Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NodeLocal DNS version 1.21.0 image vulnerabilities reported for CVE-2021-3711 and CVE-2021-3712 #478

Closed
rtheis opened this issue Sep 9, 2021 · 8 comments
Assignees

Comments

@rtheis
Copy link

rtheis commented Sep 9, 2021

NodeLocal DNS version 1.21.0 image vulnerabilities reported for CVE-2021-3711 and CVE-2021-3712.

The scan results show that 2 ISSUES were found for the image.

Vulnerable Packages Found
=========================

Vulnerability ID   Policy Status   Affected Packages   How to Resolve   
CVE-2021-3711      Active          libssl1.1           Upgrade libssl1.1 to >= 1.1.1d-0+deb10u7   
CVE-2021-3712      Active          libssl1.1           Upgrade libssl1.1 to >= 1.1.1d-0+deb10u7   

To see the details about the fixes for these packages, run the command again with the '--extended' flag.

OK
@prameshj
Copy link
Contributor

prameshj commented Sep 9, 2021

Thanks!

cc @wespanther @justaugustus Looks like we need a new debian base/iptables?
Do we need a new issue like kubernetes/release#2189?

@Rustem05
Copy link

Dns

@Rustem05
Copy link

Intra

@prameshj
Copy link
Contributor

cc @rahulkjoshi

@prameshj
Copy link
Contributor

This should be fixed with the 1.21.1 image being promoted in kubernetes/k8s.io#2759

@prameshj
Copy link
Contributor

/assign @rtheis

Please verify and close if needed.

@rtheis
Copy link
Author

rtheis commented Sep 21, 2021

I've verified this is now fixed:

image

@rtheis
Copy link
Author

rtheis commented Sep 21, 2021

Thank you.

@rtheis rtheis closed this as completed Sep 21, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants