[Security Advisory] CVE-2023-2253 in nfd-master and nfd-topology-updater #1267
Closed
sakshisharma84
started this conversation in
General
Replies: 1 comment
-
It's in an indirect dependency brought in by kubernetes. I don't see any reason this particular vulnerability would be relevant to nfd. Moreover, it hasn't been fixed in kubernetes release branches so we cannot update it either. If you're concerned please report against kubernetes. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi guys,
We are using the latest version(v0.13.2) of node-feature-discovery and our sysdig scanner shows a vulnerability(CVE-2023-2253) in the following two binaries: nfd-master and nfd-topology-updater (screenshots attached for reference).
Are there any plans to roll out the fixes any time soon?
Beta Was this translation helpful? Give feedback.
All reactions