Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Critical CVE CVE-2024-45337 flagged by aqua scan #474

Closed
kvijai82 opened this issue Jan 23, 2025 · 2 comments
Closed

Critical CVE CVE-2024-45337 flagged by aqua scan #474

kvijai82 opened this issue Jan 23, 2025 · 2 comments

Comments

@kvijai82
Copy link

The following critical CVE is being flagged by Aqua scans:

cve sev epss package type version fixedIn arch path
CVE-2024-45337 critical (aqua) 0.045% golang.org/x/crypto go (aqua) 0.25.0 (aqua) 0.31.0 (aqua) amd64 /usr/bin/local-path-provisioner (aqua)

cve sev epss package type version fixedIn arch path
CVE-2024-45337 critical (aqua) 0.045% golang.org/x/crypto go (aqua) 0.25.0 (aqua) 0.31.0 (aqua) amd64 /usr/bin/local-path-provisioner (aqua)

Could this be reviewed to determine if it's an issue? Is this package used in this image? In the go.mod file I don't see this package being used. Thanks!

@derekbit
Copy link
Member

Sure. Thanks for raising the CVE.

@derekbit
Copy link
Member

Fixed in #472.
Will release soon.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants