/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-vf83-jw7j-7q4p

Published

Last updated

https://images.chainguard.dev/security/CGA-vf83-jw7j-7q4p
Package

rancher-agent-2.9

Repository

Chainguard

Latest Update
Not affected
Aliases
  • CVE-2025-1767
  • GHSA-3wgm-2gw2-vh5m

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-1767

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

This vulnerability applies to the git-repo volume provisioner, not the k8s client itself.

Status

Pending upstream fix

Impact

The k8s.io CVE affecting this package has been remediated in the upstream master branch, however due to the complexity of the differences between master and the v1.30.x version stream, it is not yet known if the fix will be backported to the v1.30.x version stream. The PR for upstream issue can be found here: https://github.com/kubernetes/kubernetes/pull/129923

Status

Under investigation

Status

Fixed

Fixed version

2.9.7-r3

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing