-
Notifications
You must be signed in to change notification settings - Fork 3.8k
Open
Labels
Description
What happened?
Image: prometheus-operator:v0.85.0
Description: Our security scans have identified vulnerabilities in the Busybox packages included in the prometheus-operator container. Details are as follows:
`▼ busybox/bin/[EXECUTABLE1.36.1
| Name | Custom Severity | Severity | Score | Fix Version | Acknowledged | Exploit Availability | Exploit Type | Exploit Reference |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42364 | medium | 5.5 | None | |||||
| CVE-2023-42363 | medium | 5.5 | None | |||||
| CVE-2023-42365 | medium | 5.5 | None | |||||
| CVE-2023-42366 | medium | 5.5 | None | |||||
| CVE-2025-46394 | low | 3.3 | None |
Please let us know if an update is planned or if there’s a recommended workaround in the meantime.
Thank you for your support!
Prometheus Operator Version
v0.85.0Kubernetes Version
Client Version: v1.32.0
Kustomize Version: v5.5.0
Server Version: v1.32.8-eks-e386d34Kubernetes Cluster Type
EKS
How did you deploy Prometheus-Operator?
helm chart:prometheus-community/kube-prometheus-stack
Manifests
prometheus-operator log output
NAAnything else?
No response