Package
helm-operator
Component
oras.land/oras-go/v2
Latest update
Fixed version
1.42.3-r10
7.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
1.42.3-r10Status
Impact
The vulnerable component is oras.land/oras-go/v2. Per the GitHub Security Advisory at https://github.com/advisories/GHSA-fxhp-mv3v-67qp, no released version of oras.land/oras-go/v2 contains the fix (all versions <=2.6.1 are affected). A fix has been merged upstream but is not yet part of a tagged release. Upstream maintainers will need to publish a release containing the fix in order to resolve this CVE.
Status