Skip to content

CVE-2025-30204 impacting kOps 1.31.0 #17325

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
JustinBokus opened this issue Mar 25, 2025 · 2 comments
Closed

CVE-2025-30204 impacting kOps 1.31.0 #17325

JustinBokus opened this issue Mar 25, 2025 · 2 comments
Labels
kind/bug Categorizes issue or PR as related to a bug.

Comments

@JustinBokus
Copy link

/kind bug

impacting kOps 1.31.0

kOps 1.31.0 uses github.com/golang-jwt/jwt/v5-v5.2.1 which is vulnerable to https://nvd.nist.gov/vuln/detail/CVE-2025-30204

This CVE is not yet listed in govulncheck will update issue when it has been added with govulncheck scan results when available.

@k8s-ci-robot k8s-ci-robot added the kind/bug Categorizes issue or PR as related to a bug. label Mar 25, 2025
@rifelpet
Copy link
Member

rifelpet commented May 7, 2025

Kops 1.32.0 has been released with github.com/golang-jwt/jwt/v5 v5.2.2

/close

@k8s-ci-robot
Copy link
Contributor

@rifelpet: Closing this issue.

In response to this:

Kops 1.32.0 has been released with github.com/golang-jwt/jwt/v5 v5.2.2

/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Categorizes issue or PR as related to a bug.
Projects
None yet
Development

No branches or pull requests

3 participants