/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-xc77-9rx9-7f3g

Published

Last updated

https://images.chainguard.dev/security/CGA-xc77-9rx9-7f3g
Package

aws-efs-csi-driver

RepositoryWolfi
Latest Update
Fixed
Fixed Version

2.1.7-r0

Aliases
  • CVE-2025-0426
  • GHSA-jgfp-53c3-624w

Severity

6.2

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-0426

Updates

Status

Fixed

Fixed version

2.1.7-r0

Status

Pending upstream fix

Impact

To remedieate this CVE the code requires upgrading Kubernetes dependencies to v1.29.14, but doing that the build fails due to missing feature flags (genericfeatures.StructuredAuthorizationConfiguration and genericfeatures.ZeroLimitedNominalConcurrencyShares) that were removed in later versions. The package currently depends on k8s.io/kubernetes v1.28.15. This requires upstream changes to support newer Kubernetes API versions and feature gates.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing