/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-g3ph-86p6-33m8

Published

Last updated

https://images.chainguard.dev/security/CGA-g3ph-86p6-33m8
Package

argocd-image-updater-fips

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2023-2253
  • GHSA-hqxw-f8mx-cpmw

Severity

6.5

Medium

CVSS CVSS_V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2023-2253

Updates

Status

Pending upstream fix

Impact

This CVE is caused by a 'go replace' block in the go.mod file pulling in the dependency, despite the package using the latest version as defined elsewhere in the go.mod file. An upstream patch has been submitted and merged which will remove this old dependency in future versions. See https://github.com/argoproj-labs/argocd-image-updater/pull/969

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing