Package
mesosphere-vsphere-csi-syncer-fips
Component
k8s.io/kubernetes
Latest update
2.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The vulnerability resides in the Kubernetes API server's NodeRestriction admission controller, which authorizes dynamic resource allocation during pod admission — control-plane code present only in the API server. This package builds a CSI driver and metadata syncer that link only a small subset of the k8s.io/kubernetes module (volume utilities and core-API type schemes); an import-graph analysis of each built binary confirms the admission-control package is absent. The affected code path cannot be reached, regardless of the embedded module version.
Status