SUSE Rancher - RKE2 v1.34.1 version - CVE Scans - 2025-10-12

How to use this page

Search:

Image Mirrored Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
rancher/hardened-coredns:v1.12.3-build20250909 false RKE2 v1.34.1 coredns github.com/coredns/coredns@v1.12.3 CVE-2025-58063
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/hardened-coredns:v1.12.3-build20250909 false RKE2 v1.34.1 coredns github.com/quic-go/quic-go@v0.54.0 CVE-2025-59530 HIGH affected gobinary
rancher/hardened-dns-node-cache:1.26.0-build20250909 false RKE2 v1.34.1 node-cache github.com/coredns/coredns@v1.12.2 CVE-2025-58063
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/hardened-dns-node-cache:1.26.0-build20250909 false RKE2 v1.34.1 node-cache github.com/quic-go/quic-go@v0.52.0 CVE-2025-59530 HIGH affected gobinary
rancher/klipper-helm:v0.9.8-build20250709 false RKE2 v1.34.1 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.24.5 CVE-2025-47907
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/klipper-helm:v0.9.8-build20250709 false RKE2 v1.34.1 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.24.5 CVE-2025-47907
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/klipper-helm:v0.9.8-build20250709 false RKE2 v1.34.1 usr/bin/helm stdlib@v1.24.4 CVE-2025-47907
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/mirrored-sig-storage-snapshot-controller:v8.2.0 true RKE2 v1.34.1 snapshot-controller stdlib@v1.23.1 CVE-2025-47907
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/nginx-ingress-controller:v1.12.6-hardened1 false RKE2 v1.34.1 libopenssl1_1 libopenssl1_1@1.1.1w-150600.5.15.1 SUSE-SU-2025:03443-1 HIGH affected sles
rancher/nginx-ingress-controller:v1.12.6-hardened1 false RKE2 v1.34.1 libopenssl3 libopenssl3@3.1.4-150600.5.36.4 SUSE-SU-2025:03442-1 HIGH affected sles
rancher/hardened-addon-resizer:1.8.23-build20250909 false RKE2 v1.34.1 pod_nanny golang.org/x/net@v0.33.0 CVE-2025-22870 none not affected vulnerable code not present gobinary
rancher/hardened-addon-resizer:1.8.23-build20250909 false RKE2 v1.34.1 pod_nanny golang.org/x/net@v0.33.0 CVE-2025-22872 none not affected vulnerable code not present gobinary
rancher/hardened-addon-resizer:1.8.23-build20250909 false RKE2 v1.34.1 pod_nanny golang.org/x/oauth2@v0.24.0 CVE-2025-22868 none not affected vulnerable code not present gobinary
rancher/hardened-calico:v3.30.3-build20250909 false RKE2 v1.34.1 libbrotlicommon1 libbrotlicommon1@1.0.7-3.3.1 SUSE-SU-2025:03268-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/hardened-calico:v3.30.3-build20250909 false RKE2 v1.34.1 libbrotlidec1 libbrotlidec1@1.0.7-3.3.1 SUSE-SU-2025:03268-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/hardened-cluster-autoscaler:v1.10.2-build20250909 false RKE2 v1.34.1 cluster-proportional-autoscaler golang.org/x/net@v0.36.0 CVE-2025-22872 none not affected vulnerable code not present gobinary
rancher/hardened-cluster-autoscaler:v1.10.2-build20250909 false RKE2 v1.34.1 cluster-proportional-autoscaler golang.org/x/oauth2@v0.23.0 CVE-2025-22868 none not affected vulnerable code not present gobinary
rancher/hardened-kubernetes:v1.34.1-rke2r1-build20250910 false RKE2 v1.34.1 libbrotlicommon1 libbrotlicommon1@1.0.7-3.3.1 SUSE-SU-2025:03268-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/hardened-kubernetes:v1.34.1-rke2r1-build20250910 false RKE2 v1.34.1 libbrotlidec1 libbrotlidec1@1.0.7-3.3.1 SUSE-SU-2025:03268-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/hardened-kubernetes:v1.34.1-rke2r1-build20250910 false RKE2 v1.34.1 libcurl4 libcurl4@8.6.0-150600.4.21.1 SUSE-SU-2025:03198-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/hardened-kubernetes:v1.34.1-rke2r1-build20250910 false RKE2 v1.34.1 curl curl@8.6.0-150600.4.21.1 SUSE-SU-2025:03198-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/klipper-helm:v0.9.8-build20250709 false RKE2 v1.34.1 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis helm.sh/helm/v3@v3.18.4 CVE-2025-55198 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.8-build20250709 false RKE2 v1.34.1 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis helm.sh/helm/v3@v3.18.4 CVE-2025-55199 none not affected vulnerable code not in execute path gobinary
rancher/mirrored-sig-storage-snapshot-controller:v8.2.0 true RKE2 v1.34.1 snapshot-controller golang.org/x/net@v0.31.0 CVE-2025-22870 none not affected vulnerable code not present gobinary
rancher/mirrored-sig-storage-snapshot-controller:v8.2.0 true RKE2 v1.34.1 snapshot-controller golang.org/x/net@v0.31.0 CVE-2025-22872 none not affected vulnerable code not present gobinary
rancher/mirrored-sig-storage-snapshot-controller:v8.2.0 true RKE2 v1.34.1 snapshot-controller golang.org/x/oauth2@v0.24.0 CVE-2025-22868 none not affected vulnerable code not present gobinary
rancher/nginx-ingress-controller:v1.12.6-hardened1 false RKE2 v1.34.1 libbrotlicommon1 libbrotlicommon1@1.0.7-3.3.1 SUSE-SU-2025:03268-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/nginx-ingress-controller:v1.12.6-hardened1 false RKE2 v1.34.1 libbrotlidec1 libbrotlidec1@1.0.7-3.3.1 SUSE-SU-2025:03268-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/nginx-ingress-controller:v1.12.6-hardened1 false RKE2 v1.34.1 libcurl4 libcurl4@8.6.0-150600.4.21.1 SUSE-SU-2025:03198-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/nginx-ingress-controller:v1.12.6-hardened1 false RKE2 v1.34.1 curl curl@8.6.0-150600.4.21.1 SUSE-SU-2025:03198-1 none not affected vulnerable code cannot be controlled by adversary sles
rancher/nginx-ingress-controller:v1.12.6-hardened1 false RKE2 v1.34.1 libopenssl-3-devel libopenssl-3-devel@3.1.4-150600.5.36.4 SUSE-SU-2025:03442-1 none not affected vulnerable code not present sles
rancher/nginx-ingress-controller:v1.12.6-hardened1 false RKE2 v1.34.1 libopenssl-3-fips-provider libopenssl-3-fips-provider@3.1.4-150600.5.36.4 SUSE-SU-2025:03442-1 none not affected vulnerable code not present sles
rancher/nginx-ingress-controller:v1.12.6-hardened1 false RKE2 v1.34.1 openssl-3 openssl-3@3.1.4-150600.5.36.4 SUSE-SU-2025:03442-1 none not affected vulnerable code not present sles