-
Notifications
You must be signed in to change notification settings - Fork 544
CVE-2023-28155 reported against kubernetes-client (because of sub package request) #1024
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Comments
@mstruebing I think 0.18.1 is already released. At least according to npm, it was published two months ago and has over 100k downloads in the past week. 😊 Still: Thank you for tagging this as a duplicate. 👍 |
Oh you are right, but there is not github tag :/ |
hrmph, my script is supposed to git tag things :( I'll look into fixing that. Closing this as a duplicate. |
I added the tag manually, in fixing the release script, I disabled tagging (I can't remember why I did that :) but I'll see about re-enabling it. |
Describe the bug
Our scanning tools are reporting CVE-2023-28155 against the request package included by kubernetes-client.
https://exchange.xforce.ibmcloud.com/vulnerabilities/250386
https://nvd.nist.gov/vuln/detail/CVE-2023-28155
** Client Version **
0.18.1
** Server Version **
N/A
To Reproduce
install kubernetes-client
Expected behavior
Remediation of security vulnerability.
** Example Code**
N/A
Environment (please complete the following information):
Additional context
The text was updated successfully, but these errors were encountered: