karmada-io / karmada

Open, Multi-Cloud, Multi-Cluster Kubernetes Orchestration
https://karmada.io
Apache License 2.0
4.14k stars 813 forks source link

[CVE-2024-2511] openssl: Unbounded memory growth with session handling in TLSv1.3 #4908

Open RainbowMango opened 1 week ago

RainbowMango commented 1 week ago

What would you like to be added: Bump base image alpine(here, and here) on all supported branches.

Why is this needed: There is a vulnerability alert reported by code scanning, that is the CVE-2024-2511, no evidence shows Karmada is affected by this issue, but we can bump the base image to silence this alert.