Skip to content

Commit 93949be

Browse files
Update CVE scans reports - 2025-11-23
1 parent 8781bd0 commit 93949be

File tree

64 files changed

+20
-20655
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

64 files changed

+20
-20655
lines changed

docs/csv/report-harvester-master-cves.csv

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -704,8 +704,6 @@ rancher/mirrored-kube-logging-config-reloader:v0.0.6,harvester/master,stdlib,v1.
704704
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/master,ruby,3.3.6-r0,alpine,CVE-2025-27219,HIGH,https://avd.aquasec.com/nvd/cve-2025-27219,rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full (alpine 3.20.3),3.3.8-r0,true,affected,
705705
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/master,ruby-libs,3.3.6-r0,alpine,CVE-2025-27219,HIGH,https://avd.aquasec.com/nvd/cve-2025-27219,rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full (alpine 3.20.3),3.3.8-r0,true,affected,
706706
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/master,google-protobuf,3.21.12,gemspec,CVE-2024-7254,HIGH,https://avd.aquasec.com/nvd/cve-2024-7254,Ruby,"~> 3.25.5, ~> 4.27.5, >= 4.28.2",true,affected,
707-
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/master,net-imap,0.3.4.1,gemspec,CVE-2025-43857,HIGH,https://avd.aquasec.com/nvd/cve-2025-43857,Ruby,"~> 0.2.5, ~> 0.3.9, ~> 0.4.20, >= 0.5.7",true,affected,
708-
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/master,net-imap,0.4.19,gemspec,CVE-2025-43857,HIGH,https://avd.aquasec.com/nvd/cve-2025-43857,Ruby,"~> 0.2.5, ~> 0.3.9, ~> 0.4.20, >= 0.5.7",true,affected,
709707
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/master,nokogiri,1.18.4,gemspec,GHSA-353f-x4gh-cqq8,CRITICAL,https://github.com/advisories/GHSA-353f-x4gh-cqq8,Ruby,>= 1.18.9,true,affected,
710708
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/master,rack,3.0.14,gemspec,CVE-2025-46727,HIGH,https://avd.aquasec.com/nvd/cve-2025-46727,Ruby,"~> 2.2.14, ~> 3.0.16, >= 3.1.14",true,affected,
711709
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/master,rack,3.0.14,gemspec,CVE-2025-61770,HIGH,https://avd.aquasec.com/nvd/cve-2025-61770,Ruby,"~> 2.2.19, ~> 3.1.17, >= 3.2.2",true,affected,

docs/csv/report-harvester-master-stats.csv

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,7 @@ rancher/mirrored-grafana-grafana:11.5.5,0,10,10
6464
rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.2,0,2,2
6565
rancher/mirrored-kiwigrid-k8s-sidecar:1.30.0,2,5,7
6666
rancher/mirrored-kube-logging-config-reloader:v0.0.6,0,3,3
67-
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,1,13,14
67+
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,1,11,12
6868
rancher/mirrored-kube-logging-logging-operator:4.10.0,0,2,2
6969
rancher/mirrored-kube-state-metrics-kube-state-metrics:v2.15.0,0,4,4
7070
rancher/mirrored-library-busybox:1.37.0,0,0,0

docs/csv/report-harvester-v1.4-head-cves.csv

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -83,7 +83,6 @@ ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4-head,libssl3,3.0.10-r0,a
8383
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4-head,libssl3,3.0.10-r0,alpine,CVE-2024-6119,HIGH,https://avd.aquasec.com/nvd/cve-2024-6119,ghcr.io/kube-logging/fluentd:v1.15-ruby3 (alpine 3.17.5),3.0.15-r0,false,affected,
8484
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4-head,nghttp2-libs,1.51.0-r1,alpine,CVE-2023-44487,HIGH,https://avd.aquasec.com/nvd/cve-2023-44487,ghcr.io/kube-logging/fluentd:v1.15-ruby3 (alpine 3.17.5),1.51.0-r2,false,affected,
8585
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4-head,google-protobuf,3.24.3,gemspec,CVE-2024-7254,HIGH,https://avd.aquasec.com/nvd/cve-2024-7254,Ruby,"~> 3.25.5, ~> 4.27.5, >= 4.28.2",false,affected,
86-
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4-head,net-imap,0.3.7,gemspec,CVE-2025-43857,HIGH,https://avd.aquasec.com/nvd/cve-2025-43857,Ruby,"~> 0.2.5, ~> 0.3.9, ~> 0.4.20, >= 0.5.7",false,affected,
8786
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4-head,nokogiri,1.15.4,gemspec,GHSA-353f-x4gh-cqq8,CRITICAL,https://github.com/advisories/GHSA-353f-x4gh-cqq8,Ruby,>= 1.18.9,false,affected,
8887
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4-head,nokogiri,1.15.4,gemspec,GHSA-mrxw-mxhj-p664,HIGH,https://github.com/advisories/GHSA-mrxw-mxhj-p664,Ruby,>= 1.18.4,false,affected,
8988
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4-head,rack,3.0.8,gemspec,CVE-2024-26141,HIGH,https://avd.aquasec.com/nvd/cve-2024-26141,Ruby,"~> 2.2.8, >= 2.2.8.1, >= 3.0.9.1",false,affected,

docs/csv/report-harvester-v1.4-head-stats.csv

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ image,critical,high,total
22
fluent/fluent-bit:2.1.8,5,25,30
33
ghcr.io/k8snetworkplumbingwg/whereabouts:v0.7.0,0,8,8
44
ghcr.io/kube-logging/config-reloader:v0.0.5,0,12,12
5-
ghcr.io/kube-logging/fluentd:v1.15-ruby3,3,26,29
5+
ghcr.io/kube-logging/fluentd:v1.15-ruby3,3,25,28
66
ghcr.io/kube-vip/kube-vip-iptables:v0.8.1,0,7,7
77
longhornio/backing-image-manager:v1.7.3,0,38,38
88
longhornio/csi-attacher:v4.8.0,0,2,2

docs/csv/report-harvester-v1.4.3-cves.csv

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -83,7 +83,6 @@ ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4.3,libssl3,3.0.10-r0,alpi
8383
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4.3,libssl3,3.0.10-r0,alpine,CVE-2024-6119,HIGH,https://avd.aquasec.com/nvd/cve-2024-6119,ghcr.io/kube-logging/fluentd:v1.15-ruby3 (alpine 3.17.5),3.0.15-r0,false,affected,
8484
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4.3,nghttp2-libs,1.51.0-r1,alpine,CVE-2023-44487,HIGH,https://avd.aquasec.com/nvd/cve-2023-44487,ghcr.io/kube-logging/fluentd:v1.15-ruby3 (alpine 3.17.5),1.51.0-r2,false,affected,
8585
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4.3,google-protobuf,3.24.3,gemspec,CVE-2024-7254,HIGH,https://avd.aquasec.com/nvd/cve-2024-7254,Ruby,"~> 3.25.5, ~> 4.27.5, >= 4.28.2",false,affected,
86-
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4.3,net-imap,0.3.7,gemspec,CVE-2025-43857,HIGH,https://avd.aquasec.com/nvd/cve-2025-43857,Ruby,"~> 0.2.5, ~> 0.3.9, ~> 0.4.20, >= 0.5.7",false,affected,
8786
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4.3,nokogiri,1.15.4,gemspec,GHSA-353f-x4gh-cqq8,CRITICAL,https://github.com/advisories/GHSA-353f-x4gh-cqq8,Ruby,>= 1.18.9,false,affected,
8887
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4.3,nokogiri,1.15.4,gemspec,GHSA-mrxw-mxhj-p664,HIGH,https://github.com/advisories/GHSA-mrxw-mxhj-p664,Ruby,>= 1.18.4,false,affected,
8988
ghcr.io/kube-logging/fluentd:v1.15-ruby3,harvester/v1.4.3,rack,3.0.8,gemspec,CVE-2024-26141,HIGH,https://avd.aquasec.com/nvd/cve-2024-26141,Ruby,"~> 2.2.8, >= 2.2.8.1, >= 3.0.9.1",false,affected,

docs/csv/report-harvester-v1.4.3-stats.csv

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ image,critical,high,total
22
fluent/fluent-bit:2.1.8,5,25,30
33
ghcr.io/k8snetworkplumbingwg/whereabouts:v0.7.0,0,8,8
44
ghcr.io/kube-logging/config-reloader:v0.0.5,0,12,12
5-
ghcr.io/kube-logging/fluentd:v1.15-ruby3,3,26,29
5+
ghcr.io/kube-logging/fluentd:v1.15-ruby3,3,25,28
66
ghcr.io/kube-vip/kube-vip-iptables:v0.8.1,0,7,7
77
longhornio/backing-image-manager:v1.7.3,0,38,38
88
longhornio/csi-attacher:v4.8.0,0,2,2

docs/csv/report-harvester-v1.5-head-cves.csv

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1500,8 +1500,6 @@ rancher/mirrored-kube-logging-config-reloader:v0.0.6,harvester/v1.5-head,stdlib,
15001500
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5-head,ruby,3.3.6-r0,alpine,CVE-2025-27219,HIGH,https://avd.aquasec.com/nvd/cve-2025-27219,rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full (alpine 3.20.3),3.3.8-r0,true,affected,
15011501
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5-head,ruby-libs,3.3.6-r0,alpine,CVE-2025-27219,HIGH,https://avd.aquasec.com/nvd/cve-2025-27219,rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full (alpine 3.20.3),3.3.8-r0,true,affected,
15021502
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5-head,google-protobuf,3.21.12,gemspec,CVE-2024-7254,HIGH,https://avd.aquasec.com/nvd/cve-2024-7254,Ruby,"~> 3.25.5, ~> 4.27.5, >= 4.28.2",true,affected,
1503-
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5-head,net-imap,0.3.4.1,gemspec,CVE-2025-43857,HIGH,https://avd.aquasec.com/nvd/cve-2025-43857,Ruby,"~> 0.2.5, ~> 0.3.9, ~> 0.4.20, >= 0.5.7",true,affected,
1504-
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5-head,net-imap,0.4.19,gemspec,CVE-2025-43857,HIGH,https://avd.aquasec.com/nvd/cve-2025-43857,Ruby,"~> 0.2.5, ~> 0.3.9, ~> 0.4.20, >= 0.5.7",true,affected,
15051503
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5-head,nokogiri,1.18.4,gemspec,GHSA-353f-x4gh-cqq8,CRITICAL,https://github.com/advisories/GHSA-353f-x4gh-cqq8,Ruby,>= 1.18.9,true,affected,
15061504
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5-head,rack,3.0.14,gemspec,CVE-2025-46727,HIGH,https://avd.aquasec.com/nvd/cve-2025-46727,Ruby,"~> 2.2.14, ~> 3.0.16, >= 3.1.14",true,affected,
15071505
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5-head,rack,3.0.14,gemspec,CVE-2025-61770,HIGH,https://avd.aquasec.com/nvd/cve-2025-61770,Ruby,"~> 2.2.19, ~> 3.1.17, >= 3.2.2",true,affected,

docs/csv/report-harvester-v1.5-head-stats.csv

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ rancher/mirrored-grafana-grafana:11.1.0,0,14,14
5858
rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.0,0,2,2
5959
rancher/mirrored-kiwigrid-k8s-sidecar:1.27.4,2,10,12
6060
rancher/mirrored-kube-logging-config-reloader:v0.0.6,0,3,3
61-
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,1,13,14
61+
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,1,11,12
6262
rancher/mirrored-kube-logging-logging-operator:4.10.0,0,2,2
6363
rancher/mirrored-kube-state-metrics-kube-state-metrics:v2.12.0,0,5,5
6464
rancher/mirrored-library-busybox:1.31.1,0,0,0

docs/csv/report-harvester-v1.5.2-cves.csv

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1500,8 +1500,6 @@ rancher/mirrored-kube-logging-config-reloader:v0.0.6,harvester/v1.5.2,stdlib,v1.
15001500
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5.2,ruby,3.3.6-r0,alpine,CVE-2025-27219,HIGH,https://avd.aquasec.com/nvd/cve-2025-27219,rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full (alpine 3.20.3),3.3.8-r0,true,affected,
15011501
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5.2,ruby-libs,3.3.6-r0,alpine,CVE-2025-27219,HIGH,https://avd.aquasec.com/nvd/cve-2025-27219,rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full (alpine 3.20.3),3.3.8-r0,true,affected,
15021502
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5.2,google-protobuf,3.21.12,gemspec,CVE-2024-7254,HIGH,https://avd.aquasec.com/nvd/cve-2024-7254,Ruby,"~> 3.25.5, ~> 4.27.5, >= 4.28.2",true,affected,
1503-
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5.2,net-imap,0.3.4.1,gemspec,CVE-2025-43857,HIGH,https://avd.aquasec.com/nvd/cve-2025-43857,Ruby,"~> 0.2.5, ~> 0.3.9, ~> 0.4.20, >= 0.5.7",true,affected,
1504-
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5.2,net-imap,0.4.19,gemspec,CVE-2025-43857,HIGH,https://avd.aquasec.com/nvd/cve-2025-43857,Ruby,"~> 0.2.5, ~> 0.3.9, ~> 0.4.20, >= 0.5.7",true,affected,
15051503
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5.2,nokogiri,1.18.4,gemspec,GHSA-353f-x4gh-cqq8,CRITICAL,https://github.com/advisories/GHSA-353f-x4gh-cqq8,Ruby,>= 1.18.9,true,affected,
15061504
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5.2,rack,3.0.14,gemspec,CVE-2025-46727,HIGH,https://avd.aquasec.com/nvd/cve-2025-46727,Ruby,"~> 2.2.14, ~> 3.0.16, >= 3.1.14",true,affected,
15071505
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,harvester/v1.5.2,rack,3.0.14,gemspec,CVE-2025-61770,HIGH,https://avd.aquasec.com/nvd/cve-2025-61770,Ruby,"~> 2.2.19, ~> 3.1.17, >= 3.2.2",true,affected,

docs/csv/report-harvester-v1.5.2-stats.csv

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ rancher/mirrored-grafana-grafana:11.1.0,0,14,14
5858
rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.0,0,2,2
5959
rancher/mirrored-kiwigrid-k8s-sidecar:1.27.4,2,10,12
6060
rancher/mirrored-kube-logging-config-reloader:v0.0.6,0,3,3
61-
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,1,13,14
61+
rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full,1,11,12
6262
rancher/mirrored-kube-logging-logging-operator:4.10.0,0,2,2
6363
rancher/mirrored-kube-state-metrics-kube-state-metrics:v2.12.0,0,5,5
6464
rancher/mirrored-library-busybox:1.31.1,0,0,0

0 commit comments

Comments
 (0)