Bugzilla – Bug 1228241
VUL-0: CVE-2023-37788: kubernetes1.24, kubernetes1.25, kubernetes1.26: goproxy: nil pointer dereference causes panic in MITM mode
Last modified: 2024-07-25 07:51:14 UTC
+++ This bug was initially created as a clone of Bug #1213466 +++ CVE-2023-37788 goproxy v1.1 was discovered to contain an issue which can lead to a Denial of service (DoS) via unspecified vectors. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-37788 https://www.cve.org/CVERecord?id=CVE-2023-37788 https://github.com/elazarl/goproxy https://github.com/elazarl/goproxy/issues/502
The following embeded a vulnerable version of goproxy: - SUSE:SLE-15-SP4:Update/kubernetes1.26 - SUSE:SLE-15-SP4:Update/kubernetes1.25 - SUSE:SLE-15-SP3:Update/kubernetes1.24 - SUSE:SLE-15-SP4:Update/kubernetes1.24 - SUSE:SLE-15-SP5:Update/kubernetes1.24
Many thanks for the complete analysis Priyanka. Closing since kubectl is not affected