crossplane-contrib / provider-kubernetes

Crossplane provider to provision and manage Kubernetes objects on (remote) Kubernetes clusters.
Apache License 2.0
141 stars 82 forks source link

CVE-2024-24786 - GHSA-8r3f-844c-mc37 #220

Closed AbrohamLincoln closed 4 months ago

AbrohamLincoln commented 6 months ago

A CVE with a moderate severity was published. https://github.com/advisories/GHSA-8r3f-844c-mc37

The protobuf dependency needs to be updated to v1.33.0 or newer to fix this CVE.

https://github.com/crossplane-contrib/provider-kubernetes/blob/main/go.mod#L93

turkenh commented 4 months ago

Closing as resolved since we are using v1.33.0 on latest main now: https://github.com/crossplane-contrib/provider-kubernetes/blob/6c1bc19e6f465596cb3a0e270d82756a8087bd62/go.mod#L92