solo-io/gloo

Busybox vulnerability in sds

twolf-adc opened this issue · 0 comments

Gloo Edge Product

Open Source

Gloo Edge Version

v1.16.12

Kubernetes Version

v1.29.9

Describe the bug

The issue is the following vulnerability in the sds component:

https://nvd.nist.gov/vuln/detail/CVE-2022-48174

As far as I can tell, there is no stable fix version of Busybox yet. Still the question, is the Gloo sds potentially affected?

Expected Behavior

Should not be susceptible.

Steps to reproduce the bug

No specific steps.

Additional Environment Detail

No response

Additional Context

No response