Package
aws-efs-csi-driver
Component
k8s.io/kubernetes
Latest update
5.9
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
This vulnerability affects versions <= v1.29.12. This vulnerability is limited to Windows hosts.
Status
Fixed version
2.1.7-r0Status
Impact
To remediate this CVE the code requires upgrading Kubernetes dependencies to v1.29.13 or later, but doing that the build fails due to missing feature flags (genericfeatures.StructuredAuthorizationConfiguration and genericfeatures.ZeroLimitedNominalConcurrencyShares) that were removed in later versions. The package currently depends on k8s.io/kubernetes v1.28.15. This requires upstream changes to support newer Kubernetes API versions and feature gates.
Status