-
Notifications
You must be signed in to change notification settings - Fork 8.4k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Vulnerable to CVE-2023-4039
#13136
Comments
This issue is currently awaiting triage. If Ingress contributors determines this is a relevant issue, they will accept it by applying the The Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Can you please share additional information on this? I looked up which GCC version provided by Alpine includes fixes for this (https://security.alpinelinux.org/vuln/CVE-2023-4039) and according to the latest build log we are using a fixed version (14.2.0-r4):
|
What CVE was reported in the scanner findings?
CVE-2023-4039
What versions of the controller did you test with?
registry.k8s.io/ingress-nginx/controller:v1.12.1
registry.k8s.io/ingress-nginx/controller:v1.11.5
The text was updated successfully, but these errors were encountered: