/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-p832-pfvm-ghh3

Published

Last updated

https://images.chainguard.dev/security/CGA-p832-pfvm-ghh3
Package

kubeflow

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2020-8565
  • GHSA-8cfg-vx93-jvxw

Severity

5.5

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2020-8565

Updates

Status

Pending upstream fix

Impact

The CVE is related to k8s.io/client-go, a dependency of access-management subpackage. The dependency is pinned to a specific version and bumping the dependency breaks the built, therefore upstream needs to fix it properly. Once this is done, we can rebuilt the package in order to remediate the CVE.

Status

Under investigation

Status

Fixed

Fixed version

1.10.0-r4

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing