—
GO-2023-2355
Knative Serving vulnerable to attacker-controlled pod causing denial of service of autoscaler in knative.dev/serving
Quick fix
GO-2023-2355 — knative.dev/serving: upgrade to the fixed version with the command below.
go get knative.dev/serving@v0.39.0Details
Knative Serving vulnerable to attacker-controlled pod causing denial of service of autoscaler in knative.dev/serving
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/knative/serving/security/advisories/GHSA-qmvj-4qr9-v547[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-48713[ADVISORY]
- https://github.com/knative/serving/commit/012ee2509231b80b7842139bfabc30516d3026ca[WEB]
- https://github.com/knative/serving/commit/101f814112b9ca0767f457e7e616b46205551cf1[WEB]
- https://github.com/knative/serving/commit/fff40ef7bac9be8380ec3d1c70fc15b57093382a[WEB]