-
Notifications
You must be signed in to change notification settings - Fork 79
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerabilities found in K8ssandra images #1444
Comments
➤ Amanda Skuldt commented: John Messavussu I added the vulnerability issue type to this project and converted this to a vulnerability. Normally this would be an epic and each CVE would be its own ticket, but however this will be fixed quickest is fine given the customer involvement. |
➤ Amanda Skuldt commented: Some of these are critical and need to be sorted ASAP: https://nvd.nist.gov/vuln/detail/cve-2024-47561 ( https://nvd.nist.gov/vuln/detail/cve-2024-47561|smart-link ) |
➤ John Messavussu commented: cc: Alexander Dejanovski to prioritize and assign. |
➤ Michael Burman commented: We do not build new 3.11 images anymore (3.11 support is deprecated). The medusa image is old (4 months ago) and has been superseded by 3 different patch releases since then and version 0.22.3 is in the current k8ssandra-operator release. Are these some old scans? |
Closing this as out of date. |
The following security vulnerabilities in K8ssandra images were found during routine scans
|----|----|----|
|Vulnerability|Image|Tag|
|PRISMA
20230067|docker.io/k8ssandra/cass-management-api|3.11.17||GHSA
xpw8rcwv-8f8p|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202447561|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202436114|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202430172|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202430171|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202426308|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202425710|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202339410|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202334462|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202333202|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202333201|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202329403|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202242004|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202242003|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202241881|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202241854|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202238752|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202238751|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202238750|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202238749|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202225857|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
20221471|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202147621|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202146877|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202129425|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202120293|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202120289|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202036518|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
20201729|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
20201695|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
202013956|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
201916869|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
20190205|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
20181320|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
201811798|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
201810237|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
20165397|docker.io/k8ssandra/cass-management-api|3.11.17||CVE
20153254|docker.io/k8ssandra/cass-management-api|3.11.17||----|----|
|Vulnerability|Image|
|CVE
202230630|docker.io/k8ssandra/cass-management-api:3.11.17||CVE
202230632|docker.io/k8ssandra/cass-management-api:3.11.17||----|----|
|Vulnerability|Image|
|PRISMA
20230067|docker.io/k8ssandra/cass-management-api:3.11.13||CVE
202324329|docker.io/k8ssandra/cass-management-api:3.11.13||CVE
202340217|docker.io/k8ssandra/cass-management-api:3.11.13||CVE
20223857|docker.io/k8ssandra/cass-management-api:3.11.13||CVE
202425710|docker.io/k8ssandra/cass-management-api:3.11.13||CVE
202426308|docker.io/k8ssandra/cass-management-api:3.11.13||CVE
202430171|docker.io/k8ssandra/cass-management-api:3.11.13||CVE
202430172|docker.io/k8ssandra/cass-management-api:3.11.13||CVE
202227943|docker.io/k8ssandra/medusa:0.22.0|┆Issue is synchronized with this Jira Bug by Unito
┆Issue Number: K8OP-286
The text was updated successfully, but these errors were encountered: