wolfi-dev / os

Main package repository for production Wolfi images
Other
713 stars 171 forks source link

kubernetes-dns-node-cache/1.23.0-r6: cve remediation #19721

Closed octo-sts[bot] closed 1 week ago

octo-sts[bot] commented 2 weeks ago

kubernetes-dns-node-cache/1.23.0-r6: fix GHSA-m9w6-wp3h-vq8g

Advisory data: https://github.com/wolfi-dev/advisories/blob/main/kubernetes-dns-node-cache.advisories.yaml

github-actions[bot] commented 2 weeks ago
Package kubernetes-dns-node-cache: Click to expand/collapse Package kubernetes-dns-node-cache: `.PKGINFO` metadata: ``` ( """ - # Generated by melange v0.16.7-22-gfe8b68a + # Generated by melange v0.7.0-12-g436f915 pkgname = kubernetes-dns-node-cache - pkgver = 1.23.0-r6 + pkgver = 1.23.0-r7 arch = x86_64 - size = 35286265 + size = 37020376 origin = kubernetes-dns-node-cache pkgdesc = NodeLocal DNSCache improves Cluster DNS performance by running a DNS caching agent on cluster nodes as a DaemonSet. url = - commit = 195e878a09b405990e60a29403b57848e9f3104c - builddate = 1715344811 + commit = 5b1a9a9560d85683ba4a03b1c7f65e4bdec22de5 license = Apache-2.0 - provides = cmd:node-cache=1.23.0-r6 - datahash = 860756096795d4714ed7e4c4630f383912061d3cd602e5a6f793e3009586920f + provides = cmd:node-cache=1.23.0-r7 + datahash = 2d2210dd6c29137937bab6ec66f46d7ca5bab867aa6eade3cc6f76f756938fa7 """ ) ``` Modified: /usr/bin/node-cache
bincapz found differences: Click to expand/collapse ## Changed: kubernetes-dns-node-cache/usr/bin/node-cache ### 4 new behaviors | RISK | KEY | DESCRIPTION | EVIDENCE | |---------|-----------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------| | +MEDIUM | **[databases/leveldb](https://github.com/chainguard-dev/bincapz/blob/main/rules/databases/leveldb.yara#leveldb)** | accesses LevelDB databases | [goleveldbruntime](https://github.com/search?q=goleveldbruntime&type=code)
[v4LevelDBNegroniv1](https://github.com/search?q=v4LevelDBNegroniv1&type=code) | | +MEDIUM | **[net/http/server](https://github.com/chainguard-dev/bincapz/blob/main/rules/net/http-server.yara#http_server)** | serves HTTP requests | [gin-gonic/](https://github.com/search?q=gin-gonic%2F&type=code) | | +LOW | **[cloud/google/metadata](https://github.com/chainguard-dev/bincapz/blob/main/rules/cloud/google-metadata.yara#google_metadata)** | Includes the token required to use the Google Cloud Platform metadata server | [Metadata-Flavor](https://github.com/search?q=Metadata-Flavor&type=code) | | +LOW | **[net/ip](https://github.com/chainguard-dev/bincapz/blob/main/rules/net/ip.yara#packets)** | access the internet | [invalid packet](https://github.com/search?q=invalid+packet&type=code) | ### 2 removed behaviors | RISK | KEY | DESCRIPTION | EVIDENCE | |---------|----------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | -MEDIUM | [3P/threat_hunting/gobfuscate](https://github.com/chainguard-dev/bincapz/blob/main/rules/yara/threat_hunting/all.yara#gobfuscate_offensive_tool_keyword) | [references 'gobfuscate' tool](https://github.com/mthcht/ThreatHunting-Keywords), by @mthcht | [gObfuscate](https://github.com/search?q=gObfuscate&type=code) | | -MEDIUM | [ref/site/http/dynamic](https://github.com/chainguard-dev/bincapz/blob/main/rules/ref/site/http-dynamic.yara#http_dynamic) | URL that is dynamically generated | [http://%s/infotrace](http://%s/infotrace)
[http://%s/v0.4/tracesreason](http://%s/v0.4/tracesreason)
[http://%s/v0.6/statsx509usefallbackrootsresourceVersionMatchAllowWatchBoo](http://%s/v0.6/statsx509usefallbackrootsresourceVersionMatchAllowWatchBoo) |