karmada icon indicating copy to clipboard operation
karmada copied to clipboard

[CVE-2024-2511] openssl: Unbounded memory growth with session handling in TLSv1.3

Open RainbowMango opened this issue 1 year ago • 4 comments

What would you like to be added: Bump base image alpine(here, and here) on all supported branches.

  • [x] master (https://github.com/karmada-io/karmada/pull/4973)
  • [ ] release-1.9 (https://github.com/karmada-io/karmada/pull/4971)
  • [x] release-1.8 (https://github.com/karmada-io/karmada/pull/4975)
  • [x] release-1.7 (https://github.com/karmada-io/karmada/pull/4972)

Why is this needed: There is a vulnerability alert reported by code scanning, that is the CVE-2024-2511, no evidence shows Karmada is affected by this issue, but we can bump the base image to silence this alert.

RainbowMango avatar May 07 '24 02:05 RainbowMango

Base image alpine has released a new version v3.20.0, and it resolves all the vulnerabilities of the previous version v3.19.1.

karmada/karmada-webhook:v1.10.0-preview4-145-gef14a9824-dirty (alpine 3.20.0)

Total: 0 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

We can wait for #4932 to be merged in and then auto bump the base image. @RainbowMango @liangyuanpeng

zhzhuang-zju avatar May 23 '24 02:05 zhzhuang-zju

I think this should wait until all PRs are merged. /reopen

liangyuanpeng avatar May 23 '24 07:05 liangyuanpeng

@liangyuanpeng: Reopened this issue.

In response to this:

I think this should wait until all PRs are merged. /reopen

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

karmada-bot avatar May 23 '24 07:05 karmada-bot

/assign @liangyuanpeng

RainbowMango avatar May 24 '24 01:05 RainbowMango

/close Great thanks to @liangyuanpeng for the excellent work!

RainbowMango avatar May 27 '24 08:05 RainbowMango

@RainbowMango: Closing this issue.

In response to this:

/close Great thanks to @liangyuanpeng for the excellent work!

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

karmada-bot avatar May 27 '24 08:05 karmada-bot