rancher/v2.10.0,stdlib,v1.22.3,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/pushprox-client,"1.22.7, 1.23.1",false,affected, rancher/pushprox-proxy:v0.1.3-rancher2-proxy,rancher/v2.10.0,stdlib,v1.22.3,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/pushprox-proxy,"1.21.11, 1.22.4",false,affected, rancher/pushprox-proxy:v0.1.3-rancher2-proxy,rancher/v2.10.0,stdlib,v1.22.3,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/pushprox-proxy,"1.22.7, 1.23.1",false,affected, -rancher/rancher-agent:v2.10.0,rancher/v2.10.0,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/agent,0.31.0,false,affected, rancher/rancher-agent:v2.10.0,rancher/v2.10.0,stdlib,v1.20.13,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/kubectl,"1.21.11, 1.22.4",false,affected, rancher/rancher-agent:v2.10.0,rancher/v2.10.0,stdlib,v1.20.13,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/kubectl,"1.21.9, 1.22.2",false,affected, rancher/rancher-agent:v2.10.0,rancher/v2.10.0,stdlib,v1.20.13,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kubectl,"1.22.7, 1.23.1",false,affected, @@ -2326,7 +2325,6 @@ rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.22.2,gobinary,CVE-2024-34156,H rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/bandwidth,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/cni,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/containerd,0.46.0,false,affected, -rancher/rancher:v2.10.0,rancher/v2.10.0,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/containerd,0.31.0,false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd-shim-runc-v2,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/etcdctl,0.31.0,false,affected, @@ -2335,12 +2333,9 @@ rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.21.10,gobinary,CVE-2024-34156, rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/firewall,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/helm_v3,0.31.0,false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/k3s,0.46.0,false,affected, -rancher/rancher:v2.10.0,rancher/v2.10.0,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/k3s,0.31.0,false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/k3s,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/kustomize,"1.21.11, 1.22.4",false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kustomize,"1.22.7, 1.23.1",false,affected, -rancher/rancher:v2.10.0,rancher/v2.10.0,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher,0.31.0,false,affected, -rancher/rancher:v2.10.0,rancher/v2.10.0,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher-machine,0.31.0,false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/runc,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,github.com/rancher/norman,v0.0.0-20210709145327-afd06f533ca3,gobinary,CVE-2023-32193,HIGH,https://avd.aquasec.com/nvd/cve-2023-32193,usr/bin/telemetry,0.0.0-20240207153100-3bb70b772b52,false,affected, rancher/rancher:v2.10.0,rancher/v2.10.0,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/telemetry,0.31.0,false,affected, @@ -2368,21 +2363,13 @@ rancher/rke2-cloud-provider:v1.30.4-build20240910,rancher/v2.10.0,golang.org/x/c rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016,rancher/v2.10.0,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.31.0-build20240910,rancher/v2.10.0,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.31.2-0.20241016053446-0955fa330f90-build20241016,rancher/v2.10.0,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.10.0,k8s.io/kubernetes,v1.28.0-rc.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-runtime:v1.29.10-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.29.10-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-runtime:v1.30.6-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.30.6-rke2r1,rancher/v2.10.0,k8s.io/kubernetes,v1.30.0,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.30.6-rke2r1,rancher/v2.10.0,k8s.io/kubernetes,v1.30.0,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,bin/crictl,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.30.6-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-runtime:v1.31.2-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.31.2-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-upgrade:v1.28.15-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, -rancher/rke2-upgrade:v1.29.10-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, -rancher/rke2-upgrade:v1.30.6-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, -rancher/rke2-upgrade:v1.31.2-rke2r1,rancher/v2.10.0,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, rancher/security-scan:v0.5.1,rancher/v2.10.0,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-bench,0.31.0,false,affected, rancher/shell:v0.2.1,rancher/v2.10.0,curl,8.6.0-150600.2.2,suse linux enterprise server,SUSE-SU-2024:2784-1,HIGH,,rancher/shell:v0.2.1 (suse linux enterprise server 15.6),8.6.0-150600.4.3.1,false,affected, rancher/shell:v0.2.1,rancher/v2.10.0,libcurl4,8.6.0-150600.2.2,suse linux enterprise server,SUSE-SU-2024:2784-1,HIGH,,rancher/shell:v0.2.1 (suse linux enterprise server 15.6),8.6.0-150600.4.3.1,false,affected, diff --git a/docs/csv/report-rancher-v2.10.0-stats.csv b/docs/csv/report-rancher-v2.10.0-stats.csv index a23eb6c..1eb1cc7 100644 --- a/docs/csv/report-rancher-v2.10.0-stats.csv +++ b/docs/csv/report-rancher-v2.10.0-stats.csv @@ -7,8 +7,8 @@ rancher/cis-operator:v1.3.1,0,0,0 rancher/eks-operator:v1.10.0,0,0,0 rancher/flannel-cni:v0.3.0-rancher9,11,54,65 rancher/flannel-cni:v1.4.1-rancher1,11,21,32 -rancher/fleet-agent:v0.11.1,0,1,1 -rancher/fleet:v0.11.1,0,3,3 +rancher/fleet-agent:v0.11.1,0,0,0 +rancher/fleet:v0.11.1,0,1,1 rancher/gke-operator:v1.10.0,0,1,1 rancher/hardened-addon-resizer:1.8.20-build20240910,0,0,0 rancher/hardened-addon-resizer:1.8.20-build20241001,0,0,0 @@ -23,8 +23,8 @@ rancher/hardened-coredns:v1.11.3-build20241018,0,1,1 rancher/hardened-dns-node-cache:1.23.1-build20240910,0,5,5 rancher/hardened-dns-node-cache:1.23.1-build20241008,0,5,5 rancher/hardened-etcd:v3.5.13-k3s1-build20240910,0,2,2 -rancher/hardened-flannel:v0.25.6-build20240910,0,9,9 -rancher/hardened-flannel:v0.25.7-build20241008,0,6,6 +rancher/hardened-flannel:v0.25.6-build20240910,0,10,10 +rancher/hardened-flannel:v0.25.7-build20241008,0,7,7 rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,0,1,1 rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,0,1,1 rancher/hardened-kubernetes:v1.28.15-rke2r1-build20241023,0,6,6 @@ -35,7 +35,7 @@ rancher/hardened-multus-cni:v4.1.0-build20240910,0,0,0 rancher/hardened-multus-cni:v4.1.2-build20241011,0,0,0 rancher/hardened-whereabouts:v0.8.0-build20240910,0,0,0 rancher/hardened-whereabouts:v0.8.0-build20241011,0,0,0 -rancher/harvester-cloud-provider:v0.2.2,0,6,6 +rancher/harvester-cloud-provider:v0.2.2,0,5,5 rancher/harvester-csi-driver:v0.1.7,0,9,9 rancher/harvester-csi-driver:v0.2.1,0,1,1 rancher/harvester-csi-driver:v0.2.2,0,1,1 @@ -54,7 +54,7 @@ rancher/k3s-upgrade:v1.31.2-k3s1,0,0,0 rancher/klipper-helm:v0.9.2-build20240828,0,6,6 rancher/klipper-helm:v0.9.3-build20241008,0,3,3 rancher/klipper-lb:v0.4.9,0,0,0 -rancher/kube-api-auth:v0.2.3,0,2,2 +rancher/kube-api-auth:v0.2.3,0,1,1 rancher/kubectl:v1.20.2,4,43,47 rancher/kubectl:v1.23.3,4,35,39 rancher/kubectl:v1.28.14,0,1,1 @@ -62,9 +62,9 @@ rancher/kubectl:v1.29.0,1,2,3 rancher/kubectl:v1.29.2,1,2,3 rancher/kubectl:v1.30.7,0,0,0 rancher/kubectl:v1.31.1,0,1,1 -rancher/local-path-provisioner:v0.0.28,1,3,4 -rancher/local-path-provisioner:v0.0.30,0,1,1 -rancher/machine:v0.15.0-rancher122,0,2,2 +rancher/local-path-provisioner:v0.0.28,1,2,3 +rancher/local-path-provisioner:v0.0.30,0,0,0 +rancher/machine:v0.15.0-rancher122,0,1,1 rancher/mirrored-bci-busybox:15.6.24.2,0,0,0 rancher/mirrored-bci-micro:15.6.24.2,0,0,0 rancher/mirrored-brancz-kube-rbac-proxy:v0.18.0,0,2,2 @@ -114,9 +114,9 @@ rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.27.0,3,15,18 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.28.0,1,9,10 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.29.0,1,4,5 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.30.1,1,3,4 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,7,26,33 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,6,15,21 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,5,12,17 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,8,26,34 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,7,15,22 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,6,12,18 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.2.0,5,18,23 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.3.0,4,15,19 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.3.1,3,9,12 @@ -210,7 +210,7 @@ rancher/mirrored-metrics-server:v0.7.2,0,2,2 rancher/mirrored-neuvector-compliance-config:latest,0,0,0 rancher/mirrored-neuvector-controller:5.4.1,0,8,8 rancher/mirrored-neuvector-enforcer:5.4.1,0,6,6 -rancher/mirrored-neuvector-manager:5.4.1,0,0,0 +rancher/mirrored-neuvector-manager:5.4.1,0,3,3 rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,2,13,15 rancher/mirrored-neuvector-registry-adapter:0.1.3,0,2,2 rancher/mirrored-neuvector-scanner:latest,0,1,1 @@ -252,10 +252,10 @@ rancher/nginx-ingress-controller:v1.10.5-hardened3,0,7,7 rancher/prometheus-federator:v0.4.3,2,13,15 rancher/pushprox-client:v0.1.3-rancher2-client,1,1,2 rancher/pushprox-proxy:v0.1.3-rancher2-proxy,1,1,2 -rancher/rancher-agent:v2.10.0,1,3,4 +rancher/rancher-agent:v2.10.0,1,2,3 rancher/rancher-csp-adapter:v5.0.1,0,0,0 rancher/rancher-webhook:v0.6.1,0,0,0 -rancher/rancher:v2.10.0,5,33,38 +rancher/rancher:v2.10.0,5,29,34 rancher/rke-tools:v0.1.105,2,9,11 rancher/rke2-cloud-provider:v1.28.13-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.28.15-0.20241016053552-63bfb1936862-build20241016,0,1,1 @@ -265,14 +265,14 @@ rancher/rke2-cloud-provider:v1.30.4-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016,0,1,1 rancher/rke2-cloud-provider:v1.31.0-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.31.2-0.20241016053446-0955fa330f90-build20241016,0,1,1 -rancher/rke2-runtime:v1.28.15-rke2r1,0,3,3 -rancher/rke2-runtime:v1.29.10-rke2r1,0,2,2 -rancher/rke2-runtime:v1.30.6-rke2r1,0,4,4 -rancher/rke2-runtime:v1.31.2-rke2r1,0,2,2 -rancher/rke2-upgrade:v1.28.15-rke2r1,0,1,1 -rancher/rke2-upgrade:v1.29.10-rke2r1,0,1,1 -rancher/rke2-upgrade:v1.30.6-rke2r1,0,1,1 -rancher/rke2-upgrade:v1.31.2-rke2r1,0,1,1 +rancher/rke2-runtime:v1.28.15-rke2r1,0,2,2 +rancher/rke2-runtime:v1.29.10-rke2r1,0,1,1 +rancher/rke2-runtime:v1.30.6-rke2r1,0,3,3 +rancher/rke2-runtime:v1.31.2-rke2r1,0,1,1 +rancher/rke2-upgrade:v1.28.15-rke2r1,0,0,0 +rancher/rke2-upgrade:v1.29.10-rke2r1,0,0,0 +rancher/rke2-upgrade:v1.30.6-rke2r1,0,0,0 +rancher/rke2-upgrade:v1.31.2-rke2r1,0,0,0 rancher/security-scan:v0.5.1,0,1,1 rancher/shell:v0.2.1,4,14,18 rancher/shell:v0.3.0,2,6,8 diff --git a/docs/csv/report-rancher-v2.8-head-cves.csv b/docs/csv/report-rancher-v2.8-head-cves.csv index ed9bbfa..38c5cb6 100644 --- a/docs/csv/report-rancher-v2.8-head-cves.csv +++ b/docs/csv/report-rancher-v2.8-head-cves.csv @@ -200,9 +200,6 @@ rancher/flannel-cni:v0.3.0-rancher9,rancher/v2.8-head,stdlib,v1.20.4,gobinary,CV rancher/flannel-cni:v0.3.0-rancher9,rancher/v2.8-head,stdlib,v1.20.4,gobinary,CVE-2023-45283,HIGH,https://avd.aquasec.com/nvd/cve-2023-45283,opt/cni/bin/vlan,"1.20.11, 1.21.4, 1.20.12, 1.21.5",false,affected, rancher/flannel-cni:v0.3.0-rancher9,rancher/v2.8-head,stdlib,v1.20.4,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,opt/cni/bin/vlan,"1.21.9, 1.22.2",false,affected, rancher/flannel-cni:v0.3.0-rancher9,rancher/v2.8-head,stdlib,v1.20.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,opt/cni/bin/vlan,"1.22.7, 1.23.1",false,affected, -rancher/fleet-agent:v0.9.12,rancher/v2.8-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleet,0.31.0,false,affected, -rancher/fleet-agent:v0.9.12,rancher/v2.8-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetagent,0.31.0,false,affected, -rancher/fleet:v0.9.12,rancher/v2.8-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetcontroller,0.31.0,false,affected, rancher/gitjob:v0.9.18,rancher/v2.8-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/gitcloner,0.31.0,false,affected, rancher/gitjob:v0.9.18,rancher/v2.8-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/gitjob,0.31.0,false,affected, rancher/gke-operator:v1.2.6-rc.1,rancher/v2.8-head,golang.org/x/crypto,v0.30.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/gke-operator,0.31.0,false,affected, @@ -428,6 +425,7 @@ rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8-head,libopenssl-3-fi rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8-head,libopenssl3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3106-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.15.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8-head,libopenssl3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8-head,libprotobuf-lite25_1_0,25.1-150600.16.4.2,suse linux enterprise server,SUSE-SU-2024:3745-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),25.1-150600.16.7.1,false,affected, +rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8-head,openssl-3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3106-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.15.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8-head,openssl-3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, @@ -439,6 +437,7 @@ rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8-head,libgmodule-2_0- rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8-head,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8-head,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, +rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8-head,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8-head,glib2-tools,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, @@ -446,6 +445,7 @@ rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8-head,libgio-2_0-0,2. rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8-head,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,rancher/v2.8-head,glibc,2.31-150300.68.1,suse linux enterprise server,SUSE-SU-2024:1375-1,HIGH,,rancher/hardened-ib-sriov-cni:v1.0.3-build20240327 (suse linux enterprise server 15.5),2.31-150300.74.1,false,affected, rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,rancher/v2.8-head,glibc,2.31-150300.68.1,suse linux enterprise server,SUSE-SU-2024:1895-1,HIGH,,rancher/hardened-ib-sriov-cni:v1.0.3-build20240327 (suse linux enterprise server 15.5),2.31-150300.83.1,false,affected, @@ -729,7 +729,6 @@ rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8-head,perl-base,5.26.1-15030 rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8-head,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2019-12274,HIGH,https://avd.aquasec.com/nvd/cve-2019-12274,usr/bin/harvester-cloud-provider,"2.2.4, 1.6.27",false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8-head,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8-head,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8-head,golang.org/x/crypto,v0.1.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8-head,golang.org/x/net,v0.7.0,gobinary,CVE-2023-39325,HIGH,https://avd.aquasec.com/nvd/cve-2023-39325,usr/bin/harvester-cloud-provider,0.17.0,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8-head,kubevirt.io/kubevirt,v0.54.0,gobinary,CVE-2023-26484,HIGH,https://avd.aquasec.com/nvd/cve-2023-26484,usr/bin/harvester-cloud-provider,,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8-head,kubevirt.io/kubevirt,v0.54.0,gobinary,GHSA-qv98-3369-g364,HIGH,https://github.com/advisories/GHSA-qv98-3369-g364,usr/bin/harvester-cloud-provider,0.55.1,false,affected, @@ -747,7 +746,6 @@ rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8-head,github.com/rancher/ran rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8-head,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8-head,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/harvester-cloud-provider,0.46.0,false,affected, -rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8-head,golang.org/x/crypto,v0.16.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8-head,stdlib,v1.20.13,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/harvester-cloud-provider,"1.21.11, 1.22.4",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8-head,stdlib,v1.20.13,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/harvester-cloud-provider,"1.21.9, 1.22.2",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8-head,stdlib,v1.20.13,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-cloud-provider,"1.22.7, 1.23.1",false,affected, @@ -755,7 +753,6 @@ rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8-head,github.com/rancher/ran rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8-head,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8-head,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/harvester-cloud-provider,0.46.0,false,affected, -rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8-head,golang.org/x/crypto,v0.16.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-cloud-provider,"1.22.7, 1.23.1",false,affected, rancher/harvester-csi-driver:v0.1.5,rancher/v2.8-head,container-suseconnect,2.4.0-150000.4.22.1,suse linux enterprise server,SUSE-SU-2023:0871-1,HIGH,,rancher/harvester-csi-driver:v0.1.5 (suse linux enterprise server 15.4),2.4.0-150000.4.24.1,false,affected, rancher/harvester-csi-driver:v0.1.5,rancher/v2.8-head,curl,7.79.1-150400.5.15.1,suse linux enterprise server,SUSE-SU-2023:2224-1,HIGH,,rancher/harvester-csi-driver:v0.1.5 (suse linux enterprise server 15.4),8.0.1-150400.5.23.1,false,affected, @@ -1127,7 +1124,6 @@ rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.8-head,golang.org/x/crypto, rancher/kube-api-auth:v0.2.1,rancher/v2.8-head,glibc,2.31-150300.63.1,suse linux enterprise server,SUSE-SU-2024:1375-1,HIGH,,rancher/kube-api-auth:v0.2.1 (suse linux enterprise server 15.5),2.31-150300.74.1,false,affected, rancher/kube-api-auth:v0.2.1,rancher/v2.8-head,glibc,2.31-150300.63.1,suse linux enterprise server,SUSE-SU-2024:1895-1,HIGH,,rancher/kube-api-auth:v0.2.1 (suse linux enterprise server 15.5),2.31-150300.83.1,false,affected, rancher/kube-api-auth:v0.2.1,rancher/v2.8-head,github.com/rancher/steve,v0.0.0-20231016202603-993540401906,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/kube-api-auth,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/kube-api-auth:v0.2.1,rancher/v2.8-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-api-auth,0.31.0,false,affected, rancher/kube-api-auth:v0.2.1,rancher/v2.8-head,k8s.io/kubernetes,v1.27.10,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,usr/bin/kube-api-auth,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/kube-api-auth:v0.2.1,rancher/v2.8-head,k8s.io/kubernetes,v1.27.10,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,usr/bin/kube-api-auth,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/kube-api-auth:v0.2.1,rancher/v2.8-head,stdlib,v1.21.6,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/kube-api-auth,"1.21.11, 1.22.4",false,affected, @@ -1301,11 +1297,9 @@ rancher/kubectl:v1.23.3,rancher/v2.8-head,stdlib,v1.17.6,gobinary,CVE-2023-45287 rancher/kubectl:v1.23.3,rancher/v2.8-head,stdlib,v1.17.6,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,bin/kubectl,"1.21.9, 1.22.2",false,affected, rancher/kubectl:v1.23.3,rancher/v2.8-head,stdlib,v1.17.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/kubectl:v1.27.16,rancher/v2.8-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.28,rancher/v2.8-head,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.8-head,stdlib,v1.21.4,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/local-path-provisioner,"1.21.11, 1.22.4",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.8-head,stdlib,v1.21.4,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/local-path-provisioner,"1.21.9, 1.22.2",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.8-head,stdlib,v1.21.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/local-path-provisioner,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.30,rancher/v2.8-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.8-head,github.com/prometheus/client_golang,v1.9.0,gobinary,CVE-2022-21698,HIGH,https://avd.aquasec.com/nvd/cve-2022-21698,csi-attacher,1.11.1,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.8-head,golang.org/x/net,v0.0.0-20210410081132-afb366fc7cd1,gobinary,CVE-2021-33194,HIGH,https://avd.aquasec.com/nvd/cve-2021-33194,csi-attacher,0.0.0-20210520170846-37e1c6afe023,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.8-head,golang.org/x/net,v0.0.0-20210410081132-afb366fc7cd1,gobinary,CVE-2022-27664,HIGH,https://avd.aquasec.com/nvd/cve-2022-27664,csi-attacher,0.0.0-20220906165146-f3363e06e74c,false,affected, @@ -1537,7 +1531,6 @@ rancher/machine:v0.15.0-rancher118,rancher/v2.8-head,libglib-2_0-0,2.78.6-150600 rancher/machine:v0.15.0-rancher118,rancher/v2.8-head,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/machine:v0.15.0-rancher118 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/machine:v0.15.0-rancher118,rancher/v2.8-head,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/machine:v0.15.0-rancher118 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/machine:v0.15.0-rancher118,rancher/v2.8-head,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/machine:v0.15.0-rancher118 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, -rancher/machine:v0.15.0-rancher118,rancher/v2.8-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rancher-machine,0.31.0,false,affected, rancher/machine:v0.15.0-rancher118,rancher/v2.8-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/rancher-machine,"1.22.7, 1.23.1",false,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,ca-certificates,2021.2.50-72.amzn2.0.3,amazon,CVE-2022-23491,HIGH,https://avd.aquasec.com/nvd/cve-2022-23491,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2021.2.50-72.amzn2.0.5,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,ca-certificates,2021.2.50-72.amzn2.0.3,amazon,CVE-2023-32803,HIGH,https://avd.aquasec.com/nvd/cve-2023-32803,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2021.2.50-72.amzn2.0.7,true,affected, @@ -1593,20 +1586,19 @@ rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openldap,2.4.44-23.amzn rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2022-4304,HIGH,https://avd.aquasec.com/nvd/cve-2022-4304,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.6,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-0215,HIGH,https://avd.aquasec.com/nvd/cve-2023-0215,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.6,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-0286,HIGH,https://avd.aquasec.com/nvd/cve-2023-0286,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.6,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-0464,HIGH,https://avd.aquasec.com/nvd/cve-2023-0464,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.7,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-0465,HIGH,https://avd.aquasec.com/nvd/cve-2023-0465,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.7,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-0466,HIGH,https://avd.aquasec.com/nvd/cve-2023-0466,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.7,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-2650,HIGH,https://avd.aquasec.com/nvd/cve-2023-2650,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.7,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-3446,HIGH,https://avd.aquasec.com/nvd/cve-2023-3446,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.9,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-3817,HIGH,https://avd.aquasec.com/nvd/cve-2023-3817,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.9,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-5678,HIGH,https://avd.aquasec.com/nvd/cve-2023-5678,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.11,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2024-0727,HIGH,https://avd.aquasec.com/nvd/cve-2024-0727,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.12,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,python,2.7.18-1.amzn2.0.5,amazon,CVE-2022-45061,HIGH,https://avd.aquasec.com/nvd/cve-2022-45061,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2.7.18-1.amzn2.0.6,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,python,2.7.18-1.amzn2.0.5,amazon,CVE-2022-48565,HIGH,https://avd.aquasec.com/nvd/cve-2022-48565,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2.7.18-1.amzn2.0.7,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,python-libs,2.7.18-1.amzn2.0.5,amazon,CVE-2022-45061,HIGH,https://avd.aquasec.com/nvd/cve-2022-45061,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2.7.18-1.amzn2.0.6,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,python-libs,2.7.18-1.amzn2.0.5,amazon,CVE-2022-48565,HIGH,https://avd.aquasec.com/nvd/cve-2022-48565,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2.7.18-1.amzn2.0.7,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,sqlite,3.7.17-8.amzn2.1.1,amazon,CVE-2022-35737,HIGH,https://avd.aquasec.com/nvd/cve-2022-35737,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),3.7.17-8.amzn2.1.2,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2021-3236,HIGH,https://avd.aquasec.com/nvd/cve-2021-3236,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1882-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2522,HIGH,https://avd.aquasec.com/nvd/cve-2022-2522,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2571,HIGH,https://avd.aquasec.com/nvd/cve-2022-2571,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2580,HIGH,https://avd.aquasec.com/nvd/cve-2022-2580,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2581,HIGH,https://avd.aquasec.com/nvd/cve-2022-2581,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2874,HIGH,https://avd.aquasec.com/nvd/cve-2022-2874,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3134,HIGH,https://avd.aquasec.com/nvd/cve-2022-3134,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3153,HIGH,https://avd.aquasec.com/nvd/cve-2022-3153,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3234,HIGH,https://avd.aquasec.com/nvd/cve-2022-3234,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3235,HIGH,https://avd.aquasec.com/nvd/cve-2022-3235,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3256,HIGH,https://avd.aquasec.com/nvd/cve-2022-3256,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, @@ -1616,7 +1608,10 @@ rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.am rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3324,HIGH,https://avd.aquasec.com/nvd/cve-2022-3324,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3352,HIGH,https://avd.aquasec.com/nvd/cve-2022-3352,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3491,HIGH,https://avd.aquasec.com/nvd/cve-2022-3491,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-4141,HIGH,https://avd.aquasec.com/nvd/cve-2022-4141,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1006-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-4292,HIGH,https://avd.aquasec.com/nvd/cve-2022-4292,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1160-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-47024,HIGH,https://avd.aquasec.com/nvd/cve-2022-47024,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0049,HIGH,https://avd.aquasec.com/nvd/cve-2023-0049,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1160-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0051,HIGH,https://avd.aquasec.com/nvd/cve-2023-0051,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0054,HIGH,https://avd.aquasec.com/nvd/cve-2023-0054,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0288,HIGH,https://avd.aquasec.com/nvd/cve-2023-0288,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, @@ -1633,6 +1628,13 @@ rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.am rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-4752,HIGH,https://avd.aquasec.com/nvd/cve-2023-4752,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1882-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-4781,HIGH,https://avd.aquasec.com/nvd/cve-2023-4781,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1882-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2021-3236,HIGH,https://avd.aquasec.com/nvd/cve-2021-3236,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1882-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2522,HIGH,https://avd.aquasec.com/nvd/cve-2022-2522,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2571,HIGH,https://avd.aquasec.com/nvd/cve-2022-2571,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2580,HIGH,https://avd.aquasec.com/nvd/cve-2022-2580,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2581,HIGH,https://avd.aquasec.com/nvd/cve-2022-2581,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2874,HIGH,https://avd.aquasec.com/nvd/cve-2022-2874,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3134,HIGH,https://avd.aquasec.com/nvd/cve-2022-3134,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3153,HIGH,https://avd.aquasec.com/nvd/cve-2022-3153,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3234,HIGH,https://avd.aquasec.com/nvd/cve-2022-3234,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3235,HIGH,https://avd.aquasec.com/nvd/cve-2022-3235,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3256,HIGH,https://avd.aquasec.com/nvd/cve-2022-3256,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, @@ -1642,7 +1644,10 @@ rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1 rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3324,HIGH,https://avd.aquasec.com/nvd/cve-2022-3324,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3352,HIGH,https://avd.aquasec.com/nvd/cve-2022-3352,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3491,HIGH,https://avd.aquasec.com/nvd/cve-2022-3491,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-4141,HIGH,https://avd.aquasec.com/nvd/cve-2022-4141,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1006-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-4292,HIGH,https://avd.aquasec.com/nvd/cve-2022-4292,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1160-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-47024,HIGH,https://avd.aquasec.com/nvd/cve-2022-47024,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0049,HIGH,https://avd.aquasec.com/nvd/cve-2023-0049,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1160-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0051,HIGH,https://avd.aquasec.com/nvd/cve-2023-0051,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0054,HIGH,https://avd.aquasec.com/nvd/cve-2023-0054,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8-head,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0288,HIGH,https://avd.aquasec.com/nvd/cve-2023-0288,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, @@ -2276,6 +2281,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8-h rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8-head,glib,2.68.4-2.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8-head,krb5,1.17-10.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8-head,krb5,1.17-10.ph4,photon,CVE-2024-37370,HIGH,https://avd.aquasec.com/nvd/cve-2024-37370,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8-head,nss-libs,3.72-4.ph4,photon,CVE-2024-0743,HIGH,https://avd.aquasec.com/nvd/cve-2024-0743,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),3.72-6.ph4,true,affected, @@ -4148,6 +4154,9 @@ rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.8-head,libglib-2_0-0,2.78.6 rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.8-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.8-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.8-head,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/consul,0.31.0,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.8-head,libpython3_12-1_0,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.8-head,python312,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.8-head,python312-base,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.8-head,libexpat,2.6.2-r0,alpine,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.8-head,libexpat,2.6.2-r0,alpine,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.8-head,libexpat,2.6.2-r0,alpine,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, @@ -6092,13 +6101,11 @@ rancher/rke2-cloud-provider:v1.28.15-0.20241016053552-63bfb1936862-build20241016 rancher/rke2-cloud-provider:v1.29.3-build20240515,rancher/v2.8-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.29.3-build20240515,rancher/v2.8-head,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/local/bin/rke2-cloud-provider,"1.21.11, 1.22.4",false,affected, rancher/rke2-cloud-provider:v1.29.3-build20240515,rancher/v2.8-head,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/rke2-cloud-provider,"1.22.7, 1.23.1",false,affected, -rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.8-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.8-head,k8s.io/kubernetes,v1.28.0-rc.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.8-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.8-head,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.8-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,opt/rke2,"1.22.7, 1.23.1",false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.8-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubectl,"1.22.7, 1.23.1",false,affected, -rancher/rke2-upgrade:v1.28.15-rke2r1,rancher/v2.8-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, rancher/security-scan:v0.3.1,rancher/v2.8-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-bench,0.31.0,false,affected, rancher/shell:v0.1.19,rancher/v2.8-head,container-suseconnect,2.4.0-150000.4.22.1,suse linux enterprise server,SUSE-SU-2023:0871-1,HIGH,,rancher/shell:v0.1.19 (suse linux enterprise server 15.4),2.4.0-150000.4.24.1,false,affected, rancher/shell:v0.1.19,rancher/v2.8-head,curl,7.79.1-150400.5.15.1,suse linux enterprise server,SUSE-SU-2023:2224-1,HIGH,,rancher/shell:v0.1.19 (suse linux enterprise server 15.4),8.0.1-150400.5.23.1,false,affected, diff --git a/docs/csv/report-rancher-v2.8-head-stats.csv b/docs/csv/report-rancher-v2.8-head-stats.csv index c321a69..790e8a1 100644 --- a/docs/csv/report-rancher-v2.8-head-stats.csv +++ b/docs/csv/report-rancher-v2.8-head-stats.csv @@ -6,8 +6,8 @@ rancher/calico-cni:v3.27.4-rancher1,3,43,46 rancher/cis-operator:v1.1.2,0,0,0 rancher/eks-operator:v1.3.6-rc.1,0,0,0 rancher/flannel-cni:v0.3.0-rancher9,11,54,65 -rancher/fleet-agent:v0.9.12,0,2,2 -rancher/fleet:v0.9.12,0,1,1 +rancher/fleet-agent:v0.9.12,0,0,0 +rancher/fleet:v0.9.12,0,0,0 rancher/gitjob:v0.9.18,0,2,2 rancher/gke-operator:v1.2.6-rc.1,0,1,1 rancher/hardened-addon-resizer:1.8.20-build20240410,1,2,3 @@ -30,9 +30,9 @@ rancher/hardened-dns-node-cache:1.23.1-build20240910,0,5,5 rancher/hardened-dns-node-cache:1.23.1-build20241008,0,5,5 rancher/hardened-etcd:v3.5.13-k3s1-build20240531,2,10,12 rancher/hardened-etcd:v3.5.13-k3s1-build20240910,0,2,2 -rancher/hardened-flannel:v0.25.5-build20240801,0,16,16 -rancher/hardened-flannel:v0.25.6-build20240910,0,9,9 -rancher/hardened-flannel:v0.25.7-build20241008,0,6,6 +rancher/hardened-flannel:v0.25.5-build20240801,0,17,17 +rancher/hardened-flannel:v0.25.6-build20240910,0,10,10 +rancher/hardened-flannel:v0.25.7-build20241008,0,7,7 rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,1,17,18 rancher/hardened-k8s-metrics-server:v0.7.1-build20240401,1,3,4 rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,0,1,1 @@ -53,9 +53,9 @@ rancher/hardened-sriov-network-webhook:v1.2.0-build20240327,1,19,20 rancher/hardened-whereabouts:v0.7.0-build20240429,2,3,5 rancher/hardened-whereabouts:v0.8.0-build20240910,0,0,0 rancher/hardened-whereabouts:v0.8.0-build20241011,0,0,0 -rancher/harvester-cloud-provider:v0.2.0,1,23,24 -rancher/harvester-cloud-provider:v0.2.1,1,10,11 -rancher/harvester-cloud-provider:v0.2.2,0,6,6 +rancher/harvester-cloud-provider:v0.2.0,1,22,23 +rancher/harvester-cloud-provider:v0.2.1,1,9,10 +rancher/harvester-cloud-provider:v0.2.2,0,5,5 rancher/harvester-csi-driver:v0.1.5,3,75,78 rancher/harvester-csi-driver:v0.1.6,3,55,58 rancher/harvester-csi-driver:v0.1.7,0,9,9 @@ -72,21 +72,21 @@ rancher/klipper-helm:v0.8.4-build20240523,14,102,116 rancher/klipper-helm:v0.9.2-build20240828,0,6,6 rancher/klipper-helm:v0.9.3-build20241008,0,3,3 rancher/klipper-lb:v0.4.9,0,0,0 -rancher/kube-api-auth:v0.2.1,1,8,9 +rancher/kube-api-auth:v0.2.1,1,7,8 rancher/kubectl:v1.20.2,4,43,47 rancher/kubectl:v1.21.5,4,38,42 rancher/kubectl:v1.22.6,4,35,39 rancher/kubectl:v1.23.3,4,35,39 rancher/kubectl:v1.27.16,0,1,1 rancher/kubectl:v1.28.15,0,0,0 -rancher/local-path-provisioner:v0.0.28,1,3,4 -rancher/local-path-provisioner:v0.0.30,0,1,1 +rancher/local-path-provisioner:v0.0.28,1,2,3 +rancher/local-path-provisioner:v0.0.30,0,0,0 rancher/longhornio-csi-attacher:v3.2.1,4,52,56 rancher/longhornio-csi-node-driver-registrar:v2.3.0,4,49,53 rancher/longhornio-csi-provisioner:v2.1.2,4,58,62 rancher/longhornio-csi-resizer:v1.2.0,4,52,56 -rancher/machine:v0.15.0-rancher118,0,6,6 -rancher/mirrored-amazon-aws-cli:2.9.14,2,119,121 +rancher/machine:v0.15.0-rancher118,0,5,5 +rancher/mirrored-amazon-aws-cli:2.9.14,2,131,133 rancher/mirrored-appscode-kubed:v0.13.2,4,34,38 rancher/mirrored-bci-busybox:15.6.24.2,0,0,0 rancher/mirrored-bci-micro:15.6.24.2,0,0,0 @@ -183,7 +183,7 @@ rancher/mirrored-cilium-operator-generic:v1.16.1,0,3,3 rancher/mirrored-cilium-operator-generic:v1.16.2,0,1,1 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.27.0,3,15,18 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.28.0,1,9,10 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,6,15,21 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,7,15,22 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.3.0,4,15,19 rancher/mirrored-cluster-api-controller:v1.4.4,3,13,16 rancher/mirrored-cluster-proportional-autoscaler:v1.8.9,1,5,6 @@ -277,7 +277,7 @@ rancher/mirrored-minio-minio:RELEASE.2023-07-07T07-13-57Z,1,22,23 rancher/mirrored-neuvector-compliance-config:latest,0,0,0 rancher/mirrored-neuvector-controller:5.4.1,0,8,8 rancher/mirrored-neuvector-enforcer:5.4.1,0,6,6 -rancher/mirrored-neuvector-manager:5.4.1,0,0,0 +rancher/mirrored-neuvector-manager:5.4.1,0,3,3 rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,2,13,15 rancher/mirrored-neuvector-registry-adapter:0.1.3,0,2,2 rancher/mirrored-neuvector-scanner:latest,0,1,1 @@ -333,9 +333,9 @@ rancher/rke-tools:v0.1.96,65,346,411 rancher/rke2-cloud-provider:v1.28.13-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.28.15-0.20241016053552-63bfb1936862-build20241016,0,1,1 rancher/rke2-cloud-provider:v1.29.3-build20240515,1,2,3 -rancher/rke2-runtime:v1.28.15-rke2r1,0,3,3 +rancher/rke2-runtime:v1.28.15-rke2r1,0,2,2 rancher/rke2-upgrade:v1.27.16-rke2r2,0,3,3 -rancher/rke2-upgrade:v1.28.15-rke2r1,0,1,1 +rancher/rke2-upgrade:v1.28.15-rke2r1,0,0,0 rancher/security-scan:v0.3.1,0,1,1 rancher/shell:v0.1.19,15,146,161 rancher/shell:v0.1.26,4,15,19 diff --git a/docs/csv/report-rancher-v2.8.10-cves.csv b/docs/csv/report-rancher-v2.8.10-cves.csv index aa0f972..2ab8bbe 100644 --- a/docs/csv/report-rancher-v2.8.10-cves.csv +++ b/docs/csv/report-rancher-v2.8.10-cves.csv @@ -201,12 +201,9 @@ rancher/flannel-cni:v0.3.0-rancher9,rancher/v2.8.10,stdlib,v1.20.4,gobinary,CVE- rancher/flannel-cni:v0.3.0-rancher9,rancher/v2.8.10,stdlib,v1.20.4,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,opt/cni/bin/vlan,"1.21.9, 1.22.2",false,affected, rancher/flannel-cni:v0.3.0-rancher9,rancher/v2.8.10,stdlib,v1.20.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,opt/cni/bin/vlan,"1.22.7, 1.23.1",false,affected, rancher/fleet-agent:v0.9.11,rancher/v2.8.10,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/fleet-agent:v0.9.11 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, -rancher/fleet-agent:v0.9.11,rancher/v2.8.10,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleet,0.31.0,false,affected, -rancher/fleet-agent:v0.9.11,rancher/v2.8.10,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetagent,0.31.0,false,affected, rancher/fleet-agent:v0.9.11,rancher/v2.8.10,k8s.io/kubernetes,v1.28.8,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,usr/bin/fleetagent,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/fleet-agent:v0.9.11,rancher/v2.8.10,k8s.io/kubernetes,v1.28.8,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,usr/bin/fleetagent,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/fleet:v0.9.11,rancher/v2.8.10,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/fleet:v0.9.11 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, -rancher/fleet:v0.9.11,rancher/v2.8.10,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetcontroller,0.31.0,false,affected, rancher/gitjob:v0.9.17,rancher/v2.8.10,libglib-2_0-0,2.70.5-150400.3.14.1,suse linux enterprise server,SUSE-SU-2024:4078-1,HIGH,,rancher/gitjob:v0.9.17 (suse linux enterprise server 15.5),2.70.5-150400.3.17.1,false,affected, rancher/gitjob:v0.9.17,rancher/v2.8.10,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/gitcloner,0.31.0,false,affected, rancher/gitjob:v0.9.17,rancher/v2.8.10,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/gitjob,0.31.0,false,affected, @@ -433,6 +430,7 @@ rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8.10,libopenssl-3-fips rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8.10,libopenssl3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3106-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.15.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8.10,libopenssl3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8.10,libprotobuf-lite25_1_0,25.1-150600.16.4.2,suse linux enterprise server,SUSE-SU-2024:3745-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),25.1-150600.16.7.1,false,affected, +rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8.10,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8.10,openssl-3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3106-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.15.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8.10,openssl-3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.8.10,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, @@ -444,6 +442,7 @@ rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8.10,libgmodule-2_0-0, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8.10,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8.10,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8.10,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, +rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8.10,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8.10,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.8.10,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8.10,glib2-tools,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, @@ -451,6 +450,7 @@ rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8.10,libgio-2_0-0,2.78 rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8.10,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8.10,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8.10,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8.10,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.8.10,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,rancher/v2.8.10,glibc,2.31-150300.68.1,suse linux enterprise server,SUSE-SU-2024:1375-1,HIGH,,rancher/hardened-ib-sriov-cni:v1.0.3-build20240327 (suse linux enterprise server 15.5),2.31-150300.74.1,false,affected, rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,rancher/v2.8.10,glibc,2.31-150300.68.1,suse linux enterprise server,SUSE-SU-2024:1895-1,HIGH,,rancher/hardened-ib-sriov-cni:v1.0.3-build20240327 (suse linux enterprise server 15.5),2.31-150300.83.1,false,affected, @@ -734,7 +734,6 @@ rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8.10,perl-base,5.26.1-150300. rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8.10,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2019-12274,HIGH,https://avd.aquasec.com/nvd/cve-2019-12274,usr/bin/harvester-cloud-provider,"2.2.4, 1.6.27",false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8.10,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8.10,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8.10,golang.org/x/crypto,v0.1.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8.10,golang.org/x/net,v0.7.0,gobinary,CVE-2023-39325,HIGH,https://avd.aquasec.com/nvd/cve-2023-39325,usr/bin/harvester-cloud-provider,0.17.0,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8.10,kubevirt.io/kubevirt,v0.54.0,gobinary,CVE-2023-26484,HIGH,https://avd.aquasec.com/nvd/cve-2023-26484,usr/bin/harvester-cloud-provider,,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.8.10,kubevirt.io/kubevirt,v0.54.0,gobinary,GHSA-qv98-3369-g364,HIGH,https://github.com/advisories/GHSA-qv98-3369-g364,usr/bin/harvester-cloud-provider,0.55.1,false,affected, @@ -752,7 +751,6 @@ rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8.10,github.com/rancher/ranch rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8.10,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8.10,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8.10,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/harvester-cloud-provider,0.46.0,false,affected, -rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8.10,golang.org/x/crypto,v0.16.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8.10,stdlib,v1.20.13,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/harvester-cloud-provider,"1.21.11, 1.22.4",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8.10,stdlib,v1.20.13,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/harvester-cloud-provider,"1.21.9, 1.22.2",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.8.10,stdlib,v1.20.13,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-cloud-provider,"1.22.7, 1.23.1",false,affected, @@ -760,7 +758,6 @@ rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8.10,github.com/rancher/ranch rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8.10,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8.10,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8.10,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/harvester-cloud-provider,0.46.0,false,affected, -rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8.10,golang.org/x/crypto,v0.16.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.8.10,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-cloud-provider,"1.22.7, 1.23.1",false,affected, rancher/harvester-csi-driver:v0.1.5,rancher/v2.8.10,container-suseconnect,2.4.0-150000.4.22.1,suse linux enterprise server,SUSE-SU-2023:0871-1,HIGH,,rancher/harvester-csi-driver:v0.1.5 (suse linux enterprise server 15.4),2.4.0-150000.4.24.1,false,affected, rancher/harvester-csi-driver:v0.1.5,rancher/v2.8.10,curl,7.79.1-150400.5.15.1,suse linux enterprise server,SUSE-SU-2023:2224-1,HIGH,,rancher/harvester-csi-driver:v0.1.5 (suse linux enterprise server 15.4),8.0.1-150400.5.23.1,false,affected, @@ -1131,7 +1128,6 @@ rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.8.10,golang.org/x/crypto,v0 rancher/kube-api-auth:v0.2.1,rancher/v2.8.10,glibc,2.31-150300.63.1,suse linux enterprise server,SUSE-SU-2024:1375-1,HIGH,,rancher/kube-api-auth:v0.2.1 (suse linux enterprise server 15.5),2.31-150300.74.1,false,affected, rancher/kube-api-auth:v0.2.1,rancher/v2.8.10,glibc,2.31-150300.63.1,suse linux enterprise server,SUSE-SU-2024:1895-1,HIGH,,rancher/kube-api-auth:v0.2.1 (suse linux enterprise server 15.5),2.31-150300.83.1,false,affected, rancher/kube-api-auth:v0.2.1,rancher/v2.8.10,github.com/rancher/steve,v0.0.0-20231016202603-993540401906,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/kube-api-auth,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/kube-api-auth:v0.2.1,rancher/v2.8.10,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-api-auth,0.31.0,false,affected, rancher/kube-api-auth:v0.2.1,rancher/v2.8.10,k8s.io/kubernetes,v1.27.10,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,usr/bin/kube-api-auth,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/kube-api-auth:v0.2.1,rancher/v2.8.10,k8s.io/kubernetes,v1.27.10,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,usr/bin/kube-api-auth,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/kube-api-auth:v0.2.1,rancher/v2.8.10,stdlib,v1.21.6,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/kube-api-auth,"1.21.11, 1.22.4",false,affected, @@ -1306,11 +1302,9 @@ rancher/kubectl:v1.23.3,rancher/v2.8.10,stdlib,v1.17.6,gobinary,CVE-2023-45288,H rancher/kubectl:v1.23.3,rancher/v2.8.10,stdlib,v1.17.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/kubectl:v1.27.16,rancher/v2.8.10,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/kubectl:v1.28.12,rancher/v2.8.10,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.28,rancher/v2.8.10,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.8.10,stdlib,v1.21.4,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/local-path-provisioner,"1.21.11, 1.22.4",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.8.10,stdlib,v1.21.4,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/local-path-provisioner,"1.21.9, 1.22.2",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.8.10,stdlib,v1.21.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/local-path-provisioner,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.30,rancher/v2.8.10,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.8.10,github.com/prometheus/client_golang,v1.9.0,gobinary,CVE-2022-21698,HIGH,https://avd.aquasec.com/nvd/cve-2022-21698,csi-attacher,1.11.1,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.8.10,golang.org/x/net,v0.0.0-20210410081132-afb366fc7cd1,gobinary,CVE-2021-33194,HIGH,https://avd.aquasec.com/nvd/cve-2021-33194,csi-attacher,0.0.0-20210520170846-37e1c6afe023,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.8.10,golang.org/x/net,v0.0.0-20210410081132-afb366fc7cd1,gobinary,CVE-2022-27664,HIGH,https://avd.aquasec.com/nvd/cve-2022-27664,csi-attacher,0.0.0-20220906165146-f3363e06e74c,false,affected, @@ -1542,7 +1536,6 @@ rancher/machine:v0.15.0-rancher118,rancher/v2.8.10,libglib-2_0-0,2.78.6-150600.4 rancher/machine:v0.15.0-rancher118,rancher/v2.8.10,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/machine:v0.15.0-rancher118 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/machine:v0.15.0-rancher118,rancher/v2.8.10,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/machine:v0.15.0-rancher118 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/machine:v0.15.0-rancher118,rancher/v2.8.10,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/machine:v0.15.0-rancher118 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, -rancher/machine:v0.15.0-rancher118,rancher/v2.8.10,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rancher-machine,0.31.0,false,affected, rancher/machine:v0.15.0-rancher118,rancher/v2.8.10,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/rancher-machine,"1.22.7, 1.23.1",false,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,ca-certificates,2021.2.50-72.amzn2.0.3,amazon,CVE-2022-23491,HIGH,https://avd.aquasec.com/nvd/cve-2022-23491,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2021.2.50-72.amzn2.0.5,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,ca-certificates,2021.2.50-72.amzn2.0.3,amazon,CVE-2023-32803,HIGH,https://avd.aquasec.com/nvd/cve-2023-32803,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2021.2.50-72.amzn2.0.7,true,affected, @@ -1598,20 +1591,19 @@ rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openldap,2.4.44-23.amzn2. rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2022-4304,HIGH,https://avd.aquasec.com/nvd/cve-2022-4304,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.6,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-0215,HIGH,https://avd.aquasec.com/nvd/cve-2023-0215,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.6,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-0286,HIGH,https://avd.aquasec.com/nvd/cve-2023-0286,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.6,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-0464,HIGH,https://avd.aquasec.com/nvd/cve-2023-0464,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.7,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-0465,HIGH,https://avd.aquasec.com/nvd/cve-2023-0465,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.7,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-0466,HIGH,https://avd.aquasec.com/nvd/cve-2023-0466,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.7,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-2650,HIGH,https://avd.aquasec.com/nvd/cve-2023-2650,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.7,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-3446,HIGH,https://avd.aquasec.com/nvd/cve-2023-3446,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.9,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-3817,HIGH,https://avd.aquasec.com/nvd/cve-2023-3817,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.9,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2023-5678,HIGH,https://avd.aquasec.com/nvd/cve-2023-5678,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.11,true,affected, -rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,openssl-libs,1:1.0.2k-24.amzn2.0.4,amazon,CVE-2024-0727,HIGH,https://avd.aquasec.com/nvd/cve-2024-0727,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),1:1.0.2k-24.amzn2.0.12,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,python,2.7.18-1.amzn2.0.5,amazon,CVE-2022-45061,HIGH,https://avd.aquasec.com/nvd/cve-2022-45061,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2.7.18-1.amzn2.0.6,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,python,2.7.18-1.amzn2.0.5,amazon,CVE-2022-48565,HIGH,https://avd.aquasec.com/nvd/cve-2022-48565,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2.7.18-1.amzn2.0.7,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,python-libs,2.7.18-1.amzn2.0.5,amazon,CVE-2022-45061,HIGH,https://avd.aquasec.com/nvd/cve-2022-45061,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2.7.18-1.amzn2.0.6,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,python-libs,2.7.18-1.amzn2.0.5,amazon,CVE-2022-48565,HIGH,https://avd.aquasec.com/nvd/cve-2022-48565,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2.7.18-1.amzn2.0.7,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,sqlite,3.7.17-8.amzn2.1.1,amazon,CVE-2022-35737,HIGH,https://avd.aquasec.com/nvd/cve-2022-35737,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),3.7.17-8.amzn2.1.2,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2021-3236,HIGH,https://avd.aquasec.com/nvd/cve-2021-3236,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1882-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2522,HIGH,https://avd.aquasec.com/nvd/cve-2022-2522,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2571,HIGH,https://avd.aquasec.com/nvd/cve-2022-2571,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2580,HIGH,https://avd.aquasec.com/nvd/cve-2022-2580,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2581,HIGH,https://avd.aquasec.com/nvd/cve-2022-2581,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2874,HIGH,https://avd.aquasec.com/nvd/cve-2022-2874,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3134,HIGH,https://avd.aquasec.com/nvd/cve-2022-3134,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3153,HIGH,https://avd.aquasec.com/nvd/cve-2022-3153,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3234,HIGH,https://avd.aquasec.com/nvd/cve-2022-3234,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3235,HIGH,https://avd.aquasec.com/nvd/cve-2022-3235,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3256,HIGH,https://avd.aquasec.com/nvd/cve-2022-3256,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, @@ -1621,7 +1613,10 @@ rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3324,HIGH,https://avd.aquasec.com/nvd/cve-2022-3324,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3352,HIGH,https://avd.aquasec.com/nvd/cve-2022-3352,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3491,HIGH,https://avd.aquasec.com/nvd/cve-2022-3491,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-4141,HIGH,https://avd.aquasec.com/nvd/cve-2022-4141,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1006-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-4292,HIGH,https://avd.aquasec.com/nvd/cve-2022-4292,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1160-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-47024,HIGH,https://avd.aquasec.com/nvd/cve-2022-47024,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0049,HIGH,https://avd.aquasec.com/nvd/cve-2023-0049,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1160-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0051,HIGH,https://avd.aquasec.com/nvd/cve-2023-0051,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0054,HIGH,https://avd.aquasec.com/nvd/cve-2023-0054,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0288,HIGH,https://avd.aquasec.com/nvd/cve-2023-0288,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, @@ -1638,6 +1633,13 @@ rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-4752,HIGH,https://avd.aquasec.com/nvd/cve-2023-4752,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1882-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-data,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-4781,HIGH,https://avd.aquasec.com/nvd/cve-2023-4781,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1882-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2021-3236,HIGH,https://avd.aquasec.com/nvd/cve-2021-3236,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1882-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2522,HIGH,https://avd.aquasec.com/nvd/cve-2022-2522,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2571,HIGH,https://avd.aquasec.com/nvd/cve-2022-2571,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2580,HIGH,https://avd.aquasec.com/nvd/cve-2022-2580,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2581,HIGH,https://avd.aquasec.com/nvd/cve-2022-2581,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-2874,HIGH,https://avd.aquasec.com/nvd/cve-2022-2874,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3134,HIGH,https://avd.aquasec.com/nvd/cve-2022-3134,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3153,HIGH,https://avd.aquasec.com/nvd/cve-2022-3153,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3234,HIGH,https://avd.aquasec.com/nvd/cve-2022-3234,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3235,HIGH,https://avd.aquasec.com/nvd/cve-2022-3235,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3256,HIGH,https://avd.aquasec.com/nvd/cve-2022-3256,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, @@ -1647,7 +1649,10 @@ rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.a rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3324,HIGH,https://avd.aquasec.com/nvd/cve-2022-3324,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3352,HIGH,https://avd.aquasec.com/nvd/cve-2022-3352,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-3491,HIGH,https://avd.aquasec.com/nvd/cve-2022-3491,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-4141,HIGH,https://avd.aquasec.com/nvd/cve-2022-4141,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1006-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-4292,HIGH,https://avd.aquasec.com/nvd/cve-2022-4292,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1160-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2022-47024,HIGH,https://avd.aquasec.com/nvd/cve-2022-47024,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, +rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0049,HIGH,https://avd.aquasec.com/nvd/cve-2023-0049,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1160-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0051,HIGH,https://avd.aquasec.com/nvd/cve-2023-0051,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0054,HIGH,https://avd.aquasec.com/nvd/cve-2023-0054,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, rancher/mirrored-amazon-aws-cli:2.9.14,rancher/v2.8.10,vim-minimal,2:9.0.828-1.amzn2.0.1,amazon,CVE-2023-0288,HIGH,https://avd.aquasec.com/nvd/cve-2023-0288,rancher/mirrored-amazon-aws-cli:2.9.14 (amazon 2 (Karoo)),2:9.0.1314-1.amzn2.0.1,true,affected, @@ -2281,6 +2286,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8.1 rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8.10,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8.10,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8.10,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8.10,glib,2.68.4-2.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8.10,krb5,1.17-10.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8.10,krb5,1.17-10.ph4,photon,CVE-2024-37370,HIGH,https://avd.aquasec.com/nvd/cve-2024-37370,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.8.10,nss-libs,3.72-4.ph4,photon,CVE-2024-0743,HIGH,https://avd.aquasec.com/nvd/cve-2024-0743,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),3.72-6.ph4,true,affected, @@ -4153,6 +4159,9 @@ rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.8.10,libglib-2_0-0,2.78.6-1 rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.8.10,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.8.10,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.8.10,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/consul,0.31.0,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.8.10,libpython3_12-1_0,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.8.10,python312,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.8.10,python312-base,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.8.10,libexpat,2.6.2-r0,alpine,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.8.10,libexpat,2.6.2-r0,alpine,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.8.10,libexpat,2.6.2-r0,alpine,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, @@ -5938,13 +5947,11 @@ rancher/rke2-cloud-provider:v1.28.15-0.20241016053552-63bfb1936862-build20241016 rancher/rke2-cloud-provider:v1.29.3-build20240515,rancher/v2.8.10,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.29.3-build20240515,rancher/v2.8.10,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/local/bin/rke2-cloud-provider,"1.21.11, 1.22.4",false,affected, rancher/rke2-cloud-provider:v1.29.3-build20240515,rancher/v2.8.10,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/rke2-cloud-provider,"1.22.7, 1.23.1",false,affected, -rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.8.10,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.8.10,k8s.io/kubernetes,v1.28.0-rc.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.8.10,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.8.10,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.8.10,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,opt/rke2,"1.22.7, 1.23.1",false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.8.10,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubectl,"1.22.7, 1.23.1",false,affected, -rancher/rke2-upgrade:v1.28.15-rke2r1,rancher/v2.8.10,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, rancher/security-scan:v0.3.0,rancher/v2.8.10,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-bench,0.31.0,false,affected, rancher/security-scan:v0.3.0,rancher/v2.8.10,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/shell:v0.1.19,rancher/v2.8.10,container-suseconnect,2.4.0-150000.4.22.1,suse linux enterprise server,SUSE-SU-2023:0871-1,HIGH,,rancher/shell:v0.1.19 (suse linux enterprise server 15.4),2.4.0-150000.4.24.1,false,affected, diff --git a/docs/csv/report-rancher-v2.8.10-stats.csv b/docs/csv/report-rancher-v2.8.10-stats.csv index 0dd9ef8..628416d 100644 --- a/docs/csv/report-rancher-v2.8.10-stats.csv +++ b/docs/csv/report-rancher-v2.8.10-stats.csv @@ -6,8 +6,8 @@ rancher/calico-cni:v3.27.4-rancher1,3,43,46 rancher/cis-operator:v1.1.0,0,0,0 rancher/eks-operator:v1.3.5,0,0,0 rancher/flannel-cni:v0.3.0-rancher9,11,54,65 -rancher/fleet-agent:v0.9.11,0,5,5 -rancher/fleet:v0.9.11,0,2,2 +rancher/fleet-agent:v0.9.11,0,3,3 +rancher/fleet:v0.9.11,0,1,1 rancher/gitjob:v0.9.17,0,3,3 rancher/gke-operator:v1.2.5,0,1,1 rancher/hardened-addon-resizer:1.8.20-build20240410,1,2,3 @@ -30,9 +30,9 @@ rancher/hardened-dns-node-cache:1.23.1-build20240910,0,5,5 rancher/hardened-dns-node-cache:1.23.1-build20241008,0,5,5 rancher/hardened-etcd:v3.5.13-k3s1-build20240531,2,10,12 rancher/hardened-etcd:v3.5.13-k3s1-build20240910,0,2,2 -rancher/hardened-flannel:v0.25.5-build20240801,0,16,16 -rancher/hardened-flannel:v0.25.6-build20240910,0,9,9 -rancher/hardened-flannel:v0.25.7-build20241008,0,6,6 +rancher/hardened-flannel:v0.25.5-build20240801,0,17,17 +rancher/hardened-flannel:v0.25.6-build20240910,0,10,10 +rancher/hardened-flannel:v0.25.7-build20241008,0,7,7 rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,1,17,18 rancher/hardened-k8s-metrics-server:v0.7.1-build20240401,1,3,4 rancher/hardened-k8s-metrics-server:v0.7.1-build20240910,0,1,1 @@ -53,9 +53,9 @@ rancher/hardened-sriov-network-webhook:v1.2.0-build20240327,1,19,20 rancher/hardened-whereabouts:v0.7.0-build20240429,2,3,5 rancher/hardened-whereabouts:v0.8.0-build20240910,0,0,0 rancher/hardened-whereabouts:v0.8.0-build20241011,0,0,0 -rancher/harvester-cloud-provider:v0.2.0,1,23,24 -rancher/harvester-cloud-provider:v0.2.1,1,10,11 -rancher/harvester-cloud-provider:v0.2.2,0,6,6 +rancher/harvester-cloud-provider:v0.2.0,1,22,23 +rancher/harvester-cloud-provider:v0.2.1,1,9,10 +rancher/harvester-cloud-provider:v0.2.2,0,5,5 rancher/harvester-csi-driver:v0.1.5,3,75,78 rancher/harvester-csi-driver:v0.1.6,3,55,58 rancher/harvester-csi-driver:v0.1.7,0,9,9 @@ -71,21 +71,21 @@ rancher/klipper-helm:v0.8.4-build20240523,14,102,116 rancher/klipper-helm:v0.9.2-build20240828,0,6,6 rancher/klipper-helm:v0.9.3-build20241008,0,3,3 rancher/klipper-lb:v0.4.9,0,0,0 -rancher/kube-api-auth:v0.2.1,1,8,9 +rancher/kube-api-auth:v0.2.1,1,7,8 rancher/kubectl:v1.20.2,4,43,47 rancher/kubectl:v1.21.5,4,38,42 rancher/kubectl:v1.22.6,4,35,39 rancher/kubectl:v1.23.3,4,35,39 rancher/kubectl:v1.27.16,0,1,1 rancher/kubectl:v1.28.12,0,1,1 -rancher/local-path-provisioner:v0.0.28,1,3,4 -rancher/local-path-provisioner:v0.0.30,0,1,1 +rancher/local-path-provisioner:v0.0.28,1,2,3 +rancher/local-path-provisioner:v0.0.30,0,0,0 rancher/longhornio-csi-attacher:v3.2.1,4,52,56 rancher/longhornio-csi-node-driver-registrar:v2.3.0,4,49,53 rancher/longhornio-csi-provisioner:v2.1.2,4,58,62 rancher/longhornio-csi-resizer:v1.2.0,4,52,56 -rancher/machine:v0.15.0-rancher118,0,6,6 -rancher/mirrored-amazon-aws-cli:2.9.14,2,119,121 +rancher/machine:v0.15.0-rancher118,0,5,5 +rancher/mirrored-amazon-aws-cli:2.9.14,2,131,133 rancher/mirrored-appscode-kubed:v0.13.2,4,34,38 rancher/mirrored-bci-busybox:15.6.24.2,0,0,0 rancher/mirrored-bci-micro:15.6.24.2,0,0,0 @@ -182,7 +182,7 @@ rancher/mirrored-cilium-operator-generic:v1.16.1,0,3,3 rancher/mirrored-cilium-operator-generic:v1.16.2,0,1,1 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.27.0,3,15,18 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.28.0,1,9,10 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,6,15,21 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,7,15,22 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.3.0,4,15,19 rancher/mirrored-cluster-api-controller:v1.4.4,3,13,16 rancher/mirrored-cluster-proportional-autoscaler:v1.8.9,1,5,6 @@ -276,7 +276,7 @@ rancher/mirrored-minio-minio:RELEASE.2023-07-07T07-13-57Z,1,22,23 rancher/mirrored-neuvector-compliance-config:latest,0,0,0 rancher/mirrored-neuvector-controller:5.4.1,0,8,8 rancher/mirrored-neuvector-enforcer:5.4.1,0,6,6 -rancher/mirrored-neuvector-manager:5.4.1,0,0,0 +rancher/mirrored-neuvector-manager:5.4.1,0,3,3 rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,2,13,15 rancher/mirrored-neuvector-registry-adapter:0.1.3,0,2,2 rancher/mirrored-neuvector-scanner:latest,0,1,1 @@ -332,9 +332,9 @@ rancher/rke-tools:v0.1.96,65,346,411 rancher/rke2-cloud-provider:v1.28.13-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.28.15-0.20241016053552-63bfb1936862-build20241016,0,1,1 rancher/rke2-cloud-provider:v1.29.3-build20240515,1,2,3 -rancher/rke2-runtime:v1.28.15-rke2r1,0,3,3 +rancher/rke2-runtime:v1.28.15-rke2r1,0,2,2 rancher/rke2-upgrade:v1.27.16-rke2r2,0,3,3 -rancher/rke2-upgrade:v1.28.15-rke2r1,0,1,1 +rancher/rke2-upgrade:v1.28.15-rke2r1,0,0,0 rancher/security-scan:v0.3.0,0,2,2 rancher/shell:v0.1.19,15,146,161 rancher/shell:v0.1.26,4,15,19 diff --git a/docs/csv/report-rancher-v2.9-head-cves.csv b/docs/csv/report-rancher-v2.9-head-cves.csv index 7def961..b63a899 100644 --- a/docs/csv/report-rancher-v2.9-head-cves.csv +++ b/docs/csv/report-rancher-v2.9-head-cves.csv @@ -278,9 +278,6 @@ rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.9-head,stdlib,v1.21.7,gobinary,CV rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.9-head,stdlib,v1.21.7,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,opt/cni/bin/vlan,"1.21.11, 1.22.4",false,affected, rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.9-head,stdlib,v1.21.7,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,opt/cni/bin/vlan,"1.21.9, 1.22.2",false,affected, rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.9-head,stdlib,v1.21.7,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,opt/cni/bin/vlan,"1.22.7, 1.23.1",false,affected, -rancher/fleet-agent:v0.10.7,rancher/v2.9-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetagent,0.31.0,false,affected, -rancher/fleet:v0.10.7,rancher/v2.9-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleet,0.31.0,false,affected, -rancher/fleet:v0.10.7,rancher/v2.9-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetcontroller,0.31.0,false,affected, rancher/gke-operator:v1.9.5-rc.1,rancher/v2.9-head,golang.org/x/crypto,v0.30.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/gke-operator,0.31.0,false,affected, rancher/hardened-addon-resizer:1.8.20-build20240410,rancher/v2.9-head,stdlib,v1.20.14,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,pod_nanny,"1.21.11, 1.22.4",false,affected, rancher/hardened-addon-resizer:1.8.20-build20240410,rancher/v2.9-head,stdlib,v1.20.14,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,pod_nanny,"1.21.9, 1.22.2",false,affected, @@ -512,6 +509,7 @@ rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9-head,libopenssl-3-fi rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9-head,libopenssl3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3106-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.15.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9-head,libopenssl3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9-head,libprotobuf-lite25_1_0,25.1-150600.16.4.2,suse linux enterprise server,SUSE-SU-2024:3745-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),25.1-150600.16.7.1,false,affected, +rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9-head,openssl-3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3106-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.15.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9-head,openssl-3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, @@ -523,6 +521,7 @@ rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9-head,libgmodule-2_0- rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9-head,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9-head,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, +rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9-head,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9-head,glib2-tools,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, @@ -530,18 +529,21 @@ rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9-head,libgio-2_0-0,2. rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9-head,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.9-head,glib2-tools,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.9-head,libgio-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.9-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.9-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.9-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.9-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rancher/v2.9-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.9-head,glib2-tools,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.9-head,libgio-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.9-head,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.9-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.9-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.9-head,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.26.1-build20241107 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.26.1-build20241107,rancher/v2.9-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,rancher/v2.9-head,glibc,2.31-150300.68.1,suse linux enterprise server,SUSE-SU-2024:1375-1,HIGH,,rancher/hardened-ib-sriov-cni:v1.0.3-build20240327 (suse linux enterprise server 15.5),2.31-150300.74.1,false,affected, rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,rancher/v2.9-head,glibc,2.31-150300.68.1,suse linux enterprise server,SUSE-SU-2024:1895-1,HIGH,,rancher/hardened-ib-sriov-cni:v1.0.3-build20240327 (suse linux enterprise server 15.5),2.31-150300.83.1,false,affected, @@ -872,7 +874,6 @@ rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9-head,perl-base,5.26.1-15030 rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9-head,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2019-12274,HIGH,https://avd.aquasec.com/nvd/cve-2019-12274,usr/bin/harvester-cloud-provider,"2.2.4, 1.6.27",false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9-head,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9-head,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9-head,golang.org/x/crypto,v0.1.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9-head,golang.org/x/net,v0.7.0,gobinary,CVE-2023-39325,HIGH,https://avd.aquasec.com/nvd/cve-2023-39325,usr/bin/harvester-cloud-provider,0.17.0,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9-head,kubevirt.io/kubevirt,v0.54.0,gobinary,CVE-2023-26484,HIGH,https://avd.aquasec.com/nvd/cve-2023-26484,usr/bin/harvester-cloud-provider,,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9-head,kubevirt.io/kubevirt,v0.54.0,gobinary,GHSA-qv98-3369-g364,HIGH,https://github.com/advisories/GHSA-qv98-3369-g364,usr/bin/harvester-cloud-provider,0.55.1,false,affected, @@ -890,7 +891,6 @@ rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9-head,github.com/rancher/ran rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9-head,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9-head,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/harvester-cloud-provider,0.46.0,false,affected, -rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9-head,golang.org/x/crypto,v0.16.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9-head,stdlib,v1.20.13,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/harvester-cloud-provider,"1.21.11, 1.22.4",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9-head,stdlib,v1.20.13,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/harvester-cloud-provider,"1.21.9, 1.22.2",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9-head,stdlib,v1.20.13,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-cloud-provider,"1.22.7, 1.23.1",false,affected, @@ -898,7 +898,6 @@ rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9-head,github.com/rancher/ran rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9-head,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9-head,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/harvester-cloud-provider,0.46.0,false,affected, -rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9-head,golang.org/x/crypto,v0.16.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-cloud-provider,"1.22.7, 1.23.1",false,affected, rancher/harvester-csi-driver:v0.1.5,rancher/v2.9-head,container-suseconnect,2.4.0-150000.4.22.1,suse linux enterprise server,SUSE-SU-2023:0871-1,HIGH,,rancher/harvester-csi-driver:v0.1.5 (suse linux enterprise server 15.4),2.4.0-150000.4.24.1,false,affected, rancher/harvester-csi-driver:v0.1.5,rancher/v2.9-head,curl,7.79.1-150400.5.15.1,suse linux enterprise server,SUSE-SU-2023:2224-1,HIGH,,rancher/harvester-csi-driver:v0.1.5 (suse linux enterprise server 15.4),8.0.1-150400.5.23.1,false,affected, @@ -1293,7 +1292,6 @@ rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.9-head,golang.org/x/crypto, rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.9-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status,0.31.0,false,affected, rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.9-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/helm,0.31.0,false,affected, rancher/kube-api-auth:v0.2.2,rancher/v2.9-head,github.com/rancher/steve,v0.0.0-20240709130809-47871606146c,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/kube-api-auth,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/kube-api-auth:v0.2.2,rancher/v2.9-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-api-auth,0.31.0,false,affected, rancher/kube-api-auth:v0.2.2,rancher/v2.9-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kube-api-auth,"1.22.7, 1.23.1",false,affected, rancher/kubectl:v1.20.2,rancher/v2.9-head,stdlib,v1.15.5,gobinary,CVE-2022-23806,CRITICAL,https://avd.aquasec.com/nvd/cve-2022-23806,bin/kubectl,"1.16.14, 1.17.7",false,affected, rancher/kubectl:v1.20.2,rancher/v2.9-head,stdlib,v1.15.5,gobinary,CVE-2023-24538,CRITICAL,https://avd.aquasec.com/nvd/cve-2023-24538,bin/kubectl,"1.19.8, 1.20.3",false,affected, @@ -1428,11 +1426,9 @@ rancher/kubectl:v1.29.2,rancher/v2.9-head,stdlib,v1.21.7,gobinary,CVE-2024-24790 rancher/kubectl:v1.29.2,rancher/v2.9-head,stdlib,v1.21.7,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,bin/kubectl,"1.21.9, 1.22.2",false,affected, rancher/kubectl:v1.29.2,rancher/v2.9-head,stdlib,v1.21.7,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/kubectl:v1.30.5,rancher/v2.9-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.28,rancher/v2.9-head,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.9-head,stdlib,v1.21.4,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/local-path-provisioner,"1.21.11, 1.22.4",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.9-head,stdlib,v1.21.4,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/local-path-provisioner,"1.21.9, 1.22.2",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.9-head,stdlib,v1.21.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/local-path-provisioner,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.30,rancher/v2.9-head,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.9-head,github.com/prometheus/client_golang,v1.9.0,gobinary,CVE-2022-21698,HIGH,https://avd.aquasec.com/nvd/cve-2022-21698,csi-attacher,1.11.1,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.9-head,golang.org/x/net,v0.0.0-20210410081132-afb366fc7cd1,gobinary,CVE-2021-33194,HIGH,https://avd.aquasec.com/nvd/cve-2021-33194,csi-attacher,0.0.0-20210520170846-37e1c6afe023,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.9-head,golang.org/x/net,v0.0.0-20210410081132-afb366fc7cd1,gobinary,CVE-2022-27664,HIGH,https://avd.aquasec.com/nvd/cve-2022-27664,csi-attacher,0.0.0-20220906165146-f3363e06e74c,false,affected, @@ -1660,7 +1656,6 @@ rancher/longhornio-csi-resizer:v1.2.0,rancher/v2.9-head,stdlib,v1.16,gobinary,CV rancher/longhornio-csi-resizer:v1.2.0,rancher/v2.9-head,stdlib,v1.16,gobinary,CVE-2023-45287,HIGH,https://avd.aquasec.com/nvd/cve-2023-45287,csi-resizer,1.20.0,false,affected, rancher/longhornio-csi-resizer:v1.2.0,rancher/v2.9-head,stdlib,v1.16,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,csi-resizer,"1.21.9, 1.22.2",false,affected, rancher/longhornio-csi-resizer:v1.2.0,rancher/v2.9-head,stdlib,v1.16,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,csi-resizer,"1.22.7, 1.23.1",false,affected, -rancher/machine:v0.15.0-rancher124,rancher/v2.9-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rancher-machine,0.31.0,false,affected, rancher/mirrored-calico-apiserver:v3.26.3,rancher/v2.9-head,github.com/projectcalico/calico,v3.26.3,gobinary,CVE-2024-33522,HIGH,https://avd.aquasec.com/nvd/cve-2024-33522,code/apiserver,"3.26.5, 3.27.3",true,affected, rancher/mirrored-calico-apiserver:v3.26.3,rancher/v2.9-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,code/apiserver,0.46.0,true,affected, rancher/mirrored-calico-apiserver:v3.26.3,rancher/v2.9-head,go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp,v0.35.0,gobinary,CVE-2023-45142,HIGH,https://avd.aquasec.com/nvd/cve-2023-45142,code/apiserver,0.44.0,true,affected, @@ -2268,6 +2263,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9-h rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9-head,expat-libs,2.2.9-11.ph4,photon,CVE-2023-52425,HIGH,https://avd.aquasec.com/nvd/cve-2023-52425,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-1.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9-head,expat-libs,2.2.9-11.ph4,photon,CVE-2024-28757,HIGH,https://avd.aquasec.com/nvd/cve-2024-28757,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-2.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9-head,expat-libs,2.2.9-11.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9-head,glib,2.68.4-1.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9-head,glibc,2.32-15.ph4,photon,CVE-2024-2961,HIGH,https://avd.aquasec.com/nvd/cve-2024-2961,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.32-17.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9-head,glibc-iconv,2.32-15.ph4,photon,CVE-2024-2961,HIGH,https://avd.aquasec.com/nvd/cve-2024-2961,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.32-17.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9-head,krb5,1.17-10.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),1.17-12.ph4,true,affected, @@ -2297,6 +2293,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9-h rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9-head,glib,2.68.4-2.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9-head,krb5,1.17-10.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9-head,krb5,1.17-10.ph4,photon,CVE-2024-37370,HIGH,https://avd.aquasec.com/nvd/cve-2024-37370,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9-head,nss-libs,3.72-4.ph4,photon,CVE-2024-0743,HIGH,https://avd.aquasec.com/nvd/cve-2024-0743,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),3.72-6.ph4,true,affected, @@ -2316,6 +2313,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.9-h rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.9-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.9-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.9-head,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.9-head,glib,2.68.4-2.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.9-head,krb5,1.17-11.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.9-head,krb5,1.17-11.ph4,photon,CVE-2024-37370,HIGH,https://avd.aquasec.com/nvd/cve-2024-37370,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,rancher/v2.9-head,nss-libs,3.72-5.ph4,photon,CVE-2024-0743,HIGH,https://avd.aquasec.com/nvd/cve-2024-0743,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 (photon 4.0),3.72-6.ph4,true,affected, @@ -3896,6 +3894,9 @@ rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.9-head,libglib-2_0-0,2.78.6 rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.9-head,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.9-head,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.9-head,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/consul,0.31.0,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.9-head,libpython3_12-1_0,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.9-head,python312,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.9-head,python312-base,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.9-head,libexpat,2.6.2-r0,alpine,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.9-head,libexpat,2.6.2-r0,alpine,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.9-head,libexpat,2.6.2-r0,alpine,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, @@ -4233,7 +4234,6 @@ rancher/pushprox-client:v0.1.3-rancher2-client,rancher/v2.9-head,stdlib,v1.22.3, rancher/pushprox-client:v0.1.3-rancher2-client,rancher/v2.9-head,stdlib,v1.22.3,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/pushprox-client,"1.22.7, 1.23.1",false,affected, rancher/pushprox-proxy:v0.1.3-rancher2-proxy,rancher/v2.9-head,stdlib,v1.22.3,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/pushprox-proxy,"1.21.11, 1.22.4",false,affected, rancher/pushprox-proxy:v0.1.3-rancher2-proxy,rancher/v2.9-head,stdlib,v1.22.3,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/pushprox-proxy,"1.22.7, 1.23.1",false,affected, -rancher/rancher-agent:v2.9-head,rancher/v2.9-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/agent,0.31.0,false,affected, rancher/rancher-agent:v2.9-head,rancher/v2.9-head,k8s.io/kubernetes,v1.30.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,usr/bin/agent,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rancher-agent:v2.9-head,rancher/v2.9-head,k8s.io/kubernetes,v1.30.1,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,usr/bin/agent,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rancher-agent:v2.9-head,rancher/v2.9-head,stdlib,v1.20.13,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/kubectl,"1.21.11, 1.22.4",false,affected, @@ -4261,7 +4261,6 @@ rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.2,gobinary,CVE-2024-341 rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/bandwidth,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/cni,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/containerd,0.46.0,false,affected, -rancher/rancher:v2.9-head,rancher/v2.9-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/containerd,0.31.0,false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/containerd-shim-runc-v2,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/etcdctl,0.31.0,false,affected, @@ -4271,16 +4270,13 @@ rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.4,gobinary,CVE-2024-341 rancher/rancher:v2.9-head,rancher/v2.9-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/helm_v3,0.31.0,false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/helm_v3,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.45.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/k3s,0.46.0,false,affected, -rancher/rancher:v2.9-head,rancher/v2.9-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/k3s,0.31.0,false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/k3s,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.21.10,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/kustomize,"1.21.11, 1.22.4",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.21.10,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kustomize,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.3,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/loglevel,"1.21.11, 1.22.4",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.3,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/loglevel,"1.22.7, 1.23.1",false,affected, -rancher/rancher:v2.9-head,rancher/v2.9-head,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher,0.31.0,false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,k8s.io/kubernetes,v1.30.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,usr/bin/rancher,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,k8s.io/kubernetes,v1.30.1,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,usr/bin/rancher,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, -rancher/rancher:v2.9-head,rancher/v2.9-head,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/rancher-machine,0.31.0,false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/rancher-machine,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,stdlib,v1.22.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/runc,"1.22.7, 1.23.1",false,affected, rancher/rancher:v2.9-head,rancher/v2.9-head,github.com/rancher/norman,v0.0.0-20210709145327-afd06f533ca3,gobinary,CVE-2023-32193,HIGH,https://avd.aquasec.com/nvd/cve-2023-32193,usr/bin/telemetry,0.0.0-20240207153100-3bb70b772b52,false,affected, @@ -4347,21 +4343,15 @@ rancher/rke2-cloud-provider:v1.29.3-build20240515,rancher/v2.9-head,stdlib,v1.21 rancher/rke2-cloud-provider:v1.29.8-build20240910,rancher/v2.9-head,golang.org/x/crypto,v0.23.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.30.4-build20240910,rancher/v2.9-head,golang.org/x/crypto,v0.23.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016,rancher/v2.9-head,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.9-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.9-head,k8s.io/kubernetes,v1.28.0-rc.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.9-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-runtime:v1.29.11-rke2r1,rancher/v2.9-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.29.11-rke2r1,rancher/v2.9-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-runtime:v1.30.7-rke2r1,rancher/v2.9-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.30.7-rke2r1,rancher/v2.9-head,k8s.io/kubernetes,v1.30.0,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.30.7-rke2r1,rancher/v2.9-head,k8s.io/kubernetes,v1.30.0,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,bin/crictl,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.30.7-rke2r1,rancher/v2.9-head,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.9-head,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.9-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,opt/rke2,"1.22.7, 1.23.1",false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.9-head,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubectl,"1.22.7, 1.23.1",false,affected, -rancher/rke2-upgrade:v1.28.15-rke2r1,rancher/v2.9-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, -rancher/rke2-upgrade:v1.29.11-rke2r1,rancher/v2.9-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, -rancher/rke2-upgrade:v1.30.7-rke2r1,rancher/v2.9-head,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, rancher/security-scan:v0.4.1,rancher/v2.9-head,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-bench,0.31.0,false,affected, rancher/shell:v0.2.1,rancher/v2.9-head,curl,8.6.0-150600.2.2,suse linux enterprise server,SUSE-SU-2024:2784-1,HIGH,,rancher/shell:v0.2.1 (suse linux enterprise server 15.6),8.6.0-150600.4.3.1,false,affected, rancher/shell:v0.2.1,rancher/v2.9-head,libcurl4,8.6.0-150600.2.2,suse linux enterprise server,SUSE-SU-2024:2784-1,HIGH,,rancher/shell:v0.2.1 (suse linux enterprise server 15.6),8.6.0-150600.4.3.1,false,affected, diff --git a/docs/csv/report-rancher-v2.9-head-stats.csv b/docs/csv/report-rancher-v2.9-head-stats.csv index 0af0733..03be696 100644 --- a/docs/csv/report-rancher-v2.9-head-stats.csv +++ b/docs/csv/report-rancher-v2.9-head-stats.csv @@ -8,8 +8,8 @@ rancher/cis-operator:v1.2.3,0,0,0 rancher/eks-operator:v1.9.5-rc.1,0,0,0 rancher/flannel-cni:v0.3.0-rancher9,11,54,65 rancher/flannel-cni:v1.4.1-rancher1,11,21,32 -rancher/fleet-agent:v0.10.7,0,1,1 -rancher/fleet:v0.10.7,0,2,2 +rancher/fleet-agent:v0.10.7,0,0,0 +rancher/fleet:v0.10.7,0,0,0 rancher/gke-operator:v1.9.5-rc.1,0,1,1 rancher/hardened-addon-resizer:1.8.20-build20240410,1,2,3 rancher/hardened-addon-resizer:1.8.20-build20240910,0,0,0 @@ -34,11 +34,11 @@ rancher/hardened-dns-node-cache:1.23.1-build20241008,0,5,5 rancher/hardened-etcd:v3.5.13-k3s1-build20240531,2,10,12 rancher/hardened-etcd:v3.5.13-k3s1-build20240910,0,2,2 rancher/hardened-etcd:v3.5.16-k3s1-build20241106,0,2,2 -rancher/hardened-flannel:v0.25.5-build20240801,0,16,16 -rancher/hardened-flannel:v0.25.6-build20240910,0,9,9 -rancher/hardened-flannel:v0.25.7-build20241008,0,6,6 -rancher/hardened-flannel:v0.26.0-build20241024,0,6,6 -rancher/hardened-flannel:v0.26.1-build20241107,0,6,6 +rancher/hardened-flannel:v0.25.5-build20240801,0,17,17 +rancher/hardened-flannel:v0.25.6-build20240910,0,10,10 +rancher/hardened-flannel:v0.25.7-build20241008,0,7,7 +rancher/hardened-flannel:v0.26.0-build20241024,0,7,7 +rancher/hardened-flannel:v0.26.1-build20241107,0,7,7 rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,1,17,18 rancher/hardened-ib-sriov-cni:v1.1.1-build20240816,1,10,11 rancher/hardened-k8s-metrics-server:v0.7.1-build20240401,1,3,4 @@ -69,9 +69,9 @@ rancher/hardened-sriov-network-webhook:v1.3.0-build20240816,0,10,10 rancher/hardened-whereabouts:v0.7.0-build20240429,2,3,5 rancher/hardened-whereabouts:v0.8.0-build20240910,0,0,0 rancher/hardened-whereabouts:v0.8.0-build20241011,0,0,0 -rancher/harvester-cloud-provider:v0.2.0,1,23,24 -rancher/harvester-cloud-provider:v0.2.1,1,10,11 -rancher/harvester-cloud-provider:v0.2.2,0,6,6 +rancher/harvester-cloud-provider:v0.2.0,1,22,23 +rancher/harvester-cloud-provider:v0.2.1,1,9,10 +rancher/harvester-cloud-provider:v0.2.2,0,5,5 rancher/harvester-csi-driver:v0.1.5,3,75,78 rancher/harvester-csi-driver:v0.1.6,3,55,58 rancher/harvester-csi-driver:v0.1.7,0,9,9 @@ -93,7 +93,7 @@ rancher/klipper-helm:v0.8.4-build20240523,14,102,116 rancher/klipper-helm:v0.9.2-build20240828,0,6,6 rancher/klipper-helm:v0.9.3-build20241008,0,3,3 rancher/klipper-lb:v0.4.9,0,0,0 -rancher/kube-api-auth:v0.2.2,0,3,3 +rancher/kube-api-auth:v0.2.2,0,2,2 rancher/kubectl:v1.20.2,4,43,47 rancher/kubectl:v1.22.6,4,35,39 rancher/kubectl:v1.23.3,4,35,39 @@ -102,13 +102,13 @@ rancher/kubectl:v1.29.0,1,2,3 rancher/kubectl:v1.29.11,0,0,0 rancher/kubectl:v1.29.2,1,2,3 rancher/kubectl:v1.30.5,0,1,1 -rancher/local-path-provisioner:v0.0.28,1,3,4 -rancher/local-path-provisioner:v0.0.30,0,1,1 +rancher/local-path-provisioner:v0.0.28,1,2,3 +rancher/local-path-provisioner:v0.0.30,0,0,0 rancher/longhornio-csi-attacher:v3.2.1,4,52,56 rancher/longhornio-csi-node-driver-registrar:v2.3.0,4,49,53 rancher/longhornio-csi-provisioner:v2.1.2,4,58,62 rancher/longhornio-csi-resizer:v1.2.0,4,52,56 -rancher/machine:v0.15.0-rancher124,0,1,1 +rancher/machine:v0.15.0-rancher124,0,0,0 rancher/mirrored-bci-busybox:15.6.24.2,0,0,0 rancher/mirrored-bci-micro:15.6.24.2,0,0,0 rancher/mirrored-calico-apiserver:v3.26.3,2,19,21 @@ -223,9 +223,9 @@ rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.27.0,3,15,18 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.28.0,1,9,10 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.29.0,1,4,5 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.30.1,1,3,4 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,7,26,33 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,6,15,21 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,5,12,17 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,8,26,34 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,7,15,22 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1,6,12,18 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.2.0,5,18,23 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.3.0,4,15,19 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.3.1,3,9,12 @@ -327,7 +327,7 @@ rancher/mirrored-metrics-server:v0.7.2,0,2,2 rancher/mirrored-neuvector-compliance-config:latest,0,0,0 rancher/mirrored-neuvector-controller:5.4.1,0,8,8 rancher/mirrored-neuvector-enforcer:5.4.1,0,6,6 -rancher/mirrored-neuvector-manager:5.4.1,0,0,0 +rancher/mirrored-neuvector-manager:5.4.1,0,3,3 rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,2,13,15 rancher/mirrored-neuvector-registry-adapter:0.1.3,0,2,2 rancher/mirrored-neuvector-scanner:latest,0,1,1 @@ -375,10 +375,10 @@ rancher/nginx-ingress-controller:v1.10.5-hardened4,0,5,5 rancher/prometheus-federator:v0.3.4,1,15,16 rancher/pushprox-client:v0.1.3-rancher2-client,1,1,2 rancher/pushprox-proxy:v0.1.3-rancher2-proxy,1,1,2 -rancher/rancher-agent:v2.9-head,2,6,8 +rancher/rancher-agent:v2.9-head,2,5,7 rancher/rancher-csp-adapter:v4.0.0,0,3,3 rancher/rancher-webhook:v0.5.4,0,2,2 -rancher/rancher:v2.9-head,6,38,44 +rancher/rancher:v2.9-head,6,34,40 rancher/rke-tools:v0.1.100,5,32,37 rancher/rke-tools:v0.1.105,2,9,11 rancher/rke2-cloud-provider:v1.28.13-build20240910,0,1,1 @@ -388,13 +388,13 @@ rancher/rke2-cloud-provider:v1.29.3-build20240515,1,2,3 rancher/rke2-cloud-provider:v1.29.8-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.30.4-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016,0,1,1 -rancher/rke2-runtime:v1.28.15-rke2r1,0,3,3 -rancher/rke2-runtime:v1.29.11-rke2r1,0,2,2 -rancher/rke2-runtime:v1.30.7-rke2r1,0,4,4 +rancher/rke2-runtime:v1.28.15-rke2r1,0,2,2 +rancher/rke2-runtime:v1.29.11-rke2r1,0,1,1 +rancher/rke2-runtime:v1.30.7-rke2r1,0,3,3 rancher/rke2-upgrade:v1.27.16-rke2r2,0,3,3 -rancher/rke2-upgrade:v1.28.15-rke2r1,0,1,1 -rancher/rke2-upgrade:v1.29.11-rke2r1,0,1,1 -rancher/rke2-upgrade:v1.30.7-rke2r1,0,1,1 +rancher/rke2-upgrade:v1.28.15-rke2r1,0,0,0 +rancher/rke2-upgrade:v1.29.11-rke2r1,0,0,0 +rancher/rke2-upgrade:v1.30.7-rke2r1,0,0,0 rancher/security-scan:v0.4.1,0,1,1 rancher/shell:v0.2.1,4,14,18 rancher/shell:v0.2.2,3,8,11 diff --git a/docs/csv/report-rancher-v2.9.4-cves.csv b/docs/csv/report-rancher-v2.9.4-cves.csv index 6dcb134..3b2fdd4 100644 --- a/docs/csv/report-rancher-v2.9.4-cves.csv +++ b/docs/csv/report-rancher-v2.9.4-cves.csv @@ -278,10 +278,7 @@ rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.9.4,stdlib,v1.21.7,gobinary,CVE-2 rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.9.4,stdlib,v1.21.7,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,opt/cni/bin/vlan,"1.21.11, 1.22.4",false,affected, rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.9.4,stdlib,v1.21.7,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,opt/cni/bin/vlan,"1.21.9, 1.22.2",false,affected, rancher/flannel-cni:v1.4.1-rancher1,rancher/v2.9.4,stdlib,v1.21.7,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,opt/cni/bin/vlan,"1.22.7, 1.23.1",false,affected, -rancher/fleet-agent:v0.10.6,rancher/v2.9.4,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetagent,0.31.0,false,affected, rancher/fleet:v0.10.6,rancher/v2.9.4,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/fleet:v0.10.6 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, -rancher/fleet:v0.10.6,rancher/v2.9.4,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleet,0.31.0,false,affected, -rancher/fleet:v0.10.6,rancher/v2.9.4,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/fleetcontroller,0.31.0,false,affected, rancher/gke-operator:v1.9.4,rancher/v2.9.4,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/gke-operator,0.31.0,false,affected, rancher/hardened-addon-resizer:1.8.20-build20240410,rancher/v2.9.4,stdlib,v1.20.14,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,pod_nanny,"1.21.11, 1.22.4",false,affected, rancher/hardened-addon-resizer:1.8.20-build20240410,rancher/v2.9.4,stdlib,v1.20.14,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,pod_nanny,"1.21.9, 1.22.2",false,affected, @@ -505,6 +502,7 @@ rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9.4,libopenssl-3-fips- rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9.4,libopenssl3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3106-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.15.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9.4,libopenssl3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9.4,libprotobuf-lite25_1_0,25.1-150600.16.4.2,suse linux enterprise server,SUSE-SU-2024:3745-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),25.1-150600.16.7.1,false,affected, +rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9.4,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9.4,openssl-3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3106-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.15.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9.4,openssl-3,3.1.4-150600.5.10.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.5-build20240801 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.5-build20240801,rancher/v2.9.4,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, @@ -516,6 +514,7 @@ rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9.4,libgmodule-2_0-0,2 rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9.4,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9.4,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9.4,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, +rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9.4,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9.4,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/hardened-flannel:v0.25.6-build20240910 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/hardened-flannel:v0.25.6-build20240910,rancher/v2.9.4,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9.4,glib2-tools,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, @@ -523,6 +522,7 @@ rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9.4,libgio-2_0-0,2.78. rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9.4,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9.4,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9.4,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9.4,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rancher/v2.9.4,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,rancher/v2.9.4,glibc,2.31-150300.68.1,suse linux enterprise server,SUSE-SU-2024:1375-1,HIGH,,rancher/hardened-ib-sriov-cni:v1.0.3-build20240327 (suse linux enterprise server 15.5),2.31-150300.74.1,false,affected, rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,rancher/v2.9.4,glibc,2.31-150300.68.1,suse linux enterprise server,SUSE-SU-2024:1895-1,HIGH,,rancher/hardened-ib-sriov-cni:v1.0.3-build20240327 (suse linux enterprise server 15.5),2.31-150300.83.1,false,affected, @@ -848,7 +848,6 @@ rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9.4,perl-base,5.26.1-150300.1 rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9.4,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2019-12274,HIGH,https://avd.aquasec.com/nvd/cve-2019-12274,usr/bin/harvester-cloud-provider,"2.2.4, 1.6.27",false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9.4,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9.4,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9.4,golang.org/x/crypto,v0.1.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9.4,golang.org/x/net,v0.7.0,gobinary,CVE-2023-39325,HIGH,https://avd.aquasec.com/nvd/cve-2023-39325,usr/bin/harvester-cloud-provider,0.17.0,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9.4,kubevirt.io/kubevirt,v0.54.0,gobinary,CVE-2023-26484,HIGH,https://avd.aquasec.com/nvd/cve-2023-26484,usr/bin/harvester-cloud-provider,,false,affected, rancher/harvester-cloud-provider:v0.2.0,rancher/v2.9.4,kubevirt.io/kubevirt,v0.54.0,gobinary,GHSA-qv98-3369-g364,HIGH,https://github.com/advisories/GHSA-qv98-3369-g364,usr/bin/harvester-cloud-provider,0.55.1,false,affected, @@ -866,7 +865,6 @@ rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9.4,github.com/rancher/ranche rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9.4,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9.4,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9.4,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/harvester-cloud-provider,0.46.0,false,affected, -rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9.4,golang.org/x/crypto,v0.16.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9.4,stdlib,v1.20.13,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/harvester-cloud-provider,"1.21.11, 1.22.4",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9.4,stdlib,v1.20.13,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/harvester-cloud-provider,"1.21.9, 1.22.2",false,affected, rancher/harvester-cloud-provider:v0.2.1,rancher/v2.9.4,stdlib,v1.20.13,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-cloud-provider,"1.22.7, 1.23.1",false,affected, @@ -874,7 +872,6 @@ rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9.4,github.com/rancher/ranche rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9.4,github.com/rancher/rancher,v0.0.0-20230124173128-2207cfed1803,gobinary,CVE-2021-36775,HIGH,https://avd.aquasec.com/nvd/cve-2021-36775,usr/bin/harvester-cloud-provider,"2.4.18, 2.5.12, 2.6.3",false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9.4,github.com/rancher/steve,v0.0.0-20221209194631-acf9d31ce0dd,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/harvester-cloud-provider,0.0.0-20241029132712-2175e090fe4b,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9.4,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,usr/bin/harvester-cloud-provider,0.46.0,false,affected, -rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9.4,golang.org/x/crypto,v0.16.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/harvester-cloud-provider,0.31.0,false,affected, rancher/harvester-cloud-provider:v0.2.2,rancher/v2.9.4,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/harvester-cloud-provider,"1.22.7, 1.23.1",false,affected, rancher/harvester-csi-driver:v0.1.5,rancher/v2.9.4,container-suseconnect,2.4.0-150000.4.22.1,suse linux enterprise server,SUSE-SU-2023:0871-1,HIGH,,rancher/harvester-csi-driver:v0.1.5 (suse linux enterprise server 15.4),2.4.0-150000.4.24.1,false,affected, rancher/harvester-csi-driver:v0.1.5,rancher/v2.9.4,curl,7.79.1-150400.5.15.1,suse linux enterprise server,SUSE-SU-2023:2224-1,HIGH,,rancher/harvester-csi-driver:v0.1.5 (suse linux enterprise server 15.4),8.0.1-150400.5.23.1,false,affected, @@ -1269,7 +1266,6 @@ rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.9.4,golang.org/x/crypto,v0. rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.9.4,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status,0.31.0,false,affected, rancher/klipper-helm:v0.9.3-build20241008,rancher/v2.9.4,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/helm,0.31.0,false,affected, rancher/kube-api-auth:v0.2.2,rancher/v2.9.4,github.com/rancher/steve,v0.0.0-20240709130809-47871606146c,gobinary,CVE-2024-52280,HIGH,https://avd.aquasec.com/nvd/cve-2024-52280,usr/bin/kube-api-auth,0.0.0-20241029132712-2175e090fe4b,false,affected, -rancher/kube-api-auth:v0.2.2,rancher/v2.9.4,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-api-auth,0.31.0,false,affected, rancher/kube-api-auth:v0.2.2,rancher/v2.9.4,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/kube-api-auth,"1.22.7, 1.23.1",false,affected, rancher/kubectl:v1.20.2,rancher/v2.9.4,stdlib,v1.15.5,gobinary,CVE-2022-23806,CRITICAL,https://avd.aquasec.com/nvd/cve-2022-23806,bin/kubectl,"1.16.14, 1.17.7",false,affected, rancher/kubectl:v1.20.2,rancher/v2.9.4,stdlib,v1.15.5,gobinary,CVE-2023-24538,CRITICAL,https://avd.aquasec.com/nvd/cve-2023-24538,bin/kubectl,"1.19.8, 1.20.3",false,affected, @@ -1366,11 +1362,9 @@ rancher/kubectl:v1.29.2,rancher/v2.9.4,stdlib,v1.21.7,gobinary,CVE-2023-45288,HI rancher/kubectl:v1.29.2,rancher/v2.9.4,stdlib,v1.21.7,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/kubectl:v1.29.7,rancher/v2.9.4,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/kubectl:v1.30.5,rancher/v2.9.4,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,bin/kubectl,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.28,rancher/v2.9.4,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.9.4,stdlib,v1.21.4,gobinary,CVE-2024-24790,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-24790,usr/bin/local-path-provisioner,"1.21.11, 1.22.4",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.9.4,stdlib,v1.21.4,gobinary,CVE-2023-45288,HIGH,https://avd.aquasec.com/nvd/cve-2023-45288,usr/bin/local-path-provisioner,"1.21.9, 1.22.2",false,affected, rancher/local-path-provisioner:v0.0.28,rancher/v2.9.4,stdlib,v1.21.4,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/bin/local-path-provisioner,"1.22.7, 1.23.1",false,affected, -rancher/local-path-provisioner:v0.0.30,rancher/v2.9.4,golang.org/x/crypto,v0.25.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/local-path-provisioner,0.31.0,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.9.4,github.com/prometheus/client_golang,v1.9.0,gobinary,CVE-2022-21698,HIGH,https://avd.aquasec.com/nvd/cve-2022-21698,csi-attacher,1.11.1,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.9.4,golang.org/x/net,v0.0.0-20210410081132-afb366fc7cd1,gobinary,CVE-2021-33194,HIGH,https://avd.aquasec.com/nvd/cve-2021-33194,csi-attacher,0.0.0-20210520170846-37e1c6afe023,false,affected, rancher/longhornio-csi-attacher:v3.2.1,rancher/v2.9.4,golang.org/x/net,v0.0.0-20210410081132-afb366fc7cd1,gobinary,CVE-2022-27664,HIGH,https://avd.aquasec.com/nvd/cve-2022-27664,csi-attacher,0.0.0-20220906165146-f3363e06e74c,false,affected, @@ -1602,7 +1596,6 @@ rancher/machine:v0.15.0-rancher118,rancher/v2.9.4,libglib-2_0-0,2.78.6-150600.4. rancher/machine:v0.15.0-rancher118,rancher/v2.9.4,libopenssl-3-fips-provider,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/machine:v0.15.0-rancher118 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/machine:v0.15.0-rancher118,rancher/v2.9.4,libopenssl3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/machine:v0.15.0-rancher118 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, rancher/machine:v0.15.0-rancher118,rancher/v2.9.4,openssl-3,3.1.4-150600.5.15.1,suse linux enterprise server,SUSE-SU-2024:3501-1,HIGH,,rancher/machine:v0.15.0-rancher118 (suse linux enterprise server 15.6),3.1.4-150600.5.18.1,false,affected, -rancher/machine:v0.15.0-rancher118,rancher/v2.9.4,golang.org/x/crypto,v0.26.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rancher-machine,0.31.0,false,affected, rancher/machine:v0.15.0-rancher118,rancher/v2.9.4,stdlib,v1.22.6,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/rancher-machine,"1.22.7, 1.23.1",false,affected, rancher/mirrored-calico-apiserver:v3.26.3,rancher/v2.9.4,github.com/projectcalico/calico,v3.26.3,gobinary,CVE-2024-33522,HIGH,https://avd.aquasec.com/nvd/cve-2024-33522,code/apiserver,"3.26.5, 3.27.3",true,affected, rancher/mirrored-calico-apiserver:v3.26.3,rancher/v2.9.4,go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc,v0.35.0,gobinary,CVE-2023-47108,HIGH,https://avd.aquasec.com/nvd/cve-2023-47108,code/apiserver,0.46.0,true,affected, @@ -2195,6 +2188,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9.4 rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9.4,expat-libs,2.2.9-11.ph4,photon,CVE-2023-52425,HIGH,https://avd.aquasec.com/nvd/cve-2023-52425,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-1.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9.4,expat-libs,2.2.9-11.ph4,photon,CVE-2024-28757,HIGH,https://avd.aquasec.com/nvd/cve-2024-28757,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-2.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9.4,expat-libs,2.2.9-11.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9.4,glib,2.68.4-1.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9.4,glibc,2.32-15.ph4,photon,CVE-2024-2961,HIGH,https://avd.aquasec.com/nvd/cve-2024-2961,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.32-17.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9.4,glibc-iconv,2.32-15.ph4,photon,CVE-2024-2961,HIGH,https://avd.aquasec.com/nvd/cve-2024-2961,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),2.32-17.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,rancher/v2.9.4,krb5,1.17-10.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 (photon 4.0),1.17-12.ph4,true,affected, @@ -2224,6 +2218,7 @@ rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9.4 rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9.4,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9.4,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9.4,expat-libs,2.4.9-2.ph4,photon,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.4.9-3.ph4,true,affected, +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9.4,glib,2.68.4-2.ph4,photon,CVE-2024-52533,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-52533,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),2.68.4-3.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9.4,krb5,1.17-10.ph4,photon,CVE-2024-37371,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-37371,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9.4,krb5,1.17-10.ph4,photon,CVE-2024-37370,HIGH,https://avd.aquasec.com/nvd/cve-2024-37370,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),1.17-12.ph4,true,affected, rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,rancher/v2.9.4,nss-libs,3.72-4.ph4,photon,CVE-2024-0743,HIGH,https://avd.aquasec.com/nvd/cve-2024-0743,rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 (photon 4.0),3.72-6.ph4,true,affected, @@ -3794,6 +3789,9 @@ rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.9.4,libglib-2_0-0,2.78.6-15 rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.9.4,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.9.4,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/mirrored-neuvector-enforcer:5.4.1 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,true,affected, rancher/mirrored-neuvector-enforcer:5.4.1,rancher/v2.9.4,golang.org/x/crypto,v0.22.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/consul,0.31.0,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.9.4,libpython3_12-1_0,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.9.4,python312,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, +rancher/mirrored-neuvector-manager:5.4.1,rancher/v2.9.4,python312-base,3.12.7-150600.3.9.1,suse linux enterprise server,SUSE-SU-2024:4291-1,HIGH,,rancher/mirrored-neuvector-manager:5.4.1 (suse linux enterprise server 15.6),3.12.8-150600.3.12.1,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.9.4,libexpat,2.6.2-r0,alpine,CVE-2024-45491,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45491,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.9.4,libexpat,2.6.2-r0,alpine,CVE-2024-45492,CRITICAL,https://avd.aquasec.com/nvd/cve-2024-45492,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,rancher/v2.9.4,libexpat,2.6.2-r0,alpine,CVE-2024-45490,HIGH,https://avd.aquasec.com/nvd/cve-2024-45490,rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 (alpine 3.20.0),2.6.3-r0,true,affected, @@ -4137,21 +4135,15 @@ rancher/rke2-cloud-provider:v1.29.3-build20240515,rancher/v2.9.4,stdlib,v1.21.10 rancher/rke2-cloud-provider:v1.29.8-build20240910,rancher/v2.9.4,golang.org/x/crypto,v0.23.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.30.4-build20240910,rancher/v2.9.4,golang.org/x/crypto,v0.23.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016,rancher/v2.9.4,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.9.4,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.9.4,k8s.io/kubernetes,v1.28.0-rc.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rancher/v2.9.4,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-runtime:v1.29.10-rke2r1,rancher/v2.9.4,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.29.10-rke2r1,rancher/v2.9.4,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, -rancher/rke2-runtime:v1.30.6-rke2r1,rancher/v2.9.4,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.30.6-rke2r1,rancher/v2.9.4,k8s.io/kubernetes,v1.30.0,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.30.6-rke2r1,rancher/v2.9.4,k8s.io/kubernetes,v1.30.0,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,bin/crictl,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.30.6-rke2r1,rancher/v2.9.4,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.9.4,golang.org/x/crypto,v0.14.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.9.4,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,opt/rke2,"1.22.7, 1.23.1",false,affected, rancher/rke2-upgrade:v1.27.16-rke2r2,rancher/v2.9.4,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubectl,"1.22.7, 1.23.1",false,affected, -rancher/rke2-upgrade:v1.28.15-rke2r1,rancher/v2.9.4,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, -rancher/rke2-upgrade:v1.29.10-rke2r1,rancher/v2.9.4,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, -rancher/rke2-upgrade:v1.30.6-rke2r1,rancher/v2.9.4,golang.org/x/crypto,v0.17.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/rke2,0.31.0,false,affected, rancher/security-scan:v0.4.0,rancher/v2.9.4,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/bin/kube-bench,0.31.0,false,affected, rancher/security-scan:v0.4.0,rancher/v2.9.4,stdlib,v1.22.5,gobinary,CVE-2024-34156,HIGH,https://avd.aquasec.com/nvd/cve-2024-34156,usr/local/bin/kubectl,"1.22.7, 1.23.1",false,affected, rancher/shell:v0.2.1,rancher/v2.9.4,curl,8.6.0-150600.2.2,suse linux enterprise server,SUSE-SU-2024:2784-1,HIGH,,rancher/shell:v0.2.1 (suse linux enterprise server 15.6),8.6.0-150600.4.3.1,false,affected, diff --git a/docs/csv/report-rancher-v2.9.4-stats.csv b/docs/csv/report-rancher-v2.9.4-stats.csv index e80a3da..3cf49a9 100644 --- a/docs/csv/report-rancher-v2.9.4-stats.csv +++ b/docs/csv/report-rancher-v2.9.4-stats.csv @@ -8,8 +8,8 @@ rancher/cis-operator:v1.2.0,0,0,0 rancher/eks-operator:v1.9.4,0,0,0 rancher/flannel-cni:v0.3.0-rancher9,11,54,65 rancher/flannel-cni:v1.4.1-rancher1,11,21,32 -rancher/fleet-agent:v0.10.6,0,1,1 -rancher/fleet:v0.10.6,0,3,3 +rancher/fleet-agent:v0.10.6,0,0,0 +rancher/fleet:v0.10.6,0,1,1 rancher/gke-operator:v1.9.4,0,1,1 rancher/hardened-addon-resizer:1.8.20-build20240410,1,2,3 rancher/hardened-addon-resizer:1.8.20-build20240910,0,0,0 @@ -31,9 +31,9 @@ rancher/hardened-dns-node-cache:1.23.1-build20240910,0,5,5 rancher/hardened-dns-node-cache:1.23.1-build20241008,0,5,5 rancher/hardened-etcd:v3.5.13-k3s1-build20240531,2,10,12 rancher/hardened-etcd:v3.5.13-k3s1-build20240910,0,2,2 -rancher/hardened-flannel:v0.25.5-build20240801,0,16,16 -rancher/hardened-flannel:v0.25.6-build20240910,0,9,9 -rancher/hardened-flannel:v0.25.7-build20241008,0,6,6 +rancher/hardened-flannel:v0.25.5-build20240801,0,17,17 +rancher/hardened-flannel:v0.25.6-build20240910,0,10,10 +rancher/hardened-flannel:v0.25.7-build20241008,0,7,7 rancher/hardened-ib-sriov-cni:v1.0.3-build20240327,1,17,18 rancher/hardened-ib-sriov-cni:v1.1.1-build20240816,1,10,11 rancher/hardened-k8s-metrics-server:v0.7.1-build20240401,1,3,4 @@ -63,9 +63,9 @@ rancher/hardened-sriov-network-webhook:v1.3.0-build20240816,0,10,10 rancher/hardened-whereabouts:v0.7.0-build20240429,2,3,5 rancher/hardened-whereabouts:v0.8.0-build20240910,0,0,0 rancher/hardened-whereabouts:v0.8.0-build20241011,0,0,0 -rancher/harvester-cloud-provider:v0.2.0,1,23,24 -rancher/harvester-cloud-provider:v0.2.1,1,10,11 -rancher/harvester-cloud-provider:v0.2.2,0,6,6 +rancher/harvester-cloud-provider:v0.2.0,1,22,23 +rancher/harvester-cloud-provider:v0.2.1,1,9,10 +rancher/harvester-cloud-provider:v0.2.2,0,5,5 rancher/harvester-csi-driver:v0.1.5,3,75,78 rancher/harvester-csi-driver:v0.1.6,3,55,58 rancher/harvester-csi-driver:v0.1.7,0,9,9 @@ -87,7 +87,7 @@ rancher/klipper-helm:v0.8.4-build20240523,14,102,116 rancher/klipper-helm:v0.9.2-build20240828,0,6,6 rancher/klipper-helm:v0.9.3-build20241008,0,3,3 rancher/klipper-lb:v0.4.9,0,0,0 -rancher/kube-api-auth:v0.2.2,0,3,3 +rancher/kube-api-auth:v0.2.2,0,2,2 rancher/kubectl:v1.20.2,4,43,47 rancher/kubectl:v1.23.3,4,35,39 rancher/kubectl:v1.28.12,0,1,1 @@ -95,13 +95,13 @@ rancher/kubectl:v1.29.0,1,2,3 rancher/kubectl:v1.29.2,1,2,3 rancher/kubectl:v1.29.7,0,1,1 rancher/kubectl:v1.30.5,0,1,1 -rancher/local-path-provisioner:v0.0.28,1,3,4 -rancher/local-path-provisioner:v0.0.30,0,1,1 +rancher/local-path-provisioner:v0.0.28,1,2,3 +rancher/local-path-provisioner:v0.0.30,0,0,0 rancher/longhornio-csi-attacher:v3.2.1,4,52,56 rancher/longhornio-csi-node-driver-registrar:v2.3.0,4,49,53 rancher/longhornio-csi-provisioner:v2.1.2,4,58,62 rancher/longhornio-csi-resizer:v1.2.0,4,52,56 -rancher/machine:v0.15.0-rancher118,0,6,6 +rancher/machine:v0.15.0-rancher118,0,5,5 rancher/mirrored-bci-busybox:15.6.24.2,0,0,0 rancher/mirrored-bci-micro:15.6.24.2,0,0,0 rancher/mirrored-calico-apiserver:v3.26.3,2,19,21 @@ -199,8 +199,8 @@ rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.27.0,3,15,18 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.28.0,1,9,10 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.29.0,1,4,5 rancher/mirrored-cloud-provider-vsphere-cpi-release-manager:v1.30.1,1,3,4 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,7,26,33 -rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,6,15,21 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0,8,26,34 +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0,7,15,22 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.2.0,5,18,23 rancher/mirrored-cloud-provider-vsphere-csi-release-syncer:v3.3.0,4,15,19 rancher/mirrored-cluster-api-controller:v1.7.3,0,2,2 @@ -301,7 +301,7 @@ rancher/mirrored-metrics-server:v0.7.2,0,2,2 rancher/mirrored-neuvector-compliance-config:latest,0,0,0 rancher/mirrored-neuvector-controller:5.4.1,0,8,8 rancher/mirrored-neuvector-enforcer:5.4.1,0,6,6 -rancher/mirrored-neuvector-manager:5.4.1,0,0,0 +rancher/mirrored-neuvector-manager:5.4.1,0,3,3 rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0,2,13,15 rancher/mirrored-neuvector-registry-adapter:0.1.3,0,2,2 rancher/mirrored-neuvector-scanner:latest,0,1,1 @@ -358,13 +358,13 @@ rancher/rke2-cloud-provider:v1.29.3-build20240515,1,2,3 rancher/rke2-cloud-provider:v1.29.8-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.30.4-build20240910,0,1,1 rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016,0,1,1 -rancher/rke2-runtime:v1.28.15-rke2r1,0,3,3 -rancher/rke2-runtime:v1.29.10-rke2r1,0,2,2 -rancher/rke2-runtime:v1.30.6-rke2r1,0,4,4 +rancher/rke2-runtime:v1.28.15-rke2r1,0,2,2 +rancher/rke2-runtime:v1.29.10-rke2r1,0,1,1 +rancher/rke2-runtime:v1.30.6-rke2r1,0,3,3 rancher/rke2-upgrade:v1.27.16-rke2r2,0,3,3 -rancher/rke2-upgrade:v1.28.15-rke2r1,0,1,1 -rancher/rke2-upgrade:v1.29.10-rke2r1,0,1,1 -rancher/rke2-upgrade:v1.30.6-rke2r1,0,1,1 +rancher/rke2-upgrade:v1.28.15-rke2r1,0,0,0 +rancher/rke2-upgrade:v1.29.10-rke2r1,0,0,0 +rancher/rke2-upgrade:v1.30.6-rke2r1,0,0,0 rancher/security-scan:v0.4.0,0,2,2 rancher/shell:v0.2.1,4,14,18 rancher/shell:v0.2.2,3,8,11 diff --git a/docs/csv/report-rke2-v1.28-cves.csv b/docs/csv/report-rke2-v1.28-cves.csv index 1b7000e..35610fa 100644 --- a/docs/csv/report-rke2-v1.28-cves.csv +++ b/docs/csv/report-rke2-v1.28-cves.csv @@ -18,6 +18,7 @@ rancher/hardened-flannel:v0.25.7-build20241008,rke2/v1.28,libgio-2_0-0,2.78.6-15 rancher/hardened-flannel:v0.25.7-build20241008,rke2/v1.28,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rke2/v1.28,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rke2/v1.28,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.25.7-build20241008,rke2/v1.28,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.25.7-build20241008 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.25.7-build20241008,rke2/v1.28,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,rke2/v1.28,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, rancher/hardened-kubernetes:v1.28.15-rke2r1-build20241023,rke2/v1.28,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/kube-apiserver,0.31.0,false,affected, @@ -39,6 +40,5 @@ rancher/nginx-ingress-controller:v1.10.5-hardened3,rke2/v1.28,libgobject-2_0-0,2 rancher/nginx-ingress-controller:v1.10.5-hardened3,rke2/v1.28,libprotobuf25_1_0,25.1-150600.16.4.2,suse linux enterprise server,SUSE-SU-2024:3745-1,HIGH,,rancher/nginx-ingress-controller:v1.10.5-hardened3 (suse linux enterprise server 15.6),25.1-150600.16.7.1,false,affected, rancher/nginx-ingress-controller:v1.10.5-hardened3,rke2/v1.28,libprotoc25_1_0,25.1-150600.16.4.2,suse linux enterprise server,SUSE-SU-2024:3745-1,HIGH,,rancher/nginx-ingress-controller:v1.10.5-hardened3 (suse linux enterprise server 15.6),25.1-150600.16.7.1,false,affected, rancher/rke2-cloud-provider:v1.28.15-0.20241016053552-63bfb1936862-build20241016,rke2/v1.28,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.28.15-rke2r1,rke2/v1.28,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rke2/v1.28,k8s.io/kubernetes,v1.28.0-rc.1,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.28.15-rke2r1,rke2/v1.28,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, diff --git a/docs/csv/report-rke2-v1.28-stats.csv b/docs/csv/report-rke2-v1.28-stats.csv index b3f923b..facaf00 100644 --- a/docs/csv/report-rke2-v1.28-stats.csv +++ b/docs/csv/report-rke2-v1.28-stats.csv @@ -5,7 +5,7 @@ rancher/hardened-cluster-autoscaler:v1.8.11-build20241014,0,0,0 rancher/hardened-coredns:v1.11.3-build20241018,0,1,1 rancher/hardened-dns-node-cache:1.23.1-build20241008,0,5,5 rancher/hardened-etcd:v3.5.13-k3s1-build20240910,0,2,2 -rancher/hardened-flannel:v0.25.7-build20241008,0,6,6 +rancher/hardened-flannel:v0.25.7-build20241008,0,7,7 rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,0,1,1 rancher/hardened-kubernetes:v1.28.15-rke2r1-build20241023,0,6,6 rancher/klipper-helm:v0.9.3-build20241008,0,3,3 @@ -16,4 +16,4 @@ rancher/mirrored-sig-storage-snapshot-controller:v8.1.0,0,1,1 rancher/mirrored-sig-storage-snapshot-validation-webhook:v8.1.0,0,1,1 rancher/nginx-ingress-controller:v1.10.5-hardened3,0,7,7 rancher/rke2-cloud-provider:v1.28.15-0.20241016053552-63bfb1936862-build20241016,0,1,1 -rancher/rke2-runtime:v1.28.15-rke2r1,0,3,3 +rancher/rke2-runtime:v1.28.15-rke2r1,0,2,2 diff --git a/docs/csv/report-rke2-v1.29-cves.csv b/docs/csv/report-rke2-v1.29-cves.csv index 42ed92e..dee9b99 100644 --- a/docs/csv/report-rke2-v1.29-cves.csv +++ b/docs/csv/report-rke2-v1.29-cves.csv @@ -18,6 +18,7 @@ rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.29,libgio-2_0-0,2.78.6-15 rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.29,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.29,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.29,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.29,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.29,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,rke2/v1.29,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, rancher/hardened-kubernetes:v1.29.11-rke2r1-build20241202,rke2/v1.29,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/kube-apiserver,0.31.0,false,affected, @@ -37,5 +38,4 @@ rancher/nginx-ingress-controller:v1.10.5-hardened4,rke2/v1.29,libglib-2_0-0,2.78 rancher/nginx-ingress-controller:v1.10.5-hardened4,rke2/v1.29,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/nginx-ingress-controller:v1.10.5-hardened4 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/nginx-ingress-controller:v1.10.5-hardened4,rke2/v1.29,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/nginx-ingress-controller:v1.10.5-hardened4 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/rke2-cloud-provider:v1.29.10-0.20241016053521-9510ac25fefb-build20241016,rke2/v1.29,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.29.11-rke2r1,rke2/v1.29,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.29.11-rke2r1,rke2/v1.29,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, diff --git a/docs/csv/report-rke2-v1.29-stats.csv b/docs/csv/report-rke2-v1.29-stats.csv index 8c4431c..88cb0c1 100644 --- a/docs/csv/report-rke2-v1.29-stats.csv +++ b/docs/csv/report-rke2-v1.29-stats.csv @@ -5,7 +5,7 @@ rancher/hardened-cluster-autoscaler:v1.8.11-build20241014,0,0,0 rancher/hardened-coredns:v1.11.3-build20241018,0,1,1 rancher/hardened-dns-node-cache:1.23.1-build20241008,0,5,5 rancher/hardened-etcd:v3.5.16-k3s1-build20241106,0,2,2 -rancher/hardened-flannel:v0.26.0-build20241024,0,6,6 +rancher/hardened-flannel:v0.26.0-build20241024,0,7,7 rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,0,1,1 rancher/hardened-kubernetes:v1.29.11-rke2r1-build20241202,0,6,6 rancher/klipper-helm:v0.9.3-build20241008,0,3,3 @@ -16,4 +16,4 @@ rancher/mirrored-sig-storage-snapshot-controller:v8.1.0,0,1,1 rancher/mirrored-sig-storage-snapshot-validation-webhook:v8.1.0,0,1,1 rancher/nginx-ingress-controller:v1.10.5-hardened4,0,5,5 rancher/rke2-cloud-provider:v1.29.10-0.20241016053521-9510ac25fefb-build20241016,0,1,1 -rancher/rke2-runtime:v1.29.11-rke2r1,0,2,2 +rancher/rke2-runtime:v1.29.11-rke2r1,0,1,1 diff --git a/docs/csv/report-rke2-v1.30-cves.csv b/docs/csv/report-rke2-v1.30-cves.csv index cfbec3a..d1a8c5c 100644 --- a/docs/csv/report-rke2-v1.30-cves.csv +++ b/docs/csv/report-rke2-v1.30-cves.csv @@ -18,6 +18,7 @@ rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.30,libgio-2_0-0,2.78.6-15 rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.30,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.30,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.30,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.30,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.30,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,rke2/v1.30,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, rancher/hardened-kubernetes:v1.30.7-rke2r1-build20241126,rke2/v1.30,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/kube-apiserver,0.31.0,false,affected, @@ -37,7 +38,6 @@ rancher/nginx-ingress-controller:v1.10.5-hardened4,rke2/v1.30,libglib-2_0-0,2.78 rancher/nginx-ingress-controller:v1.10.5-hardened4,rke2/v1.30,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/nginx-ingress-controller:v1.10.5-hardened4 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/nginx-ingress-controller:v1.10.5-hardened4,rke2/v1.30,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/nginx-ingress-controller:v1.10.5-hardened4 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016,rke2/v1.30,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.30.7-rke2r1,rke2/v1.30,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.30.7-rke2r1,rke2/v1.30,k8s.io/kubernetes,v1.30.0,gobinary,CVE-2024-10220,HIGH,https://avd.aquasec.com/nvd/cve-2024-10220,bin/crictl,"1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.30.7-rke2r1,rke2/v1.30,k8s.io/kubernetes,v1.30.0,gobinary,CVE-2024-5321,HIGH,https://avd.aquasec.com/nvd/cve-2024-5321,bin/crictl,"1.27.16, 1.28.12, 1.29.7, 1.30.3",false,affected, rancher/rke2-runtime:v1.30.7-rke2r1,rke2/v1.30,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, diff --git a/docs/csv/report-rke2-v1.30-stats.csv b/docs/csv/report-rke2-v1.30-stats.csv index d460286..088034f 100644 --- a/docs/csv/report-rke2-v1.30-stats.csv +++ b/docs/csv/report-rke2-v1.30-stats.csv @@ -5,7 +5,7 @@ rancher/hardened-cluster-autoscaler:v1.8.11-build20241014,0,0,0 rancher/hardened-coredns:v1.11.3-build20241018,0,1,1 rancher/hardened-dns-node-cache:1.23.1-build20241008,0,5,5 rancher/hardened-etcd:v3.5.16-k3s1-build20241106,0,2,2 -rancher/hardened-flannel:v0.26.0-build20241024,0,6,6 +rancher/hardened-flannel:v0.26.0-build20241024,0,7,7 rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,0,1,1 rancher/hardened-kubernetes:v1.30.7-rke2r1-build20241126,0,6,6 rancher/klipper-helm:v0.9.3-build20241008,0,3,3 @@ -16,4 +16,4 @@ rancher/mirrored-sig-storage-snapshot-controller:v8.1.0,0,1,1 rancher/mirrored-sig-storage-snapshot-validation-webhook:v8.1.0,0,1,1 rancher/nginx-ingress-controller:v1.10.5-hardened4,0,5,5 rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016,0,1,1 -rancher/rke2-runtime:v1.30.7-rke2r1,0,4,4 +rancher/rke2-runtime:v1.30.7-rke2r1,0,3,3 diff --git a/docs/csv/report-rke2-v1.31-cves.csv b/docs/csv/report-rke2-v1.31-cves.csv index dc6f9a0..25990ad 100644 --- a/docs/csv/report-rke2-v1.31-cves.csv +++ b/docs/csv/report-rke2-v1.31-cves.csv @@ -18,6 +18,7 @@ rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.31,libgio-2_0-0,2.78.6-15 rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.31,libglib-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.31,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.31,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, +rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.31,libsoup-2_4-1,2.74.3-150600.2.2,suse linux enterprise server,SUSE-SU-2024:4290-1,HIGH,,rancher/hardened-flannel:v0.26.0-build20241024 (suse linux enterprise server 15.6),2.74.3-150600.4.3.1,false,affected, rancher/hardened-flannel:v0.26.0-build20241024,rke2/v1.31,golang.org/x/crypto,v0.28.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,opt/bin/flanneld,0.31.0,false,affected, rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,rke2/v1.31,golang.org/x/crypto,v0.18.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,metrics-server,0.31.0,false,affected, rancher/hardened-kubernetes:v1.31.3-rke2r1-build20241121,rke2/v1.31,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/kube-apiserver,0.31.0,false,affected, @@ -37,5 +38,4 @@ rancher/nginx-ingress-controller:v1.10.5-hardened4,rke2/v1.31,libglib-2_0-0,2.78 rancher/nginx-ingress-controller:v1.10.5-hardened4,rke2/v1.31,libgmodule-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/nginx-ingress-controller:v1.10.5-hardened4 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/nginx-ingress-controller:v1.10.5-hardened4,rke2/v1.31,libgobject-2_0-0,2.78.6-150600.4.3.1,suse linux enterprise server,SUSE-SU-2024:4254-1,HIGH,,rancher/nginx-ingress-controller:v1.10.5-hardened4 (suse linux enterprise server 15.6),2.78.6-150600.4.8.1,false,affected, rancher/rke2-cloud-provider:v1.31.2-0.20241016053446-0955fa330f90-build20241016,rke2/v1.31,golang.org/x/crypto,v0.27.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,usr/local/bin/rke2-cloud-provider,0.31.0,false,affected, -rancher/rke2-runtime:v1.31.3-rke2r1,rke2/v1.31,golang.org/x/crypto,v0.21.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/containerd,0.31.0,false,affected, rancher/rke2-runtime:v1.31.3-rke2r1,rke2/v1.31,golang.org/x/crypto,v0.24.0,gobinary,CVE-2024-45337,HIGH,https://avd.aquasec.com/nvd/cve-2024-45337,bin/kubelet,0.31.0,false,affected, diff --git a/docs/csv/report-rke2-v1.31-stats.csv b/docs/csv/report-rke2-v1.31-stats.csv index 081318f..7cd54d0 100644 --- a/docs/csv/report-rke2-v1.31-stats.csv +++ b/docs/csv/report-rke2-v1.31-stats.csv @@ -5,7 +5,7 @@ rancher/hardened-cluster-autoscaler:v1.8.11-build20241014,0,0,0 rancher/hardened-coredns:v1.11.3-build20241018,0,1,1 rancher/hardened-dns-node-cache:1.23.1-build20241008,0,5,5 rancher/hardened-etcd:v3.5.16-k3s1-build20241106,0,2,2 -rancher/hardened-flannel:v0.26.0-build20241024,0,6,6 +rancher/hardened-flannel:v0.26.0-build20241024,0,7,7 rancher/hardened-k8s-metrics-server:v0.7.1-build20241008,0,1,1 rancher/hardened-kubernetes:v1.31.3-rke2r1-build20241121,0,6,6 rancher/klipper-helm:v0.9.3-build20241008,0,3,3 @@ -16,4 +16,4 @@ rancher/mirrored-sig-storage-snapshot-controller:v8.1.0,0,1,1 rancher/mirrored-sig-storage-snapshot-validation-webhook:v8.1.0,0,1,1 rancher/nginx-ingress-controller:v1.10.5-hardened4,0,5,5 rancher/rke2-cloud-provider:v1.31.2-0.20241016053446-0955fa330f90-build20241016,0,1,1 -rancher/rke2-runtime:v1.31.3-rke2r1,0,2,2 +rancher/rke2-runtime:v1.31.3-rke2r1,0,1,1 diff --git a/docs/harvester-master.html b/docs/harvester-master.html index 0232ba8..d01aa43 100644 --- a/docs/harvester-master.html +++ b/docs/harvester-master.html @@ -573,16 +573,6 @@

How to use this page

gobinary -rancher/fleet-agent:v0.10.2 -false -Harvester master -usr/bin/fleetagent -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/fleet:v0.10.2 false Harvester master @@ -623,26 +613,6 @@

How to use this page

suse linux enterprise server -rancher/fleet:v0.10.2 -false -Harvester master -usr/bin/fleet -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet:v0.10.2 -false -Harvester master -usr/bin/fleetcontroller -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/gitjob:v0.9.8 false Harvester master @@ -1056,6 +1026,16 @@

How to use this page

rancher/hardened-flannel:v0.25.6-build20240910 false Harvester master +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.6-build20240910 +false +Harvester master openssl-3 openssl-3@3.1.4-150600.5.15.1 SUSE-SU-2024:3501-1 @@ -1217,16 +1197,6 @@

How to use this page

false Harvester master usr/bin/eventrouter -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-eventrouter:v0.3.2 -false -Harvester master -usr/bin/eventrouter stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -1357,16 +1327,6 @@

How to use this page

false Harvester master usr/bin/harvester-network-controller -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-network-controller:master-head -false -Harvester master -usr/bin/harvester-network-controller kubevirt.io/kubevirt@v0.54.0 CVE-2023-26484 HIGH @@ -1417,16 +1377,6 @@

How to use this page

false Harvester master usr/bin/harvester-network-helper -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-network-helper:master-head -false -Harvester master -usr/bin/harvester-network-helper kubevirt.io/kubevirt@v0.54.0 CVE-2023-26484 HIGH @@ -1477,16 +1427,6 @@

How to use this page

false Harvester master usr/bin/harvester-network-webhook -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-network-webhook:master-head -false -Harvester master -usr/bin/harvester-network-webhook kubevirt.io/kubevirt@v0.54.0 CVE-2023-26484 HIGH @@ -1623,16 +1563,6 @@

How to use this page

suse linux enterprise server -rancher/harvester-seeder:v0.4.1 -false -Harvester master -bin/manager -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/harvester-upgrade:master-head false Harvester master @@ -1673,16 +1603,6 @@

How to use this page

gobinary -rancher/harvester-upgrade:master-head -false -Harvester master -usr/local/bin/upgrade-helper -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/harvester-vm-import-controller:v0.4.1 false Harvester master @@ -1773,16 +1693,6 @@

How to use this page

gobinary -rancher/harvester-webhook:master-head -false -Harvester master -usr/bin/harvester-webhook -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/harvester:master-head false Harvester master @@ -1793,16 +1703,6 @@

How to use this page

gobinary -rancher/harvester:master-head -false -Harvester master -usr/bin/harvester -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/klipper-helm:v0.9.2-build20240828 false Harvester master @@ -7597,16 +7497,6 @@

How to use this page

false Harvester master usr/bin/containerd -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9.2 -false -Harvester master -usr/bin/containerd stdlib@v1.22.4 CVE-2024-34156 HIGH @@ -7697,16 +7587,6 @@

How to use this page

false Harvester master usr/bin/k3s -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9.2 -false -Harvester master -usr/bin/k3s stdlib@v1.22.4 CVE-2024-34156 HIGH @@ -7797,16 +7677,6 @@

How to use this page

false Harvester master usr/bin/rancher -golang.org/x/crypto@v0.27.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9.2 -false -Harvester master -usr/bin/rancher k8s.io/kubernetes@v1.30.1 CVE-2024-10220 HIGH @@ -7946,16 +7816,6 @@

How to use this page

rancher/rke2-runtime:v1.29.9-rke2r1 false Harvester master -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.29.9-rke2r1 -false -Harvester master bin/crictl github.com/docker/docker@v24.0.7+incompatible CVE-2024-41110 diff --git a/docs/harvester-v1.3-head.html b/docs/harvester-v1.3-head.html index 171842a..5752b47 100644 --- a/docs/harvester-v1.3-head.html +++ b/docs/harvester-v1.3-head.html @@ -3057,16 +3057,6 @@

How to use this page

false Harvester v1.3 head usr/bin/eventrouter -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-eventrouter:v0.3.2 -false -Harvester v1.3 head -usr/bin/eventrouter stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -4047,16 +4037,6 @@

How to use this page

false Harvester v1.3 head bin/pcidevices -golang.org/x/crypto@v0.18.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-pcidevices:v0.3.3 -false -Harvester v1.3 head -bin/pcidevices stdlib@v1.22.5 CVE-2024-34156 HIGH @@ -4087,16 +4067,6 @@

How to use this page

false Harvester v1.3 head bin/manager -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-seeder:v0.3.2 -false -Harvester v1.3 head -bin/manager stdlib@v1.21.13 CVE-2024-34156 HIGH @@ -14087,16 +14057,6 @@

How to use this page

false Harvester v1.3 head bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.28.12-rke2r1 -false -Harvester v1.3 head -bin/containerd stdlib@v1.22.3 CVE-2024-24790 CRITICAL diff --git a/docs/harvester-v1.3.2.html b/docs/harvester-v1.3.2.html index ba371bc..3e5b60b 100644 --- a/docs/harvester-v1.3.2.html +++ b/docs/harvester-v1.3.2.html @@ -3077,16 +3077,6 @@

How to use this page

false Harvester v1.3.2 usr/bin/eventrouter -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-eventrouter:v0.2.0 -false -Harvester v1.3.2 -usr/bin/eventrouter stdlib@v1.21.10 CVE-2024-24790 CRITICAL @@ -4077,16 +4067,6 @@

How to use this page

false Harvester v1.3.2 bin/pcidevices -golang.org/x/crypto@v0.18.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-pcidevices:v0.3.3 -false -Harvester v1.3.2 -bin/pcidevices stdlib@v1.22.5 CVE-2024-34156 HIGH @@ -4117,16 +4097,6 @@

How to use this page

false Harvester v1.3.2 bin/manager -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-seeder:v0.3.2 -false -Harvester v1.3.2 -bin/manager stdlib@v1.21.13 CVE-2024-34156 HIGH @@ -14397,16 +14367,6 @@

How to use this page

false Harvester v1.3.2 bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.28.12-rke2r1 -false -Harvester v1.3.2 -bin/containerd stdlib@v1.22.3 CVE-2024-24790 CRITICAL diff --git a/docs/harvester-v1.4-head.html b/docs/harvester-v1.4-head.html index 4d653d0..7ea7968 100644 --- a/docs/harvester-v1.4-head.html +++ b/docs/harvester-v1.4-head.html @@ -593,16 +593,6 @@

How to use this page

gobinary -rancher/fleet-agent:v0.10.2 -false -Harvester v1.4 head -usr/bin/fleetagent -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/fleet:v0.10.2 false Harvester v1.4 head @@ -643,26 +633,6 @@

How to use this page

suse linux enterprise server -rancher/fleet:v0.10.2 -false -Harvester v1.4 head -usr/bin/fleet -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet:v0.10.2 -false -Harvester v1.4 head -usr/bin/fleetcontroller -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/gitjob:v0.9.8 false Harvester v1.4 head @@ -1076,6 +1046,16 @@

How to use this page

rancher/hardened-flannel:v0.25.6-build20240910 false Harvester v1.4 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.6-build20240910 +false +Harvester v1.4 head openssl-3 openssl-3@3.1.4-150600.5.15.1 SUSE-SU-2024:3501-1 @@ -1237,16 +1217,6 @@

How to use this page

false Harvester v1.4 head usr/bin/eventrouter -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-eventrouter:v0.3.2 -false -Harvester v1.4 head -usr/bin/eventrouter stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -1873,16 +1843,6 @@

How to use this page

suse linux enterprise server -rancher/harvester-seeder:v0.4.1 -false -Harvester v1.4 head -bin/manager -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/harvester-upgrade:v1.4-head false Harvester v1.4 head @@ -1923,16 +1883,6 @@

How to use this page

gobinary -rancher/harvester-upgrade:v1.4-head -false -Harvester v1.4 head -usr/local/bin/upgrade-helper -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/harvester-vm-import-controller:v0.4.1 false Harvester v1.4 head @@ -2023,16 +1973,6 @@

How to use this page

gobinary -rancher/harvester-webhook:v1.4-head -false -Harvester v1.4 head -usr/bin/harvester-webhook -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/harvester:v1.4-head false Harvester v1.4 head @@ -2043,16 +1983,6 @@

How to use this page

gobinary -rancher/harvester:v1.4-head -false -Harvester v1.4 head -usr/bin/harvester -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/klipper-helm:v0.9.2-build20240828 false Harvester v1.4 head @@ -7847,16 +7777,6 @@

How to use this page

false Harvester v1.4 head usr/bin/containerd -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9.2 -false -Harvester v1.4 head -usr/bin/containerd stdlib@v1.22.4 CVE-2024-34156 HIGH @@ -7947,16 +7867,6 @@

How to use this page

false Harvester v1.4 head usr/bin/k3s -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9.2 -false -Harvester v1.4 head -usr/bin/k3s stdlib@v1.22.4 CVE-2024-34156 HIGH @@ -8047,16 +7957,6 @@

How to use this page

false Harvester v1.4 head usr/bin/rancher -golang.org/x/crypto@v0.27.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9.2 -false -Harvester v1.4 head -usr/bin/rancher k8s.io/kubernetes@v1.30.1 CVE-2024-10220 HIGH @@ -8196,16 +8096,6 @@

How to use this page

rancher/rke2-runtime:v1.29.9-rke2r1 false Harvester v1.4 head -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.29.9-rke2r1 -false -Harvester v1.4 head bin/crictl github.com/docker/docker@v24.0.7+incompatible CVE-2024-41110 diff --git a/docs/harvester-v1.4.0.html b/docs/harvester-v1.4.0.html index 6976c61..843eb75 100644 --- a/docs/harvester-v1.4.0.html +++ b/docs/harvester-v1.4.0.html @@ -593,16 +593,6 @@

How to use this page

gobinary -rancher/fleet-agent:v0.10.2 -false -Harvester v1.4.0 -usr/bin/fleetagent -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/fleet:v0.10.2 false Harvester v1.4.0 @@ -643,26 +633,6 @@

How to use this page

suse linux enterprise server -rancher/fleet:v0.10.2 -false -Harvester v1.4.0 -usr/bin/fleet -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet:v0.10.2 -false -Harvester v1.4.0 -usr/bin/fleetcontroller -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/gitjob:v0.9.8 false Harvester v1.4.0 @@ -1076,6 +1046,16 @@

How to use this page

rancher/hardened-flannel:v0.25.6-build20240910 false Harvester v1.4.0 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.6-build20240910 +false +Harvester v1.4.0 openssl-3 openssl-3@3.1.4-150600.5.15.1 SUSE-SU-2024:3501-1 @@ -1247,16 +1227,6 @@

How to use this page

false Harvester v1.4.0 usr/bin/eventrouter -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-eventrouter:v0.3.2 -false -Harvester v1.4.0 -usr/bin/eventrouter stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -1883,16 +1853,6 @@

How to use this page

suse linux enterprise server -rancher/harvester-seeder:v0.4.1 -false -Harvester v1.4.0 -bin/manager -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/harvester-upgrade:v1.4.0 false Harvester v1.4.0 @@ -1963,16 +1923,6 @@

How to use this page

gobinary -rancher/harvester-upgrade:v1.4.0 -false -Harvester v1.4.0 -usr/local/bin/upgrade-helper -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/harvester-vm-import-controller:v0.4.1 false Harvester v1.4.0 @@ -2073,16 +2023,6 @@

How to use this page

gobinary -rancher/harvester-webhook:v1.4.0 -false -Harvester v1.4.0 -usr/bin/harvester-webhook -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/harvester:v1.4.0 false Harvester v1.4.0 @@ -2103,16 +2043,6 @@

How to use this page

gobinary -rancher/harvester:v1.4.0 -false -Harvester v1.4.0 -usr/bin/harvester -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/klipper-helm:v0.9.2-build20240828 false Harvester v1.4.0 @@ -7907,16 +7837,6 @@

How to use this page

false Harvester v1.4.0 usr/bin/containerd -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9.2 -false -Harvester v1.4.0 -usr/bin/containerd stdlib@v1.22.4 CVE-2024-34156 HIGH @@ -8007,16 +7927,6 @@

How to use this page

false Harvester v1.4.0 usr/bin/k3s -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9.2 -false -Harvester v1.4.0 -usr/bin/k3s stdlib@v1.22.4 CVE-2024-34156 HIGH @@ -8107,16 +8017,6 @@

How to use this page

false Harvester v1.4.0 usr/bin/rancher -golang.org/x/crypto@v0.27.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9.2 -false -Harvester v1.4.0 -usr/bin/rancher k8s.io/kubernetes@v1.30.1 CVE-2024-10220 HIGH @@ -8256,16 +8156,6 @@

How to use this page

rancher/rke2-runtime:v1.29.9-rke2r1 false Harvester v1.4.0 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.29.9-rke2r1 -false -Harvester v1.4.0 bin/crictl github.com/docker/docker@v24.0.7+incompatible CVE-2024-41110 diff --git a/docs/rancher-v2.10-head.html b/docs/rancher-v2.10-head.html index a550561..600778e 100644 --- a/docs/rancher-v2.10-head.html +++ b/docs/rancher-v2.10-head.html @@ -2343,36 +2343,6 @@

How to use this page

gobinary -rancher/fleet-agent:v0.11.2-rc.2 -false -Rancher v2.10 head -usr/bin/fleetagent -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet:v0.11.2-rc.2 -false -Rancher v2.10 head -usr/bin/fleet -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet:v0.11.2-rc.2 -false -Rancher v2.10 head -usr/bin/fleetcontroller -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/gke-operator:v1.10.1-rc.3 false Rancher v2.10 head @@ -2856,6 +2826,16 @@

How to use this page

rancher/hardened-flannel:v0.25.6-build20240910 false Rancher v2.10 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.6-build20240910 +false +Rancher v2.10 head openssl-3 openssl-3@3.1.4-150600.5.15.1 SUSE-SU-2024:3501-1 @@ -2926,6 +2906,16 @@

How to use this page

rancher/hardened-flannel:v0.25.7-build20241008 false Rancher v2.10 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.7-build20241008 +false +Rancher v2.10 head opt/bin/flanneld golang.org/x/crypto@v0.27.0 CVE-2024-45337 @@ -2986,6 +2976,16 @@

How to use this page

rancher/hardened-flannel:v0.26.0-build20241024 false Rancher v2.10 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.26.0-build20241024 +false +Rancher v2.10 head opt/bin/flanneld golang.org/x/crypto@v0.28.0 CVE-2024-45337 @@ -3046,6 +3046,16 @@

How to use this page

rancher/hardened-flannel:v0.26.1-build20241107 false Rancher v2.10 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.26.1-build20241107 +false +Rancher v2.10 head opt/bin/flanneld golang.org/x/crypto@v0.28.0 CVE-2024-45337 @@ -3407,16 +3417,6 @@

How to use this page

false Rancher v2.10 head usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.16.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.2 -false -Rancher v2.10 head -usr/bin/harvester-cloud-provider stdlib@v1.22.5 CVE-2024-34156 HIGH @@ -4743,16 +4743,6 @@

How to use this page

gobinary -rancher/kube-api-auth:v0.2.3 -false -Rancher v2.10 head -usr/bin/kube-api-auth -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/kubectl:v1.20.2 false Rancher v2.10 head @@ -5697,16 +5687,6 @@

How to use this page

false Rancher v2.10 head usr/bin/local-path-provisioner -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/local-path-provisioner:v0.0.28 -false -Rancher v2.10 head -usr/bin/local-path-provisioner stdlib@v1.21.4 CVE-2024-24790 CRITICAL @@ -5733,26 +5713,6 @@

How to use this page

gobinary -rancher/local-path-provisioner:v0.0.30 -false -Rancher v2.10 head -usr/bin/local-path-provisioner -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/machine:v0.15.0-rancher124 -false -Rancher v2.10 head -usr/local/bin/rancher-machine -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/mirrored-brancz-kube-rbac-proxy:v0.18.0 true Rancher v2.10 head @@ -7356,6 +7316,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 true Rancher v2.10 head +glib +glib@2.68.4-1.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 +true +Rancher v2.10 head glibc glibc@2.32-15.ph4 CVE-2024-2961 @@ -7646,6 +7616,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 true Rancher v2.10 head +glib +glib@2.68.4-2.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 +true +Rancher v2.10 head krb5 krb5@1.17-10.ph4 CVE-2024-37371 @@ -7836,6 +7816,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 true Rancher v2.10 head +glib +glib@2.68.4-2.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 +true +Rancher v2.10 head krb5 krb5@1.17-11.ph4 CVE-2024-37371 @@ -19313,6 +19303,36 @@

How to use this page

gobinary +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.10 head +libpython3_12-1_0 +libpython3_12-1_0@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.10 head +python312 +python312@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.10 head +python312-base +python312-base@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 true Rancher v2.10 head @@ -21317,16 +21337,6 @@

How to use this page

false Rancher v2.10 head usr/bin/containerd -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.10-head -false -Rancher v2.10 head -usr/bin/containerd stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -21407,16 +21417,6 @@

How to use this page

false Rancher v2.10 head usr/bin/k3s -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.10-head -false -Rancher v2.10 head -usr/bin/k3s stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -21456,16 +21456,6 @@

How to use this page

rancher/rancher:v2.10-head false Rancher v2.10 head -usr/bin/rancher-machine -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.10-head -false -Rancher v2.10 head usr/bin/runc stdlib@v1.22.6 CVE-2024-34156 @@ -21736,16 +21726,6 @@

How to use this page

rancher/rke2-runtime:v1.28.15-rke2r1 false Rancher v2.10 head -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.28.15-rke2r1 -false -Rancher v2.10 head bin/crictl k8s.io/kubernetes@v1.28.0-rc.1 CVE-2024-10220 @@ -21766,16 +21746,6 @@

How to use this page

rancher/rke2-runtime:v1.29.11-rke2r1 false Rancher v2.10 head -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.29.11-rke2r1 -false -Rancher v2.10 head bin/kubelet golang.org/x/crypto@v0.21.0 CVE-2024-45337 @@ -21786,16 +21756,6 @@

How to use this page

rancher/rke2-runtime:v1.30.7-rke2r1 false Rancher v2.10 head -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.30.7-rke2r1 -false -Rancher v2.10 head bin/crictl k8s.io/kubernetes@v1.30.0 CVE-2024-10220 @@ -21826,16 +21786,6 @@

How to use this page

rancher/rke2-runtime:v1.31.3-rke2r1 false Rancher v2.10 head -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.31.3-rke2r1 -false -Rancher v2.10 head bin/kubelet golang.org/x/crypto@v0.24.0 CVE-2024-45337 @@ -21843,46 +21793,6 @@

How to use this page

gobinary -rancher/rke2-upgrade:v1.28.15-rke2r1 -false -Rancher v2.10 head -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-upgrade:v1.29.11-rke2r1 -false -Rancher v2.10 head -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-upgrade:v1.30.7-rke2r1 -false -Rancher v2.10 head -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-upgrade:v1.31.3-rke2r1 -false -Rancher v2.10 head -opt/rke2 -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/security-scan:v0.5.2 false Rancher v2.10 head diff --git a/docs/rancher-v2.10.0.html b/docs/rancher-v2.10.0.html index 86e404d..d563663 100644 --- a/docs/rancher-v2.10.0.html +++ b/docs/rancher-v2.10.0.html @@ -1963,16 +1963,6 @@

How to use this page

gobinary -rancher/fleet-agent:v0.11.1 -false -Rancher v2.10.0 -usr/bin/fleetagent -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/fleet:v0.11.1 false Rancher v2.10.0 @@ -1983,26 +1973,6 @@

How to use this page

suse linux enterprise server -rancher/fleet:v0.11.1 -false -Rancher v2.10.0 -usr/bin/fleet -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet:v0.11.1 -false -Rancher v2.10.0 -usr/bin/fleetcontroller -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/gke-operator:v1.10.0 false Rancher v2.10.0 @@ -2406,6 +2376,16 @@

How to use this page

rancher/hardened-flannel:v0.25.6-build20240910 false Rancher v2.10.0 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.6-build20240910 +false +Rancher v2.10.0 openssl-3 openssl-3@3.1.4-150600.5.15.1 SUSE-SU-2024:3501-1 @@ -2476,6 +2456,16 @@

How to use this page

rancher/hardened-flannel:v0.25.7-build20241008 false Rancher v2.10.0 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.7-build20241008 +false +Rancher v2.10.0 opt/bin/flanneld golang.org/x/crypto@v0.27.0 CVE-2024-45337 @@ -2787,16 +2777,6 @@

How to use this page

false Rancher v2.10.0 usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.16.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.2 -false -Rancher v2.10.0 -usr/bin/harvester-cloud-provider stdlib@v1.22.5 CVE-2024-34156 HIGH @@ -4103,16 +4083,6 @@

How to use this page

gobinary -rancher/kube-api-auth:v0.2.3 -false -Rancher v2.10.0 -usr/bin/kube-api-auth -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/kubectl:v1.20.2 false Rancher v2.10.0 @@ -5057,16 +5027,6 @@

How to use this page

false Rancher v2.10.0 usr/bin/local-path-provisioner -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/local-path-provisioner:v0.0.28 -false -Rancher v2.10.0 -usr/bin/local-path-provisioner stdlib@v1.21.4 CVE-2024-24790 CRITICAL @@ -5093,16 +5053,6 @@

How to use this page

gobinary -rancher/local-path-provisioner:v0.0.30 -false -Rancher v2.10.0 -usr/bin/local-path-provisioner -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/machine:v0.15.0-rancher122 false Rancher v2.10.0 @@ -5113,16 +5063,6 @@

How to use this page

suse linux enterprise server -rancher/machine:v0.15.0-rancher122 -false -Rancher v2.10.0 -usr/local/bin/rancher-machine -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/mirrored-brancz-kube-rbac-proxy:v0.18.0 true Rancher v2.10.0 @@ -6596,6 +6536,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 true Rancher v2.10.0 +glib +glib@2.68.4-1.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 +true +Rancher v2.10.0 glibc glibc@2.32-15.ph4 CVE-2024-2961 @@ -6886,6 +6836,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 true Rancher v2.10.0 +glib +glib@2.68.4-2.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 +true +Rancher v2.10.0 krb5 krb5@1.17-10.ph4 CVE-2024-37371 @@ -7076,6 +7036,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 true Rancher v2.10.0 +glib +glib@2.68.4-2.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 +true +Rancher v2.10.0 krb5 krb5@1.17-11.ph4 CVE-2024-37371 @@ -21333,6 +21303,36 @@

How to use this page

gobinary +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.10.0 +libpython3_12-1_0 +libpython3_12-1_0@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.10.0 +python312 +python312@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.10.0 +python312-base +python312-base@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 true Rancher v2.10.0 @@ -23136,16 +23136,6 @@

How to use this page

rancher/rancher-agent:v2.10.0 false Rancher v2.10.0 -usr/bin/agent -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher-agent:v2.10.0 -false -Rancher v2.10.0 usr/bin/kubectl stdlib@v1.20.13 CVE-2024-24790 @@ -23327,16 +23317,6 @@

How to use this page

false Rancher v2.10.0 usr/bin/containerd -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.10.0 -false -Rancher v2.10.0 -usr/bin/containerd stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -23417,16 +23397,6 @@

How to use this page

false Rancher v2.10.0 usr/bin/k3s -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.10.0 -false -Rancher v2.10.0 -usr/bin/k3s stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -23456,26 +23426,6 @@

How to use this page

rancher/rancher:v2.10.0 false Rancher v2.10.0 -usr/bin/rancher -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.10.0 -false -Rancher v2.10.0 -usr/bin/rancher-machine -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.10.0 -false -Rancher v2.10.0 usr/bin/runc stdlib@v1.22.6 CVE-2024-34156 @@ -23746,16 +23696,6 @@

How to use this page

rancher/rke2-runtime:v1.28.15-rke2r1 false Rancher v2.10.0 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.28.15-rke2r1 -false -Rancher v2.10.0 bin/crictl k8s.io/kubernetes@v1.28.0-rc.1 CVE-2024-10220 @@ -23776,16 +23716,6 @@

How to use this page

rancher/rke2-runtime:v1.29.10-rke2r1 false Rancher v2.10.0 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.29.10-rke2r1 -false -Rancher v2.10.0 bin/kubelet golang.org/x/crypto@v0.21.0 CVE-2024-45337 @@ -23796,16 +23726,6 @@

How to use this page

rancher/rke2-runtime:v1.30.6-rke2r1 false Rancher v2.10.0 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.30.6-rke2r1 -false -Rancher v2.10.0 bin/crictl k8s.io/kubernetes@v1.30.0 CVE-2024-10220 @@ -23836,16 +23756,6 @@

How to use this page

rancher/rke2-runtime:v1.31.2-rke2r1 false Rancher v2.10.0 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.31.2-rke2r1 -false -Rancher v2.10.0 bin/kubelet golang.org/x/crypto@v0.24.0 CVE-2024-45337 @@ -23853,46 +23763,6 @@

How to use this page

gobinary -rancher/rke2-upgrade:v1.28.15-rke2r1 -false -Rancher v2.10.0 -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-upgrade:v1.29.10-rke2r1 -false -Rancher v2.10.0 -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-upgrade:v1.30.6-rke2r1 -false -Rancher v2.10.0 -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-upgrade:v1.31.2-rke2r1 -false -Rancher v2.10.0 -opt/rke2 -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/security-scan:v0.5.1 false Rancher v2.10.0 diff --git a/docs/rancher-v2.8-head.html b/docs/rancher-v2.8-head.html index b85110b..235614f 100644 --- a/docs/rancher-v2.8-head.html +++ b/docs/rancher-v2.8-head.html @@ -2063,36 +2063,6 @@

How to use this page

gobinary -rancher/fleet-agent:v0.9.12 -false -Rancher v2.8 head -usr/bin/fleet -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet-agent:v0.9.12 -false -Rancher v2.8 head -usr/bin/fleetagent -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet:v0.9.12 -false -Rancher v2.8 head -usr/bin/fleetcontroller -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/gitjob:v0.9.18 false Rancher v2.8 head @@ -4346,6 +4316,16 @@

How to use this page

rancher/hardened-flannel:v0.25.5-build20240801 false Rancher v2.8 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.5-build20240801 +false +Rancher v2.8 head openssl-3 openssl-3@3.1.4-150600.5.10.1 SUSE-SU-2024:3106-1 @@ -4456,6 +4436,16 @@

How to use this page

rancher/hardened-flannel:v0.25.6-build20240910 false Rancher v2.8 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.6-build20240910 +false +Rancher v2.8 head openssl-3 openssl-3@3.1.4-150600.5.15.1 SUSE-SU-2024:3501-1 @@ -4526,6 +4516,16 @@

How to use this page

rancher/hardened-flannel:v0.25.7-build20241008 false Rancher v2.8 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.7-build20241008 +false +Rancher v2.8 head opt/bin/flanneld golang.org/x/crypto@v0.27.0 CVE-2024-45337 @@ -7357,16 +7357,6 @@

How to use this page

false Rancher v2.8 head usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.1.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.0 -false -Rancher v2.8 head -usr/bin/harvester-cloud-provider golang.org/x/net@v0.7.0 CVE-2023-39325 HIGH @@ -7537,16 +7527,6 @@

How to use this page

false Rancher v2.8 head usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.16.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.1 -false -Rancher v2.8 head -usr/bin/harvester-cloud-provider stdlib@v1.20.13 CVE-2024-24790 CRITICAL @@ -7617,16 +7597,6 @@

How to use this page

false Rancher v2.8 head usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.16.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.2 -false -Rancher v2.8 head -usr/bin/harvester-cloud-provider stdlib@v1.22.5 CVE-2024-34156 HIGH @@ -11337,16 +11307,6 @@

How to use this page

false Rancher v2.8 head usr/bin/kube-api-auth -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/kube-api-auth:v0.2.1 -false -Rancher v2.8 head -usr/bin/kube-api-auth k8s.io/kubernetes@v1.27.10 CVE-2024-10220 HIGH @@ -13077,16 +13037,6 @@

How to use this page

false Rancher v2.8 head usr/bin/local-path-provisioner -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/local-path-provisioner:v0.0.28 -false -Rancher v2.8 head -usr/bin/local-path-provisioner stdlib@v1.21.4 CVE-2024-24790 CRITICAL @@ -13113,16 +13063,6 @@

How to use this page

gobinary -rancher/local-path-provisioner:v0.0.30 -false -Rancher v2.8 head -usr/bin/local-path-provisioner -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/longhornio-csi-attacher:v3.2.1 false Rancher v2.8 head @@ -15437,16 +15377,6 @@

How to use this page

false Rancher v2.8 head usr/local/bin/rancher-machine -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/machine:v0.15.0-rancher118 -false -Rancher v2.8 head -usr/local/bin/rancher-machine stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -15996,19 +15926,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-0464 -HIGH -amazon - - -rancher/mirrored-amazon-aws-cli:2.9.14 -true -Rancher v2.8 head -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-0465 +python +python@2.7.18-1.amzn2.0.5 +CVE-2022-45061 HIGH amazon @@ -16016,9 +15936,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-0466 +python +python@2.7.18-1.amzn2.0.5 +CVE-2022-48565 HIGH amazon @@ -16026,9 +15946,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-2650 +python-libs +python-libs@2.7.18-1.amzn2.0.5 +CVE-2022-45061 HIGH amazon @@ -16036,9 +15956,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-3446 +python-libs +python-libs@2.7.18-1.amzn2.0.5 +CVE-2022-48565 HIGH amazon @@ -16046,9 +15966,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-3817 +sqlite +sqlite@3.7.17-8.amzn2.1.1 +CVE-2022-35737 HIGH amazon @@ -16056,9 +15976,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-5678 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2021-3236 HIGH amazon @@ -16066,9 +15986,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2024-0727 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-2522 HIGH amazon @@ -16076,9 +15996,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -python -python@2.7.18-1.amzn2.0.5 -CVE-2022-45061 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-2571 HIGH amazon @@ -16086,9 +16006,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -python -python@2.7.18-1.amzn2.0.5 -CVE-2022-48565 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-2580 HIGH amazon @@ -16096,9 +16016,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -python-libs -python-libs@2.7.18-1.amzn2.0.5 -CVE-2022-45061 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-2581 HIGH amazon @@ -16106,9 +16026,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -python-libs -python-libs@2.7.18-1.amzn2.0.5 -CVE-2022-48565 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-2874 HIGH amazon @@ -16116,9 +16036,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8 head -sqlite -sqlite@3.7.17-8.amzn2.1.1 -CVE-2022-35737 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-3134 HIGH amazon @@ -16128,7 +16048,7 @@

How to use this page

Rancher v2.8 head vim-data vim-data@2:9.0.828-1.amzn2.0.1 -CVE-2021-3236 +CVE-2022-3153 HIGH amazon @@ -16228,6 +16148,26 @@

How to use this page

Rancher v2.8 head vim-data vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-4141 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-4292 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 CVE-2022-47024 HIGH amazon @@ -16238,6 +16178,16 @@

How to use this page

Rancher v2.8 head vim-data vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2023-0049 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 CVE-2023-0051 HIGH amazon @@ -16398,6 +16348,76 @@

How to use this page

Rancher v2.8 head vim-minimal vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-2522 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-2571 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-2580 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-2581 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-2874 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-3134 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-3153 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 CVE-2022-3234 HIGH amazon @@ -16488,6 +16508,26 @@

How to use this page

Rancher v2.8 head vim-minimal vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-4141 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-4292 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 CVE-2022-47024 HIGH amazon @@ -16498,6 +16538,16 @@

How to use this page

Rancher v2.8 head vim-minimal vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2023-0049 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8 head +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 CVE-2023-0051 HIGH amazon @@ -22826,6 +22876,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 true Rancher v2.8 head +glib +glib@2.68.4-2.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 +true +Rancher v2.8 head krb5 krb5@1.17-10.ph4 CVE-2024-37371 @@ -41543,6 +41603,36 @@

How to use this page

gobinary +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.8 head +libpython3_12-1_0 +libpython3_12-1_0@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.8 head +python312 +python312@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.8 head +python312-base +python312-base@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 true Rancher v2.8 head @@ -60986,16 +61076,6 @@

How to use this page

rancher/rke2-runtime:v1.28.15-rke2r1 false Rancher v2.8 head -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.28.15-rke2r1 -false -Rancher v2.8 head bin/crictl k8s.io/kubernetes@v1.28.0-rc.1 CVE-2024-10220 @@ -61043,16 +61123,6 @@

How to use this page

gobinary -rancher/rke2-upgrade:v1.28.15-rke2r1 -false -Rancher v2.8 head -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/security-scan:v0.3.1 false Rancher v2.8 head diff --git a/docs/rancher-v2.8.10.html b/docs/rancher-v2.8.10.html index 246a8f1..ef5870f 100644 --- a/docs/rancher-v2.8.10.html +++ b/docs/rancher-v2.8.10.html @@ -2076,26 +2076,6 @@

How to use this page

rancher/fleet-agent:v0.9.11 false Rancher v2.8.10 -usr/bin/fleet -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet-agent:v0.9.11 -false -Rancher v2.8.10 -usr/bin/fleetagent -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet-agent:v0.9.11 -false -Rancher v2.8.10 usr/bin/fleetagent k8s.io/kubernetes@v1.28.8 CVE-2024-10220 @@ -2123,16 +2103,6 @@

How to use this page

suse linux enterprise server -rancher/fleet:v0.9.11 -false -Rancher v2.8.10 -usr/bin/fleetcontroller -golang.org/x/crypto@v0.24.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/gitjob:v0.9.17 false Rancher v2.8.10 @@ -4396,6 +4366,16 @@

How to use this page

rancher/hardened-flannel:v0.25.5-build20240801 false Rancher v2.8.10 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.5-build20240801 +false +Rancher v2.8.10 openssl-3 openssl-3@3.1.4-150600.5.10.1 SUSE-SU-2024:3106-1 @@ -4506,6 +4486,16 @@

How to use this page

rancher/hardened-flannel:v0.25.6-build20240910 false Rancher v2.8.10 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.6-build20240910 +false +Rancher v2.8.10 openssl-3 openssl-3@3.1.4-150600.5.15.1 SUSE-SU-2024:3501-1 @@ -4576,6 +4566,16 @@

How to use this page

rancher/hardened-flannel:v0.25.7-build20241008 false Rancher v2.8.10 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.7-build20241008 +false +Rancher v2.8.10 opt/bin/flanneld golang.org/x/crypto@v0.27.0 CVE-2024-45337 @@ -7407,16 +7407,6 @@

How to use this page

false Rancher v2.8.10 usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.1.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.0 -false -Rancher v2.8.10 -usr/bin/harvester-cloud-provider golang.org/x/net@v0.7.0 CVE-2023-39325 HIGH @@ -7587,16 +7577,6 @@

How to use this page

false Rancher v2.8.10 usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.16.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.1 -false -Rancher v2.8.10 -usr/bin/harvester-cloud-provider stdlib@v1.20.13 CVE-2024-24790 CRITICAL @@ -7667,16 +7647,6 @@

How to use this page

false Rancher v2.8.10 usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.16.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.2 -false -Rancher v2.8.10 -usr/bin/harvester-cloud-provider stdlib@v1.22.5 CVE-2024-34156 HIGH @@ -11377,16 +11347,6 @@

How to use this page

false Rancher v2.8.10 usr/bin/kube-api-auth -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/kube-api-auth:v0.2.1 -false -Rancher v2.8.10 -usr/bin/kube-api-auth k8s.io/kubernetes@v1.27.10 CVE-2024-10220 HIGH @@ -13127,16 +13087,6 @@

How to use this page

false Rancher v2.8.10 usr/bin/local-path-provisioner -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/local-path-provisioner:v0.0.28 -false -Rancher v2.8.10 -usr/bin/local-path-provisioner stdlib@v1.21.4 CVE-2024-24790 CRITICAL @@ -13163,16 +13113,6 @@

How to use this page

gobinary -rancher/local-path-provisioner:v0.0.30 -false -Rancher v2.8.10 -usr/bin/local-path-provisioner -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/longhornio-csi-attacher:v3.2.1 false Rancher v2.8.10 @@ -15487,16 +15427,6 @@

How to use this page

false Rancher v2.8.10 usr/local/bin/rancher-machine -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/machine:v0.15.0-rancher118 -false -Rancher v2.8.10 -usr/local/bin/rancher-machine stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -16046,19 +15976,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-0464 -HIGH -amazon - - -rancher/mirrored-amazon-aws-cli:2.9.14 -true -Rancher v2.8.10 -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-0465 +python +python@2.7.18-1.amzn2.0.5 +CVE-2022-45061 HIGH amazon @@ -16066,9 +15986,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-0466 +python +python@2.7.18-1.amzn2.0.5 +CVE-2022-48565 HIGH amazon @@ -16076,9 +15996,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-2650 +python-libs +python-libs@2.7.18-1.amzn2.0.5 +CVE-2022-45061 HIGH amazon @@ -16086,9 +16006,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-3446 +python-libs +python-libs@2.7.18-1.amzn2.0.5 +CVE-2022-48565 HIGH amazon @@ -16096,9 +16016,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-3817 +sqlite +sqlite@3.7.17-8.amzn2.1.1 +CVE-2022-35737 HIGH amazon @@ -16106,9 +16026,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2023-5678 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2021-3236 HIGH amazon @@ -16116,9 +16036,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -openssl-libs -openssl-libs@1:1.0.2k-24.amzn2.0.4 -CVE-2024-0727 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-2522 HIGH amazon @@ -16126,9 +16046,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -python -python@2.7.18-1.amzn2.0.5 -CVE-2022-45061 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-2571 HIGH amazon @@ -16136,9 +16056,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -python -python@2.7.18-1.amzn2.0.5 -CVE-2022-48565 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-2580 HIGH amazon @@ -16146,9 +16066,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -python-libs -python-libs@2.7.18-1.amzn2.0.5 -CVE-2022-45061 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-2581 HIGH amazon @@ -16156,9 +16076,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -python-libs -python-libs@2.7.18-1.amzn2.0.5 -CVE-2022-48565 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-2874 HIGH amazon @@ -16166,9 +16086,9 @@

How to use this page

rancher/mirrored-amazon-aws-cli:2.9.14 true Rancher v2.8.10 -sqlite -sqlite@3.7.17-8.amzn2.1.1 -CVE-2022-35737 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-3134 HIGH amazon @@ -16178,7 +16098,7 @@

How to use this page

Rancher v2.8.10 vim-data vim-data@2:9.0.828-1.amzn2.0.1 -CVE-2021-3236 +CVE-2022-3153 HIGH amazon @@ -16278,6 +16198,26 @@

How to use this page

Rancher v2.8.10 vim-data vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-4141 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2022-4292 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 CVE-2022-47024 HIGH amazon @@ -16288,6 +16228,16 @@

How to use this page

Rancher v2.8.10 vim-data vim-data@2:9.0.828-1.amzn2.0.1 +CVE-2023-0049 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-data +vim-data@2:9.0.828-1.amzn2.0.1 CVE-2023-0051 HIGH amazon @@ -16448,6 +16398,76 @@

How to use this page

Rancher v2.8.10 vim-minimal vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-2522 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-2571 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-2580 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-2581 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-2874 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-3134 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-3153 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 CVE-2022-3234 HIGH amazon @@ -16538,6 +16558,26 @@

How to use this page

Rancher v2.8.10 vim-minimal vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-4141 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2022-4292 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 CVE-2022-47024 HIGH amazon @@ -16548,6 +16588,16 @@

How to use this page

Rancher v2.8.10 vim-minimal vim-minimal@2:9.0.828-1.amzn2.0.1 +CVE-2023-0049 +HIGH +amazon + + +rancher/mirrored-amazon-aws-cli:2.9.14 +true +Rancher v2.8.10 +vim-minimal +vim-minimal@2:9.0.828-1.amzn2.0.1 CVE-2023-0051 HIGH amazon @@ -22876,6 +22926,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 true Rancher v2.8.10 +glib +glib@2.68.4-2.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 +true +Rancher v2.8.10 krb5 krb5@1.17-10.ph4 CVE-2024-37371 @@ -41593,6 +41653,36 @@

How to use this page

gobinary +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.8.10 +libpython3_12-1_0 +libpython3_12-1_0@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.8.10 +python312 +python312@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.8.10 +python312-base +python312-base@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 true Rancher v2.8.10 @@ -59446,16 +59536,6 @@

How to use this page

rancher/rke2-runtime:v1.28.15-rke2r1 false Rancher v2.8.10 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.28.15-rke2r1 -false -Rancher v2.8.10 bin/crictl k8s.io/kubernetes@v1.28.0-rc.1 CVE-2024-10220 @@ -59503,16 +59583,6 @@

How to use this page

gobinary -rancher/rke2-upgrade:v1.28.15-rke2r1 -false -Rancher v2.8.10 -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/security-scan:v0.3.0 false Rancher v2.8.10 diff --git a/docs/rancher-v2.9-head.html b/docs/rancher-v2.9-head.html index 5551ae2..a4cbe7f 100644 --- a/docs/rancher-v2.9-head.html +++ b/docs/rancher-v2.9-head.html @@ -2843,36 +2843,6 @@

How to use this page

gobinary -rancher/fleet-agent:v0.10.7 -false -Rancher v2.9 head -usr/bin/fleetagent -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet:v0.10.7 -false -Rancher v2.9 head -usr/bin/fleet -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet:v0.10.7 -false -Rancher v2.9 head -usr/bin/fleetcontroller -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/gke-operator:v1.9.5-rc.1 false Rancher v2.9 head @@ -5186,6 +5156,16 @@

How to use this page

rancher/hardened-flannel:v0.25.5-build20240801 false Rancher v2.9 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.5-build20240801 +false +Rancher v2.9 head openssl-3 openssl-3@3.1.4-150600.5.10.1 SUSE-SU-2024:3106-1 @@ -5296,6 +5276,16 @@

How to use this page

rancher/hardened-flannel:v0.25.6-build20240910 false Rancher v2.9 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.6-build20240910 +false +Rancher v2.9 head openssl-3 openssl-3@3.1.4-150600.5.15.1 SUSE-SU-2024:3501-1 @@ -5366,6 +5356,16 @@

How to use this page

rancher/hardened-flannel:v0.25.7-build20241008 false Rancher v2.9 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.7-build20241008 +false +Rancher v2.9 head opt/bin/flanneld golang.org/x/crypto@v0.27.0 CVE-2024-45337 @@ -5426,6 +5426,16 @@

How to use this page

rancher/hardened-flannel:v0.26.0-build20241024 false Rancher v2.9 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.26.0-build20241024 +false +Rancher v2.9 head opt/bin/flanneld golang.org/x/crypto@v0.28.0 CVE-2024-45337 @@ -5486,6 +5496,16 @@

How to use this page

rancher/hardened-flannel:v0.26.1-build20241107 false Rancher v2.9 head +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.26.1-build20241107 +false +Rancher v2.9 head opt/bin/flanneld golang.org/x/crypto@v0.28.0 CVE-2024-45337 @@ -8787,16 +8807,6 @@

How to use this page

false Rancher v2.9 head usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.1.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.0 -false -Rancher v2.9 head -usr/bin/harvester-cloud-provider golang.org/x/net@v0.7.0 CVE-2023-39325 HIGH @@ -8967,16 +8977,6 @@

How to use this page

false Rancher v2.9 head usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.16.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.1 -false -Rancher v2.9 head -usr/bin/harvester-cloud-provider stdlib@v1.20.13 CVE-2024-24790 CRITICAL @@ -9047,16 +9047,6 @@

How to use this page

false Rancher v2.9 head usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.16.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.2 -false -Rancher v2.9 head -usr/bin/harvester-cloud-provider stdlib@v1.22.5 CVE-2024-34156 HIGH @@ -12997,16 +12987,6 @@

How to use this page

false Rancher v2.9 head usr/bin/kube-api-auth -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/kube-api-auth:v0.2.2 -false -Rancher v2.9 head -usr/bin/kube-api-auth stdlib@v1.22.5 CVE-2024-34156 HIGH @@ -14347,16 +14327,6 @@

How to use this page

false Rancher v2.9 head usr/bin/local-path-provisioner -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/local-path-provisioner:v0.0.28 -false -Rancher v2.9 head -usr/bin/local-path-provisioner stdlib@v1.21.4 CVE-2024-24790 CRITICAL @@ -14383,16 +14353,6 @@

How to use this page

gobinary -rancher/local-path-provisioner:v0.0.30 -false -Rancher v2.9 head -usr/bin/local-path-provisioner -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/longhornio-csi-attacher:v3.2.1 false Rancher v2.9 head @@ -16663,16 +16623,6 @@

How to use this page

gobinary -rancher/machine:v0.15.0-rancher124 -false -Rancher v2.9 head -usr/local/bin/rancher-machine -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/mirrored-calico-apiserver:v3.26.3 true Rancher v2.9 head @@ -22746,6 +22696,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 true Rancher v2.9 head +glib +glib@2.68.4-1.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 +true +Rancher v2.9 head glibc glibc@2.32-15.ph4 CVE-2024-2961 @@ -23036,6 +22996,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 true Rancher v2.9 head +glib +glib@2.68.4-2.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 +true +Rancher v2.9 head krb5 krb5@1.17-10.ph4 CVE-2024-37371 @@ -23226,6 +23196,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 true Rancher v2.9 head +glib +glib@2.68.4-2.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.1 +true +Rancher v2.9 head krb5 krb5@1.17-11.ph4 CVE-2024-37371 @@ -39023,6 +39003,36 @@

How to use this page

gobinary +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.9 head +libpython3_12-1_0 +libpython3_12-1_0@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.9 head +python312 +python312@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.9 head +python312-base +python312-base@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 true Rancher v2.9 head @@ -42397,16 +42407,6 @@

How to use this page

false Rancher v2.9 head usr/bin/agent -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher-agent:v2.9-head -false -Rancher v2.9 head -usr/bin/agent k8s.io/kubernetes@v1.30.1 CVE-2024-10220 HIGH @@ -42677,16 +42677,6 @@

How to use this page

false Rancher v2.9 head usr/bin/containerd -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9-head -false -Rancher v2.9 head -usr/bin/containerd stdlib@v1.22.4 CVE-2024-34156 HIGH @@ -42777,16 +42767,6 @@

How to use this page

false Rancher v2.9 head usr/bin/k3s -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9-head -false -Rancher v2.9 head -usr/bin/k3s stdlib@v1.22.4 CVE-2024-34156 HIGH @@ -42837,16 +42817,6 @@

How to use this page

false Rancher v2.9 head usr/bin/rancher -golang.org/x/crypto@v0.28.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9-head -false -Rancher v2.9 head -usr/bin/rancher k8s.io/kubernetes@v1.30.1 CVE-2024-10220 HIGH @@ -42867,16 +42837,6 @@

How to use this page

false Rancher v2.9 head usr/bin/rancher-machine -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rancher:v2.9-head -false -Rancher v2.9 head -usr/bin/rancher-machine stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -43536,16 +43496,6 @@

How to use this page

rancher/rke2-runtime:v1.28.15-rke2r1 false Rancher v2.9 head -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.28.15-rke2r1 -false -Rancher v2.9 head bin/crictl k8s.io/kubernetes@v1.28.0-rc.1 CVE-2024-10220 @@ -43566,16 +43516,6 @@

How to use this page

rancher/rke2-runtime:v1.29.11-rke2r1 false Rancher v2.9 head -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.29.11-rke2r1 -false -Rancher v2.9 head bin/kubelet golang.org/x/crypto@v0.21.0 CVE-2024-45337 @@ -43586,16 +43526,6 @@

How to use this page

rancher/rke2-runtime:v1.30.7-rke2r1 false Rancher v2.9 head -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.30.7-rke2r1 -false -Rancher v2.9 head bin/crictl k8s.io/kubernetes@v1.30.0 CVE-2024-10220 @@ -43653,36 +43583,6 @@

How to use this page

gobinary -rancher/rke2-upgrade:v1.28.15-rke2r1 -false -Rancher v2.9 head -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-upgrade:v1.29.11-rke2r1 -false -Rancher v2.9 head -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-upgrade:v1.30.7-rke2r1 -false -Rancher v2.9 head -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/security-scan:v0.4.1 false Rancher v2.9 head diff --git a/docs/rancher-v2.9.4.html b/docs/rancher-v2.9.4.html index d8ee020..dbc8ab4 100644 --- a/docs/rancher-v2.9.4.html +++ b/docs/rancher-v2.9.4.html @@ -2843,16 +2843,6 @@

How to use this page

gobinary -rancher/fleet-agent:v0.10.6 -false -Rancher v2.9.4 -usr/bin/fleetagent -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/fleet:v0.10.6 false Rancher v2.9.4 @@ -2863,26 +2853,6 @@

How to use this page

suse linux enterprise server -rancher/fleet:v0.10.6 -false -Rancher v2.9.4 -usr/bin/fleet -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/fleet:v0.10.6 -false -Rancher v2.9.4 -usr/bin/fleetcontroller -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/gke-operator:v1.9.4 false Rancher v2.9.4 @@ -5116,6 +5086,16 @@

How to use this page

rancher/hardened-flannel:v0.25.5-build20240801 false Rancher v2.9.4 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.5-build20240801 +false +Rancher v2.9.4 openssl-3 openssl-3@3.1.4-150600.5.10.1 SUSE-SU-2024:3106-1 @@ -5226,6 +5206,16 @@

How to use this page

rancher/hardened-flannel:v0.25.6-build20240910 false Rancher v2.9.4 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.6-build20240910 +false +Rancher v2.9.4 openssl-3 openssl-3@3.1.4-150600.5.15.1 SUSE-SU-2024:3501-1 @@ -5296,6 +5286,16 @@

How to use this page

rancher/hardened-flannel:v0.25.7-build20241008 false Rancher v2.9.4 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.7-build20241008 +false +Rancher v2.9.4 opt/bin/flanneld golang.org/x/crypto@v0.27.0 CVE-2024-45337 @@ -8547,16 +8547,6 @@

How to use this page

false Rancher v2.9.4 usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.1.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.0 -false -Rancher v2.9.4 -usr/bin/harvester-cloud-provider golang.org/x/net@v0.7.0 CVE-2023-39325 HIGH @@ -8727,16 +8717,6 @@

How to use this page

false Rancher v2.9.4 usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.16.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.1 -false -Rancher v2.9.4 -usr/bin/harvester-cloud-provider stdlib@v1.20.13 CVE-2024-24790 CRITICAL @@ -8807,16 +8787,6 @@

How to use this page

false Rancher v2.9.4 usr/bin/harvester-cloud-provider -golang.org/x/crypto@v0.16.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/harvester-cloud-provider:v0.2.2 -false -Rancher v2.9.4 -usr/bin/harvester-cloud-provider stdlib@v1.22.5 CVE-2024-34156 HIGH @@ -12757,16 +12727,6 @@

How to use this page

false Rancher v2.9.4 usr/bin/kube-api-auth -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/kube-api-auth:v0.2.2 -false -Rancher v2.9.4 -usr/bin/kube-api-auth stdlib@v1.22.5 CVE-2024-34156 HIGH @@ -13727,16 +13687,6 @@

How to use this page

false Rancher v2.9.4 usr/bin/local-path-provisioner -golang.org/x/crypto@v0.14.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/local-path-provisioner:v0.0.28 -false -Rancher v2.9.4 -usr/bin/local-path-provisioner stdlib@v1.21.4 CVE-2024-24790 CRITICAL @@ -13763,16 +13713,6 @@

How to use this page

gobinary -rancher/local-path-provisioner:v0.0.30 -false -Rancher v2.9.4 -usr/bin/local-path-provisioner -golang.org/x/crypto@v0.25.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/longhornio-csi-attacher:v3.2.1 false Rancher v2.9.4 @@ -16087,16 +16027,6 @@

How to use this page

false Rancher v2.9.4 usr/local/bin/rancher-machine -golang.org/x/crypto@v0.26.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/machine:v0.15.0-rancher118 -false -Rancher v2.9.4 -usr/local/bin/rancher-machine stdlib@v1.22.6 CVE-2024-34156 HIGH @@ -22016,6 +21946,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 true Rancher v2.9.4 +glib +glib@2.68.4-1.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.2.0 +true +Rancher v2.9.4 glibc glibc@2.32-15.ph4 CVE-2024-2961 @@ -22306,6 +22246,16 @@

How to use this page

rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 true Rancher v2.9.4 +glib +glib@2.68.4-2.ph4 +CVE-2024-52533 +CRITICAL +photon + + +rancher/mirrored-cloud-provider-vsphere-csi-release-driver:v3.3.0 +true +Rancher v2.9.4 krb5 krb5@1.17-10.ph4 CVE-2024-37371 @@ -38003,6 +37953,36 @@

How to use this page

gobinary +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.9.4 +libpython3_12-1_0 +libpython3_12-1_0@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.9.4 +python312 +python312@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + +rancher/mirrored-neuvector-manager:5.4.1 +true +Rancher v2.9.4 +python312-base +python312-base@3.12.7-150600.3.9.1 +SUSE-SU-2024:4291-1 +HIGH +suse linux enterprise server + + rancher/mirrored-neuvector-prometheus-exporter:1-1.0.0 true Rancher v2.9.4 @@ -41436,16 +41416,6 @@

How to use this page

rancher/rke2-runtime:v1.28.15-rke2r1 false Rancher v2.9.4 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.28.15-rke2r1 -false -Rancher v2.9.4 bin/crictl k8s.io/kubernetes@v1.28.0-rc.1 CVE-2024-10220 @@ -41466,16 +41436,6 @@

How to use this page

rancher/rke2-runtime:v1.29.10-rke2r1 false Rancher v2.9.4 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.29.10-rke2r1 -false -Rancher v2.9.4 bin/kubelet golang.org/x/crypto@v0.21.0 CVE-2024-45337 @@ -41486,16 +41446,6 @@

How to use this page

rancher/rke2-runtime:v1.30.6-rke2r1 false Rancher v2.9.4 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.30.6-rke2r1 -false -Rancher v2.9.4 bin/crictl k8s.io/kubernetes@v1.30.0 CVE-2024-10220 @@ -41553,36 +41503,6 @@

How to use this page

gobinary -rancher/rke2-upgrade:v1.28.15-rke2r1 -false -Rancher v2.9.4 -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-upgrade:v1.29.10-rke2r1 -false -Rancher v2.9.4 -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-upgrade:v1.30.6-rke2r1 -false -Rancher v2.9.4 -opt/rke2 -golang.org/x/crypto@v0.17.0 -CVE-2024-45337 -HIGH -gobinary - - rancher/security-scan:v0.4.0 false Rancher v2.9.4 diff --git a/docs/rke2-v1.28.html b/docs/rke2-v1.28.html index 5a88e01..8c22fe0 100644 --- a/docs/rke2-v1.28.html +++ b/docs/rke2-v1.28.html @@ -246,6 +246,16 @@

How to use this page

rancher/hardened-flannel:v0.25.7-build20241008 false RKE2 v1.28 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.25.7-build20241008 +false +RKE2 v1.28 opt/bin/flanneld golang.org/x/crypto@v0.27.0 CVE-2024-45337 @@ -456,16 +466,6 @@

How to use this page

rancher/rke2-runtime:v1.28.15-rke2r1 false RKE2 v1.28 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.28.15-rke2r1 -false -RKE2 v1.28 bin/crictl k8s.io/kubernetes@v1.28.0-rc.1 CVE-2024-10220 diff --git a/docs/rke2-v1.29.html b/docs/rke2-v1.29.html index dea749c..a292dda 100644 --- a/docs/rke2-v1.29.html +++ b/docs/rke2-v1.29.html @@ -246,6 +246,16 @@

How to use this page

rancher/hardened-flannel:v0.26.0-build20241024 false RKE2 v1.29 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.26.0-build20241024 +false +RKE2 v1.29 opt/bin/flanneld golang.org/x/crypto@v0.28.0 CVE-2024-45337 @@ -436,16 +446,6 @@

How to use this page

rancher/rke2-runtime:v1.29.11-rke2r1 false RKE2 v1.29 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.29.11-rke2r1 -false -RKE2 v1.29 bin/kubelet golang.org/x/crypto@v0.21.0 CVE-2024-45337 diff --git a/docs/rke2-v1.30.html b/docs/rke2-v1.30.html index ac5716d..5d332b7 100644 --- a/docs/rke2-v1.30.html +++ b/docs/rke2-v1.30.html @@ -246,6 +246,16 @@

How to use this page

rancher/hardened-flannel:v0.26.0-build20241024 false RKE2 v1.30 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.26.0-build20241024 +false +RKE2 v1.30 opt/bin/flanneld golang.org/x/crypto@v0.28.0 CVE-2024-45337 @@ -436,16 +446,6 @@

How to use this page

rancher/rke2-runtime:v1.30.7-rke2r1 false RKE2 v1.30 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.30.7-rke2r1 -false -RKE2 v1.30 bin/crictl k8s.io/kubernetes@v1.30.0 CVE-2024-10220 diff --git a/docs/rke2-v1.31.html b/docs/rke2-v1.31.html index 48c7622..2873f08 100644 --- a/docs/rke2-v1.31.html +++ b/docs/rke2-v1.31.html @@ -246,6 +246,16 @@

How to use this page

rancher/hardened-flannel:v0.26.0-build20241024 false RKE2 v1.31 +libsoup-2_4-1 +libsoup-2_4-1@2.74.3-150600.2.2 +SUSE-SU-2024:4290-1 +HIGH +suse linux enterprise server + + +rancher/hardened-flannel:v0.26.0-build20241024 +false +RKE2 v1.31 opt/bin/flanneld golang.org/x/crypto@v0.28.0 CVE-2024-45337 @@ -436,16 +446,6 @@

How to use this page

rancher/rke2-runtime:v1.31.3-rke2r1 false RKE2 v1.31 -bin/containerd -golang.org/x/crypto@v0.21.0 -CVE-2024-45337 -HIGH -gobinary - - -rancher/rke2-runtime:v1.31.3-rke2r1 -false -RKE2 v1.31 bin/kubelet golang.org/x/crypto@v0.24.0 CVE-2024-45337