Skip to content

Security Vulnerabilities Identified in prometheus-operator:v0.85.0 #8011

@vanshiika

Description

@vanshiika

What happened?

Image: prometheus-operator:v0.85.0
Description: Our security scans have identified vulnerabilities in the Busybox packages included in the prometheus-operator container. Details are as follows:

` busybox/bin/[EXECUTABLE1.36.1

Name Custom Severity Severity Score Fix Version Acknowledged Exploit Availability Exploit Type Exploit Reference
CVE-2023-42364   medium 5.5 None        
CVE-2023-42363   medium 5.5 None        
CVE-2023-42365   medium 5.5 None        
CVE-2023-42366   medium 5.5 None        
CVE-2025-46394   low 3.3 None        
Would it be possible to address these vulnerabilities in the next release of the image?

Please let us know if an update is planned or if there’s a recommended workaround in the meantime.

Thank you for your support!

Prometheus Operator Version

v0.85.0

Kubernetes Version

Client Version: v1.32.0
Kustomize Version: v5.5.0
Server Version: v1.32.8-eks-e386d34

Kubernetes Cluster Type

EKS

How did you deploy Prometheus-Operator?

helm chart:prometheus-community/kube-prometheus-stack

Manifests

prometheus-operator log output

NA

Anything else?

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions