7.5
CVSS V3
Status
Impact
CVE-2023-44487 affected a wide range of software, including Go's http2 stack. Although x/net was upgraded at the time to remediate the CVE, it appears that k8s.io/apimachinery was separately affected (https://github.com/kubernetes/apimachinery/commit/a0fd4b065528566eec54fe207aa5e3131babc378) but this doesn't seem to have been included in CNA advisories, leading to missed detections. Unfortunately, it's not currently possible to upgrade this dependency due to incompatibilities, upstream will need to make code changes to upgrade to at least v0.24.0
Status
Fixed version
1.10.0-r4Status