6.6
CVSS V3
Status
Impact
Upstream currently relies on a fork of github.com/containernetworking/plugins (https://github.com/rancher/plugins), as referenced in the k3s build script (https://github.com/k3s-io/k3s/blob/8dac81b2a24e78ce4cf951c7788ea6a8d4a59aa7/scripts/build#L165). This fork has fallen behind the main repository. To remediate the vulnerability, upstream must first update the fork to version 1.9.0 or later and then update the corresponding dependency in k3s.
Status