Skip to content

blackduck vuln scan high issues #7601

Discussion options

You must be logged in to vote

Do you mean https://github.com/vmware-tanzu/helm-charts/releases/tag/velero-6.0.0?
The related Velero version should be v1.13.x.

The released Velero tags v1.13.0 and v1.13.1 are affected by these CVEs.
The planned v1.13.2 will contain the fix of CVE-2024-24785.
I will check whether there are fixes for the other two CVEs in the Velero base image. If there isn't any fix, it should be acceptable, because Velero doesn't use related functions.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@sergeykuperman
Comment options

@blackpiglet
Comment options

Answer selected by sergeykuperman
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants