/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-53w9-6g64-qrwc

Published

Last updated

https://images.chainguard.dev/security/CGA-53w9-6g64-qrwc
Package

kubernetes-1.28

Repository

Chainguard

Latest Update
Not affected
Aliases
  • CVE-2024-28180
  • GHSA-c5q2-7r4c-mv6g

Severity

4.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-28180

Updates

Status

Not affected

Justification

Vulnerable code not in execute path

Impact

See https://github.com/kubernetes/kubernetes/pull/123253#issuecomment-1940379993: "The specific issue is go-jose/go-jose@65351c2 / go-jose/go-jose#64 which does not impact Kube at all because we have no codepath that uses JWEs. In order to update this dep, you have to update quite a lot of code in k/k since it is used by go-oidc. #117437 (comment) and #114772 (review) tried to do that, and failed because the change is non-trivial to review and there isn't any strong motivation to make any changes to these deps (there is no actual security issue)."

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing