kubereboot / kured

Kubernetes Reboot Daemon
https://kured.dev
Apache License 2.0
2.14k stars 201 forks source link

Security vulnerabilities #956

Closed aldanr closed 1 month ago

aldanr commented 1 month ago

Hi everyone

Are there any plans to address these CVE's? our scanner detected a few vulnerabilities that have been addressed in the latest Alpine Linux version for OpenSSL and busybox

[CVE-2024-4603,http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4603] [CVE-2023-42366,http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42366] [CVE-2023-42363,http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42363] [CVE-2023-42364,http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42364] [CVE-2023-42365,http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42365]

Best regards

jackfrancis commented 1 month ago

Thanks @aldanr

The latest alpine release is in main branch, so we just need to cut a new release. Stand by.

cc @ckotzbauer

aldanr commented 1 month ago

Thanks @jackfrancis, do you have an ETA by any chance? My team is really looking forward for the next version

ckotzbauer commented 1 month ago

I can cut a release in the next few days.