Package
kubeadm-1.32
Component
gopkg.in/square/go-jose.v2
Latest update
4.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
This vulnerability requires non-trivial upstream code changes to replace the affected dependency. Kubernetes implemented these changes in the 1.33 release: https://github.com/kubernetes/kubernetes/blob/2ac0bdf360cf2529a3675c7012d0bf415e1051f3/CHANGELOG/CHANGELOG-1.33.md?plain=1#L1704 The upstream maintainers would need to backport this fix to the 1.32 branch.
Status