-
Notifications
You must be signed in to change notification settings - Fork 138
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerabilities on V1.9 #855
Comments
what is this CVE? the latest version of smb csi driver is v1.16.0 |
We are currently using the following Helm version for the CSI Driver SMB. However, we have received several critical vulnerability alerts for this version. Can you please guide us to resolve the vulnerabilities? resource "helm_release" "csi_smb" { |
We have upgrade the csi-driver-smb to v1.16.0 but still there is a critical vulnerabilities. Can you help us to resolve the issue ? <style> </style>
|
does
|
i have upgraded the plugin version to 1.16 but one critical version is there. need your support to resolve the vulnerabilities on v1.16. |
@tamilselvan1588 what CVE are you hitting now? |
Here, the vulnerabilitie details. <style> </style>
|
it's related to kubernetes/k8s.io#6908 (comment), the golang version of this image build is still using 1.22.3, that's a common upstream image build issue, if you want to get it fixed quickly, you could build the image by yourself using fixed golang version. |
Sure, thanks. i will try |
@tamilselvan1588 this is fixed by #857, which uses go 1.22.5 to build image, pls try gcr.io/k8s-staging-sig-storage/smbplugin:canary again, thx |
@andyzhangx is there a timeline to release v1.17 which includes fixes for above reported CVE's? |
@kropiwnickij it should be in next month |
we have identified some critical vulnerabilities in v1.9. Can you provide the solution to resolve the vulnerabilities
<style> </style>The text was updated successfully, but these errors were encountered: