Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

v1.31.1 showing HIGH vulnerability CVE-2023-44487 #2953

Open
mitchellmaler opened this issue Oct 27, 2023 · 1 comment
Open

v1.31.1 showing HIGH vulnerability CVE-2023-44487 #2953

mitchellmaler opened this issue Oct 27, 2023 · 1 comment

Comments

@mitchellmaler
Copy link

v1.31.1 is using the net package that has the vulnerability CVE-2023-44487. This requires upgrading Golang and the net package to resolve the CVE.
Screenshot 2023-10-27 at 10 30 17 AM

@tmjd
Copy link
Member

tmjd commented Oct 27, 2023

Thank you for reporting this. You've reported this as HIGH but the CVE is Moderate. It looks like the tool you're using reports the vulnerability as HIGH so I guess that's why you've reported it this way.

Since the operator's primary function does not act as a server I don't think this issue very critical to the operator. We should still look at getting this updated though.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants