Skip to content

[BUG] Security patch for [CVE-2024-13176] required by upgrading to newer Alpine base docker image #818

@mcphersonwhite-axon

Description

@mcphersonwhite-axon

Note: Make sure to check out known issues (https://akv2k8s.io/troubleshooting/known-issues/) before submitting

Components and versions
Select which component(s) the bug relates to with [X].

[X] Controller, version: 1.7.3 (docker image tag)
[ ] Env-Injector (webhook), version: x.x.x (docker image tag)
[ ] Other

Describe the bug
Currently there is an active CVE-2024-13176 against the currently referenced version of alpine used in the Dockerfile, 3.20.3. Upon researching this issue it appears that alpine has addressed the CVE in their 3.21.3 or 3.20.6 (to stay in the same major.minor) version ref.

Would you consider upgrading the base alpine version used to build the docker image to address the CVE related to OpenSSL?

To Reproduce
N/A

Expected behavior
Upgrading the base alpine version used to build the docker image to address the CVE related to OpenSSL.

Logs
N/A

Additional context
Add any other context about the problem here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions