Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cluster AutoScaler v1.25.3 showing 6 Critical Vulnerabilities #6501

Closed
Rajashekhar29 opened this issue Feb 2, 2024 · 3 comments
Closed

cluster AutoScaler v1.25.3 showing 6 Critical Vulnerabilities #6501

Rajashekhar29 opened this issue Feb 2, 2024 · 3 comments
Labels
area/cluster-autoscaler area/core-autoscaler Denotes an issue that is related to the core autoscaler and is not specific to any provider. kind/bug Categorizes issue or PR as related to a bug.

Comments

@Rajashekhar29
Copy link

Which component are you using?:
cluster autoscaler

cluster-autoscaler

What version of the component are you using?:
1.25.3

cluster-autoscaler-1.25.3
Component version:

What k8s version are you using (kubectl version)?:

kubectl version Output
$ kubectl version

What environment is this in?:
Dev

What did you expect to happen?:
Image scan to show clean without any critical Vulenerabilities

What happened instead?:
Scan report has critical vulnerabilities

How to reproduce it (as minimally and precisely as possible):

Anything else we need to know?:

List of CVE ID's that are marked as critical.
CVE-2023-24538
CVE-2023-24540
CVE-2023-29405
CVE-2023-29404
CVE-2023-29402
CVE-2023-39323

@Rajashekhar29 Rajashekhar29 added the kind/bug Categorizes issue or PR as related to a bug. label Feb 2, 2024
@towca towca added area/cluster-autoscaler area/core-autoscaler Denotes an issue that is related to the core autoscaler and is not specific to any provider. labels Mar 21, 2024
@Shubham82
Copy link
Contributor

@Rajashekhar29 These CVEs are resolved in the latest release, Here is the issue opened for CVE #5343
see this comment which has the output of vulnerability scanning (using trivy) on the CA 1.30.0 image.

@Shubham82
Copy link
Contributor

closing this issue, as all CVE is fixed.
/close

@k8s-ci-robot
Copy link
Contributor

@Shubham82: Closing this issue.

In response to this:

closing this issue, as all CVE is fixed.
/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/cluster-autoscaler area/core-autoscaler Denotes an issue that is related to the core autoscaler and is not specific to any provider. kind/bug Categorizes issue or PR as related to a bug.
Projects
None yet
Development

No branches or pull requests

4 participants