blackduck vuln scan high issues #7601
-
Hello , golang-runtime 1.21.6: the last one is the more critical one. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
Do you mean https://github.com/vmware-tanzu/helm-charts/releases/tag/velero-6.0.0? The released Velero tags v1.13.0 and v1.13.1 are affected by these CVEs. |
Beta Was this translation helpful? Give feedback.
Do you mean https://github.com/vmware-tanzu/helm-charts/releases/tag/velero-6.0.0?
The related Velero version should be v1.13.x.
The released Velero tags v1.13.0 and v1.13.1 are affected by these CVEs.
The planned v1.13.2 will contain the fix of CVE-2024-24785.
I will check whether there are fixes for the other two CVEs in the Velero base image. If there isn't any fix, it should be acceptable, because Velero doesn't use related functions.