/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-5prg-fc3x-7vrg

Published

Last updated

https://images.chainguard.dev/security/CGA-5prg-fc3x-7vrg
Package

argocd-image-updater

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2023-2253
  • GHSA-hqxw-f8mx-cpmw

Severity

6.5

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2023-2253

Updates

Status

Pending upstream fix

Impact

This CVE is caused by a 'go replace' block in the go.mod file pulling in the dependency, despite the package using the latest version as defined elsewhere in the go.mod file. An upstream patch has been submitted and merged which will remove this old dependency in future versions. See https://github.com/argoproj-labs/argocd-image-updater/pull/969

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing