Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-45338 in addon-resizer #7658

Open
kumar-mallikarjuna opened this issue Jan 6, 2025 · 0 comments
Open

CVE-2024-45338 in addon-resizer #7658

kumar-mallikarjuna opened this issue Jan 6, 2025 · 0 comments
Labels
area/addon-resizer kind/bug Categorizes issue or PR as related to a bug.

Comments

@kumar-mallikarjuna
Copy link

Which component are you using?:
/area addon-resizer

What version of the component are you using?:
1.8.22

Component version:

What k8s version are you using (kubectl version)?:

Client Version: v1.29.2
Kustomize Version: v5.0.4-0.20230601165947-6ce0bf390ce3
Server Version: v1.30.7-eks-56e63d8
kubectl version Output
$ kubectl version

What environment is this in?:
prod

aws

What did you expect to happen?:
Not have CVEs.

What happened instead?:
Trivy scan shows:

┌──────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────┐
│     Library      │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                       Title                       │
├──────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────┤
│ golang.org/x/net │ CVE-2024-45338 │ HIGH     │ fixed  │ v0.23.0           │ 0.33.0        │ golang.org/x/net/html: Non-linear parsing of      │
│                  │                │          │        │                   │               │ case-insensitive content in golang.org/x/net/html │
│                  │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2024-45338        │
└──────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────┘

How to reproduce it (as minimally and precisely as possible):
Run a trivy scan on 1.8.22 build for addon-resizer.

Anything else we need to know?:

@kumar-mallikarjuna kumar-mallikarjuna added the kind/bug Categorizes issue or PR as related to a bug. label Jan 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/addon-resizer kind/bug Categorizes issue or PR as related to a bug.
Projects
None yet
Development

No branches or pull requests

2 participants