CRITICAl vulnerability storage-initializer:0.7.0
See original GitHub issue/kind bug
Hi team
Our tool shows following crtical vulnerability for storage-initializer:0.7.0. I checked release notes for 0.8.0 but couldn’t find any refence of any fix. Are there any plans to fix the vulnerability?
CVE-2021-44228
https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2021-44228
</body> </html>What steps did you take and what happened: [A clear and concise description of what the bug is.]
What did you expect to happen:
Anything else you would like to add: [Miscellaneous information that will assist in solving the issue.]
Environment:
- Istio Version:
- Knative Version:
- KFServing Version:
- Kubeflow version:
- Kfdef:[k8s_istio/istio_dex/gcp_basic_auth/gcp_iap/aws/aws_cognito/ibm]
- Minikube version:
- Kubernetes version: (use
kubectl version
): - OS (e.g. from
/etc/os-release
):
Issue Analytics
- State:
- Created a year ago
- Comments:13 (6 by maintainers)
Top Results From Across the Web
CVE-2022-42475: Critical Unauthenticated Remote Code ...
FortiGuard Labs has confirmed at least one instance of the vulnerability being exploited in the wild and included the current indicators of ...
Read more >Known Exploited Vulnerabilities Catalog | CISA
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require ...
Read more >Vulnerability Metrics - NVD
The Common Vulnerability Scoring System (CVSS) is a method used to supply a qualitative measure of severity. CVSS is not a measure of...
Read more >Incoming OpenSSL critical fix: Organizations, users, get ready!
The OpenSSL Project team has announced the release of OpenSSL version 3.0.7, which will fix a critical vulnerability, so prepare asap.
Read more >Qualys Research Alert: OpenSSL 3.0.7 - What You Need To ...
These vulnerabilities only apply to OpenSSL 3.x. Both these vulnerabilities are rated as HIGH and downgraded from CRITICAL as initially rated in ...
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
@andyi2it @yuzisun Thanks for making the changes. Could you please confirm which KServe release this fix goes into and when?
This there anything that @psheorangithub or I can do to assist with this getting included in the next KServe release? We are keen to get this closed out.