Skip to content

Multiple high severity CVEs on latest nvidia-device-plugin(v1.0.20) #303

@sakshisharma84

Description

@sakshisharma84

We use the latest version of nvidia-device-plugin(v1.0.20) and the following packages report some high vulnerabilities by the sysdig scanner.

  1. github.com/prometheus/client_golang: CVE-2022-21698
  2. golang.org/x/net : CVE-2021-33194, CVE-2021-44716, CVE-2022-27664, CVE-2022-41723
  3. golang.org/x/text: CVE-2021-38561 , CVE-2022-32149
Screenshot 2023-07-24 at 12 14 08 PM

Are there any plans to fix them anytime soon?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions