-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Keda 2.13.1 Sysdig scan Vulnerabilities CVE-2024-27304 CVE-2024-24786 CVE-2024-28110 CVE-2024-28180 #5660
Comments
Hello @amardeep2006 , |
Thanks @JorTurFer . I did a rescan of main tag and CVE-2024-28180 in github.com/go-jose/go-jose/v3 - v3.0.1 is fixed. Here are the Vulnerabilities that still needs to be looked into : GHSA-mrww-27vc-gghv in github.com/jackc/pgx/v5 - v5.5.2 |
keda-metrics-apiserver also needs some dependency bump . GHSA-mrww-27vc-gghv in github.com/jackc/pgx/v5 - v5.5.2 |
Thanks for reporting, let's mitigate these in 2.14 |
I am closing this issue as KEDA 2.14.0 has passed the scan. I highly appreciate the remediation. Thanks a lot for the awesome project. |
Thank you for checking it and reporting the feedback too! ❤️ |
Report
I scanned keda v 2.13.1 and see following in report.
CVE-2024-27304 in github.com/jackc/pgx/v5 - v5.5.2
CVE-2024-24786 in google.golang.org/protobuf - v1.32.0
CVE-2024-28110 in github.com/cloudevents/sdk-go/v2 - v2.14.0
CVE-2024-28180 in github.com/go-jose/go-jose/v3 - v3.0.1
Expected Behavior
There should be no vulnerability if affected packages are bumped up.
Actual Behavior
Sysdig scan fails.
Steps to Reproduce the Problem
Standard scan
Logs from KEDA operator
KEDA Version
2.13.1
Kubernetes Version
None
Platform
None
Scaler Details
No response
Anything else?
No response
The text was updated successfully, but these errors were encountered: