k3s-io / klipper-lb

Embedded service load balancer in Klipper
Apache License 2.0
354 stars 41 forks source link

Busybox CVE-2022-48174 #59

Closed tr4de0ff closed 5 months ago

tr4de0ff commented 1 year ago

Hi,

The current 0.4.4 version is flagging with a Critical vulnerability CVE-2022-48174 due to busybox: https://security.snyk.io/vuln/SNYK-ALPINE318-BUSYBOX-5890990. This is preventing us using k3s.

The vulnerability looks to be resolved in the latest Alpine maintenance: https://www.alpinelinux.org/posts/Alpine-3.18.4-released.html