SUSE Rancher - RKE2 v1.30.10 version - CVE Scans - 2025-03-14

How to use this page

Search:

Image Mirrored Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
rancher/hardened-calico:v3.29.2-build20250218 false RKE2 v1.30.10 libxml2-2 libxml2-2@2.10.3-150500.5.20.1 SUSE-SU-2025:0746-1 HIGH affected sles
rancher/hardened-flannel:v0.26.4-build20250218 false RKE2 v1.30.10 libxml2-2 libxml2-2@2.10.3-150500.5.20.1 SUSE-SU-2025:0746-1 HIGH affected sles
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 libxml2-2 libxml2-2@2.10.3-150500.5.20.1 SUSE-SU-2025:0746-1 HIGH affected sles
rancher/nginx-ingress-controller:v1.12.0-hardened6 false RKE2 v1.30.10 libxml2-2 libxml2-2@2.10.3-150500.5.20.1 SUSE-SU-2025:0746-1 HIGH affected sles
rancher/nginx-ingress-controller:v1.12.0-hardened6 false RKE2 v1.30.10 libxml2-tools libxml2-tools@2.10.3-150500.5.20.1 SUSE-SU-2025:0746-1 HIGH affected sles
rancher/hardened-addon-resizer:1.8.22-build20250110 false RKE2 v1.30.10 pod_nanny golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/hardened-calico:v3.29.2-build20250218 false RKE2 v1.30.10 opt/cni/bin/dhcp golang.org/x/net@v0.30.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/hardened-cluster-autoscaler:v1.9.0-build20241126 false RKE2 v1.30.10 cluster-proportional-autoscaler golang.org/x/net@v0.26.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/hardened-coredns:v1.12.0-build20241126 false RKE2 v1.30.10 coredns golang.org/x/crypto@v0.29.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/hardened-coredns:v1.12.0-build20241126 false RKE2 v1.30.10 coredns golang.org/x/net@v0.31.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/hardened-dns-node-cache:1.24.0-build20241211 false RKE2 v1.30.10 node-cache golang.org/x/crypto@v0.22.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/hardened-dns-node-cache:1.24.0-build20241211 false RKE2 v1.30.10 node-cache golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/hardened-k8s-metrics-server:v0.7.2-build20250110 false RKE2 v1.30.10 metrics-server golang.org/x/crypto@v0.26.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/hardened-k8s-metrics-server:v0.7.2-build20250110 false RKE2 v1.30.10 metrics-server golang.org/x/net@v0.28.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 libtasn1 libtasn1@4.13-150000.4.8.1 SUSE-SU-2025:0548-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 libtasn1-6 libtasn1-6@4.13-150000.4.8.1 SUSE-SU-2025:0548-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-apiserver go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.0 CVE-2023-47108 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-apiserver golang.org/x/crypto@v0.21.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-apiserver golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-controller-manager go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.0 CVE-2023-47108 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-controller-manager golang.org/x/crypto@v0.21.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-controller-manager golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-proxy go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.0 CVE-2023-47108 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-proxy golang.org/x/crypto@v0.21.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-proxy golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-scheduler go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.0 CVE-2023-47108 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-scheduler golang.org/x/crypto@v0.21.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kube-scheduler golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kubeadm golang.org/x/crypto@v0.21.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kubeadm golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kubectl golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kubelet go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful@v0.42.0 CVE-2023-45142 none not affected vulnerable code not present gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kubelet go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.0 CVE-2023-47108 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kubelet golang.org/x/crypto@v0.21.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.30.10-rke2r1-build20250213 false RKE2 v1.30.10 usr/local/bin/kubelet golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.30.10 libcrypto3 libcrypto3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.30.10 libssl3 libssl3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.30.10 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.26.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.30.10 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/net@v0.28.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.30.10 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.25.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.30.10 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.30.10 usr/bin/helm golang.org/x/net@v0.26.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/klipper-lb:v0.4.10 false RKE2 v1.30.10 libcrypto3 libcrypto3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/klipper-lb:v0.4.10 false RKE2 v1.30.10 libssl3 libssl3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/mirrored-sig-storage-snapshot-controller:v8.2.0 true RKE2 v1.30.10 snapshot-controller golang.org/x/net@v0.31.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016 false RKE2 v1.30.10 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.27.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.30.6-0.20241016053533-5ec454f50e7a-build20241016 false RKE2 v1.30.10 usr/local/bin/rke2-cloud-provider golang.org/x/net@v0.28.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/containerd go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.45.0 CVE-2023-47108 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/containerd golang.org/x/crypto@v0.21.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/containerd golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/containerd-shim-runc-v2 golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/crictl go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.0 CVE-2023-47108 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/crictl golang.org/x/net@v0.24.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/ctr golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/kubectl golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/kubelet go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful@v0.42.0 CVE-2023-45142 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/kubelet go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.0 CVE-2023-47108 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/kubelet golang.org/x/crypto@v0.21.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/kubelet golang.org/x/net@v0.23.0 CVE-2024-45338 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.30.10-rke2r1 false RKE2 v1.30.10 bin/runc golang.org/x/net@v0.24.0 CVE-2024-45338 none not affected vulnerable code not present gobinary