-
Notifications
You must be signed in to change notification settings - Fork 300
Open
Labels
kind/bugCategorizes issue or PR as related to a bug.Categorizes issue or PR as related to a bug.
Description
Some scanning tools (eg. Prisma) are reporting the following CVE in acr-credential-provider: https://www.cve.org/CVERecord?id=CVE-2025-30204
It seems to affect following binary "/var/lib/kubelet/credential-provider/acr-credential-provider":
CVE-2025-30204 ... github.com/golang-jwt/jwt/v4 ... v4.5.0 ... /var/lib/kubelet/credential-provider/acr-credential-provider ... fixed in 4.5.2
ASK = Can you please upgrade the golang-jwt/jwt to at least v4.5.2 to fix that vulnerability ?
mainred
Metadata
Metadata
Assignees
Labels
kind/bugCategorizes issue or PR as related to a bug.Categorizes issue or PR as related to a bug.