SUSE Rancher - RKE2 v1.32.3 version - CVE Scans - 2025-04-01

How to use this page

Search:

Image Mirrored Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
rancher/hardened-coredns:v1.12.0-build20241126 false RKE2 v1.32.3 coredns github.com/expr-lang/expr@v1.16.9 CVE-2025-29786 HIGH affected gobinary
rancher/rke2-cloud-provider:v1.32.0-rc3.0.20241220224140-68fbd1a6b543-build20250101 false RKE2 v1.32.3 usr/local/bin/rke2-cloud-provider github.com/golang-jwt/jwt/v4@v4.5.1 CVE-2025-30204 HIGH affected gobinary
rancher/hardened-coredns:v1.12.0-build20241126 false RKE2 v1.32.3 coredns github.com/golang-jwt/jwt/v4@v4.5.1 CVE-2025-30204 none not affected vulnerable code not in execute path gobinary
rancher/hardened-coredns:v1.12.0-build20241126 false RKE2 v1.32.3 coredns golang.org/x/crypto@v0.29.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/hardened-dns-node-cache:1.24.0-build20241211 false RKE2 v1.32.3 node-cache golang.org/x/crypto@v0.22.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/hardened-etcd:v3.5.19-k3s1-build20250306 false RKE2 v1.32.3 usr/local/bin/etcd github.com/golang-jwt/jwt/v4@v4.5.1 CVE-2025-30204 none not affected vulnerable code not in execute path gobinary
rancher/hardened-etcd:v3.5.19-k3s1-build20250306 false RKE2 v1.32.3 usr/local/bin/etcdctl github.com/golang-jwt/jwt/v4@v4.5.1 CVE-2025-30204 none not affected vulnerable code not in execute path gobinary
rancher/hardened-k8s-metrics-server:v0.7.2-build20250110 false RKE2 v1.32.3 metrics-server golang.org/x/crypto@v0.26.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/hardened-kubernetes:v1.32.3-rke2r1-build20250312 false RKE2 v1.32.3 usr/local/bin/kube-apiserver golang.org/x/crypto@v0.28.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.32.3-rke2r1-build20250312 false RKE2 v1.32.3 usr/local/bin/kube-controller-manager golang.org/x/crypto@v0.28.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.32.3-rke2r1-build20250312 false RKE2 v1.32.3 usr/local/bin/kube-proxy golang.org/x/crypto@v0.28.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.32.3-rke2r1-build20250312 false RKE2 v1.32.3 usr/local/bin/kube-scheduler golang.org/x/crypto@v0.28.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.32.3-rke2r1-build20250312 false RKE2 v1.32.3 usr/local/bin/kubeadm golang.org/x/crypto@v0.28.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.32.3-rke2r1-build20250312 false RKE2 v1.32.3 usr/local/bin/kubelet go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful@v0.42.0 CVE-2023-45142 none not affected vulnerable code not present gobinary
rancher/hardened-kubernetes:v1.32.3-rke2r1-build20250312 false RKE2 v1.32.3 usr/local/bin/kubelet golang.org/x/crypto@v0.28.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.32.3 libcrypto3 libcrypto3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.32.3 libssl3 libssl3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.32.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.26.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.9.4-build20250113 false RKE2 v1.32.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.25.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.32.0-rc3.0.20241220224140-68fbd1a6b543-build20250101 false RKE2 v1.32.3 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.29.0 CVE-2024-45337 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.32.3-rke2r1 false RKE2 v1.32.3 bin/kubelet go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful@v0.42.0 CVE-2023-45142 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.32.3-rke2r1 false RKE2 v1.32.3 bin/kubelet golang.org/x/crypto@v0.28.0 CVE-2024-45337 none not affected vulnerable code not in execute path gobinary