Skip to content

CVE-2025-30204 in acr-credential-provider ? #9233

@axelgMS

Description

@axelgMS

Some scanning tools (eg. Prisma) are reporting the following CVE in acr-credential-provider: https://www.cve.org/CVERecord?id=CVE-2025-30204

It seems to affect following binary "/var/lib/kubelet/credential-provider/acr-credential-provider":

CVE-2025-30204 ... github.com/golang-jwt/jwt/v4 ... v4.5.0 ... /var/lib/kubelet/credential-provider/acr-credential-provider ... fixed in 4.5.2

ASK = Can you please upgrade the golang-jwt/jwt to at least v4.5.2 to fix that vulnerability ?

Metadata

Metadata

Assignees

Labels

kind/bugCategorizes issue or PR as related to a bug.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions