-
Notifications
You must be signed in to change notification settings - Fork 39
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2024-22189 HIGH vulnerability wiz-kubernetes-integration@v0.1.100 helm chart #343
Comments
Hi @BurakCetin3129, thanks for the post, Ofir from the Kubernetes team in Wiz. Thanks. |
Hi @ofirc-wiz It's a Wiz finding :) |
I think |
I installed |
@BurakCetin3129 CVE-2024-22189 is coming from registry.k8s.io/coredns/coredns:v1.11.1 which at this time is the latest release version, this is fixed in coredns:v1.11.3 as per CVE-2024-22189 - Memory Exhaustion Attack using library github.com/quic-go/quic-go #6597 , but as is not fully released then we don't have an image yet (2024-June-08). More info here |
When I install
wiz-kubernetes-integration@v0.1.100
helm chart,wiz-kubernetes-connector
hasCVE-2024-22189
HIGH vulnerability finding.Can you please fix it?
The text was updated successfully, but these errors were encountered: