CVE-2023-42282 vulnerability in summerwind/actions-runner:latest image Node16 NPM #3756
Open
7 tasks done
Labels
bug
Something isn't working
community
Community contribution
needs triage
Requires review from the maintainers
Checks
Controller Version
0.27.4
Helm Chart Version
0.23.3
CertManager Version
No response
Deployment Method
ArgoCD
cert-manager installation
Yes to all
Checks
Resource Definitions
To Reproduce
Describe the bug
We run several
RunnerDeployment
instances across our EKS clusters. AWS Inspector has identified that the currentsummerwind/actions-runner:latest
image (digest2b12329ec3fbec1ebfae20acdf23c245b3111da89e34fb220af60d255f88a574
) is susceptible to CVE-2023-42282. The offendingip
package is located in/runnertmp/externalstmp/node16/lib/node_modules/npm/node_modules/ip
.It does appear though that NPM for the
node16
distribution can be upgraded up to 9.9.0, which deprecates theip
package entirely.Describe the expected behavior
Expected no critical vulnerabilities in the latest image.
Whole Controller Logs
Whole Runner Pod Logs
Additional Context
No response
The text was updated successfully, but these errors were encountered: