rancher-webhook-fips-0.6
Chainguard
Status
Impact
The k8s.io/kubernetes @ v1.31.6 vulnerability affects the deprecated gitRepo volume feature that allows inadvertent local repository access. According to the GitHub Advisory (GHSA-3wgm-2gw2-vh5m), this deprecated feature will not receive security updates upstream and has no patch version available. The rancher-webhook package depends on k8s.io/kubernetes v1.31.6 which includes this deprecated but vulnerable code. This vulnerability only affects Kubernetes clusters that utilize the in-tree gitRepo volume feature, which has been deprecated. A fix requires upstream Kubernetes to either remove the deprecated feature entirely or provide a security update, despite their stated policy of not updating deprecated features.
Status