/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-fc4w-m9gg-hq8m

Published

Last updated

https://images.chainguard.dev/security/CGA-fc4w-m9gg-hq8m
Package

kubeflow

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • GHSA-74fp-r6jw-h4mp

Severity

Unknown

References

  • https://github.com/advisories/GHSA-74fp-r6jw-h4mp

Updates

Status

Pending upstream fix

Impact

The CVE is related to k8s.io/apimachinery, a dependency of access-management subpackage. The dependency is pinned to a specific version and bumping the dependency breaks the built, therefore upstream needs to fix it properly. Once this is done, we can rebuilt the package in order to remediate the CVE.

Status

Affected

Impact

Govulncheck found vulnerable symbols in Go binaries at the following locations: in kubeflow-access-management-1.10.0-r4.apk, at usr/bin/access-management, usr/bin/access-management.

Status

Under investigation

Status

Fixed

Fixed version

1.10.0-r4

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing