/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-rv23-m924-g58v

Published

Last updated

https://images.chainguard.dev/security/CGA-rv23-m924-g58v
Package

kubernetes-1.31

Repository

Chainguard

Latest Update
Not affected
Aliases
  • CVE-2025-1767
  • GHSA-3wgm-2gw2-vh5m

Severity

6.5

Medium

CVSS CVSS_V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-1767

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

CVE-2025-1767 does not affect the Kubernetes client or the core Kubernetes platform. This vulnerability is specifically related to the deprecated gitRepo volume feature, which is no longer maintained and will not receive security updates. Importantly, the issue lies in the git-repo volume provisioner, not the Kubernetes client itself.

Status

Pending upstream fix

Impact

The k8s.io CVE affecting this package is currently in the triage stage upstream, PR on the issue can be found here: https://github.com/kubernetes/kubernetes/issues/130786

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing