Skip to content

CVE-2023-28155 reported against kubernetes-client (because of sub package request) #1024

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Closed
sgrube opened this issue Mar 24, 2023 · 5 comments

Comments

@sgrube
Copy link

sgrube commented Mar 24, 2023

Describe the bug
Our scanning tools are reporting CVE-2023-28155 against the request package included by kubernetes-client.

https://exchange.xforce.ibmcloud.com/vulnerabilities/250386
https://nvd.nist.gov/vuln/detail/CVE-2023-28155

** Client Version **
0.18.1

** Server Version **
N/A

To Reproduce
install kubernetes-client

Expected behavior
Remediation of security vulnerability.

** Example Code**
N/A

Environment (please complete the following information):

  • OS: Linux
  • NodeJS Version 18

Additional context

@mstruebing
Copy link
Member

mstruebing commented Mar 24, 2023

Duplicate of #1020, #414 and #754

There is no published 0.18.1 version out there, so you probably mean 0.18.0.

@felix-gohla
Copy link

felix-gohla commented Mar 24, 2023

@mstruebing I think 0.18.1 is already released. At least according to npm, it was published two months ago and has over 100k downloads in the past week. 😊

Still: Thank you for tagging this as a duplicate. 👍

@mstruebing
Copy link
Member

Oh you are right, but there is not github tag :/

@brendandburns
Copy link
Contributor

hrmph, my script is supposed to git tag things :( I'll look into fixing that.

Closing this as a duplicate.

@brendandburns
Copy link
Contributor

I added the tag manually, in fixing the release script, I disabled tagging (I can't remember why I did that :) but I'll see about re-enabling it.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants