SUSE Rancher - K3s v1.32.2 version - CVE Scans - 2025-03-14

How to use this page

Search:

Image Mirrored Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
rancher/mirrored-library-traefik:3.3.2 true K3s v1.32.2 libcrypto3 libcrypto3@3.3.2-r4 CVE-2024-12797 HIGH affected alpine
rancher/mirrored-library-traefik:3.3.2 true K3s v1.32.2 libssl3 libssl3@3.3.2-r4 CVE-2024-12797 HIGH affected alpine
rancher/mirrored-metrics-server:v0.7.2 true K3s v1.32.2 metrics-server stdlib@v1.22.5 CVE-2024-34156
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/k3s:v1.32.2-k3s1 false K3s v1.32.2 bin/containerd-shim-runc-v2 golang.org/x/net@v0.30.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/k3s:v1.32.2-k3s1 false K3s v1.32.2 bin/k3s golang.org/x/crypto@v0.24.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/k3s:v1.32.2-k3s1 false K3s v1.32.2 bin/k3s golang.org/x/net@v0.26.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/k3s:v1.32.2-k3s1 false K3s v1.32.2 bin/runc golang.org/x/net@v0.24.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.9.4-build20250113 false K3s v1.32.2 libcrypto3 libcrypto3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/klipper-helm:v0.9.4-build20250113 false K3s v1.32.2 libssl3 libssl3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/klipper-helm:v0.9.4-build20250113 false K3s v1.32.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.26.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.9.4-build20250113 false K3s v1.32.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/net@v0.28.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.4-build20250113 false K3s v1.32.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.25.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.9.4-build20250113 false K3s v1.32.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.4-build20250113 false K3s v1.32.2 usr/bin/helm golang.org/x/net@v0.26.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/klipper-lb:v0.4.10 false K3s v1.32.2 libcrypto3 libcrypto3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/klipper-lb:v0.4.10 false K3s v1.32.2 libssl3 libssl3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/local-path-provisioner:v0.0.31 false K3s v1.32.2 libcrypto3 libcrypto3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/local-path-provisioner:v0.0.31 false K3s v1.32.2 libssl3 libssl3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/mirrored-coredns-coredns:1.12.0 true K3s v1.32.2 coredns golang.org/x/crypto@v0.29.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/mirrored-coredns-coredns:1.12.0 true K3s v1.32.2 coredns golang.org/x/net@v0.31.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/mirrored-metrics-server:v0.7.2 true K3s v1.32.2 metrics-server golang.org/x/crypto@v0.26.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/mirrored-metrics-server:v0.7.2 true K3s v1.32.2 metrics-server golang.org/x/net@v0.28.0 CVE-2024-45338 none not affected vulnerable code not present gobinary