Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-4323 - Provide v3.0.4 fluenbit in kubesphere/fluent-bit image #1175

Closed
els-ipatel opened this issue May 21, 2024 · 2 comments · Fixed by #1176
Closed

CVE-2024-4323 - Provide v3.0.4 fluenbit in kubesphere/fluent-bit image #1175

els-ipatel opened this issue May 21, 2024 · 2 comments · Fixed by #1176

Comments

@els-ipatel
Copy link
Contributor

Is your feature request related to a problem? Please describe.

Upstream fluent-bit have release v3.0.4 (https://github.com/fluent/fluent-bit/releases/tag/v3.0.4) to address https://nvd.nist.gov/vuln/detail/CVE-2024-4323, latest fluent-bit version in kubesphere/fluent-bit registry is 2.8.0.

To run a non-vulnerable version of fluent-bit with the fluent-operator, support for v3.0.4 is needed.

Describe the solution you'd like

  • Publish kubesphere/fluent-bit image with fluent-bit 3.0.4

  • Set the default kubesphere/fluent-bit image reference in installation manifests/helm charts to ensure those using defaults are not inadevertently spinning up vulnerable version of fluent-bit.

Additional context

No response

@398264197
Copy link

没有这个镜像呀,是我操作不对嘛
registry.cn-beijing.aliyuncs.com/kubesphereio/fluent-bit:v3.0.4

@els-ipatel
Copy link
Contributor Author

@benjaminhuo thanks for the review/merge, when can we expect the tagged image to be published to dockerhub? I'm guessing a release is needed on this repo for this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants