kubernetes-1.29
Chainguard
4.3
CVSS CVSS_V3
Status
Justification
Impact
See https://github.com/kubernetes/kubernetes/pull/123253#issuecomment-1940379993: "The specific issue is go-jose/go-jose@65351c2 / go-jose/go-jose#64 which does not impact Kube at all because we have no codepath that uses JWEs. In order to update this dep, you have to update quite a lot of code in k/k since it is used by go-oidc. #117437 (comment) and #114772 (review) tried to do that, and failed because the change is non-trivial to review and there isn't any strong motivation to make any changes to these deps (there is no actual security issue)."
Status