Skip to content

Commit 5382813

Browse files
authored
* fix: CVE-2025-30204 Signed-off-by: Jorge Turrado <[email protected]> * fix: CVE-2025-30204 Signed-off-by: Jorge Turrado <[email protected]> * fix: CVE-2025-30204 Signed-off-by: Jorge Turrado <[email protected]> --------- Signed-off-by: Jorge Turrado <[email protected]>
1 parent 72e6296 commit 5382813

File tree

9 files changed

+89
-29
lines changed

9 files changed

+89
-29
lines changed

CHANGELOG.md

+1
Original file line numberDiff line numberDiff line change
@@ -92,6 +92,7 @@ Here is an overview of all new **experimental** features:
9292
- **General**: Centralize and improve automaxprocs configuration with proper structured logging ([#5970](https://github.com/kedacore/keda/issues/5970))
9393
- **General**: Fix CVE-2025-27144 and CVE-2025-22868 ([#6613](https://github.com/kedacore/keda/issues/6613))
9494
- **General**: Fix CVE-2025-29786 ([#6637](https://github.com/kedacore/keda/issues/6637))
95+
- **General**: Fix CVE-2025-30204 ([#6641](https://github.com/kedacore/keda/pull/6641))
9596
- **General**: Fix event text when deactivation fails ([#6469](https://github.com/kedacore/keda/issues/6469))
9697
- **General**: Make sure the exposed metrics (from KEDA operator) are updated when there is a change to triggers ([#6618](https://github.com/kedacore/keda/pull/6618))
9798
- **General**: Paused ScaledObject count is reported correctly after operator restart ([#6321](https://github.com/kedacore/keda/issues/6321))

go.mod

+2-5
Original file line numberDiff line numberDiff line change
@@ -159,9 +159,6 @@ replace (
159159
// we need a version with a proper license
160160
github.com/chzyer/logex => github.com/chzyer/logex v1.2.1
161161

162-
// https://github.com/advisories/GHSA-29wx-vh33-7x7r
163-
github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.1
164-
165162
// we use an updated package to avoid other vulnerabilities on its deps (like github.com/dgrijalva/jwt-go)
166163
github.com/spf13/viper => github.com/spf13/viper v1.19.0
167164

@@ -255,8 +252,8 @@ require (
255252
github.com/gofrs/uuid v4.4.0+incompatible // indirect
256253
github.com/gogo/protobuf v1.3.2 // indirect
257254
github.com/golang-jwt/jwt v3.2.2+incompatible // indirect
258-
github.com/golang-jwt/jwt/v4 v4.5.1 // indirect
259-
github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
255+
github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
256+
github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
260257
github.com/golang-sql/civil v0.0.0-20220223132316-b832511892a9 // indirect
261258
github.com/golang-sql/sqlexp v0.1.0 // indirect
262259
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect

go.sum

+7-4
Original file line numberDiff line numberDiff line change
@@ -1782,10 +1782,13 @@ github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
17821782
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
17831783
github.com/golang-jwt/jwt v3.2.2+incompatible h1:IfV12K8xAKAnZqdXVzCZ+TOjboZ2keLg81eXfW3O+oY=
17841784
github.com/golang-jwt/jwt v3.2.2+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
1785-
github.com/golang-jwt/jwt/v4 v4.5.1 h1:JdqV9zKUdtaa9gdPlywC3aeoEsR681PlKC+4F5gQgeo=
1786-
github.com/golang-jwt/jwt/v4 v4.5.1/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
1787-
github.com/golang-jwt/jwt/v5 v5.2.1 h1:OuVbFODueb089Lh128TAcimifWaLhJwVflnrgM17wHk=
1788-
github.com/golang-jwt/jwt/v5 v5.2.1/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
1785+
github.com/golang-jwt/jwt/v4 v4.0.0/go.mod h1:/xlHOz8bRuivTWchD4jCa+NbatV+wEUSzwAxVc6locg=
1786+
github.com/golang-jwt/jwt/v4 v4.2.0/go.mod h1:/xlHOz8bRuivTWchD4jCa+NbatV+wEUSzwAxVc6locg=
1787+
github.com/golang-jwt/jwt/v4 v4.5.0/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
1788+
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
1789+
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
1790+
github.com/golang-jwt/jwt/v5 v5.2.2 h1:Rl4B7itRWVtYIHFrSNd7vhTiz9UpLdi6gZhZ3wEeDy8=
1791+
github.com/golang-jwt/jwt/v5 v5.2.2/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
17891792
github.com/golang-sql/civil v0.0.0-20190719163853-cb61b32ac6fe/go.mod h1:8vg3r2VgvsThLBIFL93Qb5yWzgyZWhEmBwUJWevAkK0=
17901793
github.com/golang-sql/civil v0.0.0-20220223132316-b832511892a9 h1:au07oEsX2xN0ktxqI+Sida1w446QrXBRJ0nee3SNZlA=
17911794
github.com/golang-sql/civil v0.0.0-20220223132316-b832511892a9/go.mod h1:8vg3r2VgvsThLBIFL93Qb5yWzgyZWhEmBwUJWevAkK0=

vendor/github.com/golang-jwt/jwt/v4/parser.go

+33-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/README.md

+8-8
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/SECURITY.md

+2-2
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/parser.go

+33-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/token.go

+1-1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/modules.txt

+2-3
Original file line numberDiff line numberDiff line change
@@ -783,10 +783,10 @@ github.com/gogo/protobuf/types
783783
# github.com/golang-jwt/jwt v3.2.2+incompatible
784784
## explicit
785785
github.com/golang-jwt/jwt
786-
# github.com/golang-jwt/jwt/v4 v4.5.1 => github.com/golang-jwt/jwt/v4 v4.5.1
786+
# github.com/golang-jwt/jwt/v4 v4.5.2
787787
## explicit; go 1.16
788788
github.com/golang-jwt/jwt/v4
789-
# github.com/golang-jwt/jwt/v5 v5.2.1
789+
# github.com/golang-jwt/jwt/v5 v5.2.2
790790
## explicit; go 1.18
791791
github.com/golang-jwt/jwt/v5
792792
# github.com/golang-sql/civil v0.0.0-20220223132316-b832511892a9
@@ -3236,7 +3236,6 @@ sigs.k8s.io/yaml/goyaml.v3
32363236
# k8s.io/kube-openapi => k8s.io/kube-openapi v0.0.0-20240228011516-70dd3763d340
32373237
# k8s.io/metrics => k8s.io/metrics v0.31.2
32383238
# github.com/chzyer/logex => github.com/chzyer/logex v1.2.1
3239-
# github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.1
32403239
# github.com/spf13/viper => github.com/spf13/viper v1.19.0
32413240
# golang.org/x/crypto => golang.org/x/crypto v0.31.0
32423241
# golang.org/x/net => golang.org/x/net v0.33.0

0 commit comments

Comments
 (0)