Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix Critical CVE Vulnerabilities #1424

Closed
yash-acquia opened this issue Aug 2, 2024 · 4 comments
Closed

Fix Critical CVE Vulnerabilities #1424

yash-acquia opened this issue Aug 2, 2024 · 4 comments
Labels
kind/bug Categorizes issue or PR as related to a bug.

Comments

@yash-acquia
Copy link

/kind bug

What happened?
An Orca scan detected the following CVEs:
CVE-2024-24790
CVE-2024-24791

What you expected to happen?
Please address the identified CVEs.

Vulnerability_id Package Name Vulnerable Version Fixed Version Type Severity
CVE-2024-24790 stdlib 1.20.14 1.21.11, 1.22.4 gobinary CRITICAL
CVE-2024-24791 stdlib 1.20.14 1.21.12, 1.22.5 gobinary HIGH

Environment
Driver version: public.ecr.aws/efs-csi-driver/amazon/aws-efs-csi-driver:v2.0.6
Kubernetes version (use kubectl version): v1.28.11-eks

@k8s-ci-robot k8s-ci-robot added the kind/bug Categorizes issue or PR as related to a bug. label Aug 2, 2024
@mskanth972
Copy link
Contributor

This PR should fix these CVEs.

@yash-acquia
Copy link
Author

yash-acquia commented Aug 6, 2024

Hi @mskanth972, Thank you for addressing the CVE. When will the new release with the latest changes be available? Can you prioritize this as it is a critical CVE and it is impacting our work?

@yash-acquia
Copy link
Author

Hi @mskanth972, When will the new helm chart version for AWS EFS CSI Driver be available?

@mskanth972
Copy link
Contributor

Hi @yash-acquia, I am starting release today. It will be available in GitHub(helm and manifest) by tomorrow morning. ECD for the Addons will be Aug 20th.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Categorizes issue or PR as related to a bug.
Projects
None yet
Development

No branches or pull requests

3 participants