Package
rancher-webhook-fips-0.6
Component
k8s.io/kubernetes
Latest update
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The k8s.io/kubernetes @ v1.31.6 vulnerability affects the deprecated gitRepo volume feature that allows inadvertent local repository access. According to the GitHub Advisory (GHSA-3wgm-2gw2-vh5m), this deprecated feature will not receive security updates upstream and has no patch version available. The rancher-webhook package depends on k8s.io/kubernetes v1.31.6 which includes this deprecated but vulnerable code. This vulnerability only affects Kubernetes clusters that utilize the in-tree gitRepo volume feature, which has been deprecated. A fix requires upstream Kubernetes to either remove the deprecated feature entirely or provide a security update, despite their stated policy of not updating deprecated features.
Status