Package
eks-distro-kubernetes-csi-external-provisioner-fips-1.31
Component
k8s.io/kubernetes
Latest update
6.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerability originates from an unpatched Kubernetes v1.32 dependency, as upgrading to v1.32.7 was not possible. Additionally, upstream has pinned the Kubernetes API-related dependency to v1.31.11, which should be updated to v1.31.12 (see: https://groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE
Status