kubernetes-sigs / azuredisk-csi-driver

Azure Disk CSI Driver
Apache License 2.0
147 stars 193 forks source link

[release-1.28] fix: CVE-2024-5321 #2420

Closed andyzhangx closed 4 months ago

andyzhangx commented 4 months ago

What type of PR is this? /kind bug

What this PR does / why we need it: fix: CVE-2024-5321

cherrypick of https://github.com/kubernetes-sigs/azuredisk-csi-driver/pull/2417

blobplugin (gobinary)
=====================
Total: 1 (UNKNOWN: 0, MEDIUM: 1, HIGH: 0, CRITICAL: 0)

┌───────────────────┬───────────────┬──────────┬────────┬───────────────────┬──────────────────────────────────┬─────────────────────────────────────────────────────────────┐
│      Library      │ Vulnerability │ Severity │ Status │ Installed Version │          Fixed Version           │                            Title                            │
├───────────────────┼───────────────┼──────────┼────────┼───────────────────┼──────────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ k8s.io/kubernetes │ CVE-2024-5321 │ MEDIUM   │ fixed  │ v1.29.4           │ 1.27.16, 1.28.12, 1.29.7, 1.30.3 │ Kubernetes sets incorrect permissions on Windows containers │
│                   │               │          │        │                   │                                  │ logs                                                        │
│                   │               │          │        │                   │                                  │ https://avd.aquasec.com/nvd/cve-2024-[53](https://github.com/kubernetes-sigs/blob-csi-driver/actions/runs/10003004852/job/27649227567?pr=1496#step:6:54)21                   │
└───────────────────┴───────────────┴──────────┴────────┴───────────────────┴──────────────────────────────────┴─────────────────────────────────────────────────────────────┘

Which issue(s) this PR fixes:

Fixes #

Requirements:

Special notes for your reviewer:

Release note:

fix: CVE-2024-5321
k8s-ci-robot commented 4 months ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: andyzhangx

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/kubernetes-sigs/azuredisk-csi-driver/blob/release-1.28/OWNERS)~~ [andyzhangx] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
andyzhangx commented 4 months ago

/retest

andyzhangx commented 4 months ago

/retest

andyzhangx commented 4 months ago

/retest