keda-fips-2.16
Chainguard
7.5
CVSS V3
Status
Impact
This vulnerability found in jwt 3.2.2 requires upgrading to a newer major version, jwt 4.x or 5.x. The Keda project has removed its dependency on jwt 3.x starting with version 2.17. Since Keda 2.16.x is now end of life and no longer receives upstream updates, it is recommended to upgrade to Keda 2.17.x or later.
Status
Impact
Govulncheck found vulnerable symbols in Go binaries at the following locations: in keda-fips-2.16-2.16.1-r11.apk, at usr/bin/keda, usr/bin/keda; in keda-fips-2.16-metrics-apiserver-2.16.1-r11.apk, at usr/bin/keda-adapter, usr/bin/keda-adapter.
Status