Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-5535, CVE-2019-12900 in the base image for calico node #9861

Open
Blintmester opened this issue Feb 18, 2025 · 0 comments
Open

CVE-2024-5535, CVE-2019-12900 in the base image for calico node #9861

Blintmester opened this issue Feb 18, 2025 · 0 comments

Comments

@Blintmester
Copy link

Our resource scan found these two CVEs in the calico-node v3.28.2 image: CVE-2024-5535, CVE-2019-12900.
I see, that the UBI_VERSION for v3.29.2 is still 8.10, so the problematic packages are still on the impacted versions.
https://github.com/projectcalico/calico/blob/v3.29.2/metadata.mk

Do you plan to update it?

https://access.redhat.com/errata/RHSA-2024:7848
https://access.redhat.com/errata/RHSA-2024:8922

The impacted packages: bzip2, openssl.

CVE-2019-12900: Upgrade bzip2-libs to >= 0:1.0.6-27.el8_10
CVE-2024-5535: Upgrade openssl-libs to >= 1:1.1.1k-14.el8_6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant