Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-22189 HIGH vulnerability wiz-kubernetes-integration@v0.1.100 helm chart #343

Open
BurakCetin3129 opened this issue Jun 3, 2024 · 5 comments

Comments

@BurakCetin3129
Copy link

When I install wiz-kubernetes-integration@v0.1.100 helm chart, wiz-kubernetes-connector has CVE-2024-22189 HIGH vulnerability finding.

Can you please fix it?

@ofirc-wiz
Copy link
Collaborator

Hi @BurakCetin3129, thanks for the post, Ofir from the Kubernetes team in Wiz.
How did you scan it?
Is it possible that you are using old images / old Helm Charts?
Please share a reproducer and we will look into that.

Thanks.

@BurakCetin3129
Copy link
Author

Hi @ofirc-wiz

It's a Wiz finding :)
I installed wiz-kubernetes-integration helm chart version: 0.1.100 and then Wiz image vulnerability scan found CVE-2024-22189 HIGH vulnerability on wiz-kubernetes-connector

@BurakCetin3129
Copy link
Author

I think wiz-kubernetes-integration helm chart version: 0.1.100 is the latest one. I'm using this unified helm chart to install all kubernetes deployments.

@BurakCetin3129
Copy link
Author

BurakCetin3129 commented Jun 6, 2024

I installed wiz-kubernetes-integration helm chart version: 0.1.106 but it still has the vulnerability. Is there any plan to mitigate it @ofirc-wiz ?

@bluPhy
Copy link
Contributor

bluPhy commented Jun 7, 2024

@BurakCetin3129 CVE-2024-22189 is coming from registry.k8s.io/coredns/coredns:v1.11.1 which at this time is the latest release version, this is fixed in coredns:v1.11.3 as per CVE-2024-22189 - Memory Exhaustion Attack using library github.com/quic-go/quic-go #6597 , but as is not fully released then we don't have an image yet (2024-June-08). More info here

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants