Skip to content

Security: Vulnerability CVE-2024-58251 detected in container image #3839

@LiChihCheng

Description

@LiChihCheng

Summary
A routine security scan using Trivy has identified a vulnerability CVE-2024-58251 within the cAdvisor image. This issue potentially impacts the security posture of the deployment and requires a dependency update or a base image rebuild to mitigate the risk.

Vulnerability Details
CVE ID: CVE-2024-58251

Severity: (Please check your Trivy output, e.g., HIGH or CRITICAL)

Package/Library: (e.g., libc, openssl, or specific Go module)

Installed Version: (Refer to your Trivy scan result)

Fixed Version: (Refer to your Trivy scan result)

Recommended Fix
We kindly request the maintainers to:

Update the affected dependency to the fixed version.

Re-tag and push a updated container image to the official registry.

Additional Context
Scanning Tool: Trivy (latest)
Target: cAdvisor Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions