Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

v2.10.0 showing HIGH vulnerability CVE-2023-44487 #2231

Closed
mitchellmaler opened this issue Oct 27, 2023 · 3 comments
Closed

v2.10.0 showing HIGH vulnerability CVE-2023-44487 #2231

mitchellmaler opened this issue Oct 27, 2023 · 3 comments
Assignees
Labels
kind/bug Categorizes issue or PR as related to a bug. triage/accepted Indicates an issue or PR is ready to be actively worked on.

Comments

@mitchellmaler
Copy link

kube-state-metrics/kube-state-metrics:v2.10.0 is showing HIGH vulnerability CVE-2023-44487. This will require upgrading to a later Golang patch version to pull in the latest net package to resolve.
Screenshot 2023-10-27 at 10 42 04 AM

@mitchellmaler mitchellmaler added the kind/bug Categorizes issue or PR as related to a bug. label Oct 27, 2023
@k8s-ci-robot k8s-ci-robot added the needs-triage Indicates an issue or PR lacks a `triage/foo` label and requires one. label Oct 27, 2023
@dashpole
Copy link
Contributor

dashpole commented Nov 2, 2023

/assign @dgrisonnet
/triage accepted

@k8s-ci-robot k8s-ci-robot added triage/accepted Indicates an issue or PR is ready to be actively worked on. and removed needs-triage Indicates an issue or PR lacks a `triage/foo` label and requires one. labels Nov 2, 2023
@dgrisonnet
Copy link
Member

It was addressed in #2214 and will be released as part of v2.10.1.

/cc @rexagod

@rexagod
Copy link
Member

rexagod commented Nov 9, 2023

Released in v2.10.1.

@rexagod rexagod closed this as completed Nov 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Categorizes issue or PR as related to a bug. triage/accepted Indicates an issue or PR is ready to be actively worked on.
Projects
None yet
Development

No branches or pull requests

5 participants