Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

kube-dns v1.17.4 image impacted by CVE-2020-29652 #481

Closed
rayandas opened this issue Sep 17, 2021 · 4 comments
Closed

kube-dns v1.17.4 image impacted by CVE-2020-29652 #481

rayandas opened this issue Sep 17, 2021 · 4 comments
Assignees

Comments

@rayandas
Copy link
Member

kube-dns v1.17.4 image impacted by CVE-2020-29652

@prameshj
Copy link
Contributor

Can you try newer images v1.20.0 or v1.21.0? Those were built with golang 1.16.

/assign @rayandas

@rayandas
Copy link
Member Author

@prameshj I was using the image from k8s.gcr.io/dns/k8s-dns-kube-dns which has v1.17.4 as latest version. Check here.

@prameshj
Copy link
Contributor

Oh, got it. The later kube-dns images were not promoted, since kube-dns is not used in OSS anymore. Do you use self-managed kube-dns?

I am promoting the latest kube-dns images in kubernetes/k8s.io#2759. Once that merges, can you try against that tag? Thanks!

@rayandas
Copy link
Member Author

@prachirp yeah right. and thanks for the 1.21.1 that you promoted.

@k8s-ci-robot
Copy link
Contributor

@rayandas: Closing this issue.

In response to this:

/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants