-
Notifications
You must be signed in to change notification settings - Fork 1.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerability report on dependency: com.squareup.okhttp3/logging-interceptor #6344
Comments
Fabric8 Kubernetes Client 7.0.0 will no longer depend on OkHttp 3.x: #5778 For previous versions, you should be able to override the OkHttp client version dependency in your pom.xml: https://github.com/fabric8io/kubernetes-client/blob/main/doc/KubernetesClientWithIPv6Clusters.md Or using a different HttpClient implementation: However, I'm not sure which of these options work better with spring-cloud-kubernetes. Hopefully, v7 will be released soon though. |
hello Marc! We will be integrating 7.0.0 when that is available, but not sooner then our |
This issue has been automatically marked as stale because it has not had any activity since 90 days. It will be closed if no further activity occurs within 7 days. Thank you for your contributions! |
Version 7.x is now available with no OkHttp mandatory dependencies. https://github.com/fabric8io/kubernetes-client/releases/tag/v7.0.1 |
Describe the bug
We have received a notification for a vulnerability in our project using
kubernetes-client:jar:6.9.2
. Details follow.Vulnerabilities in: pkg:maven/com.squareup.okhttp3/[email protected] [CVE-2023-0833] (owasp)
currently there is not released version from
io.fabric8:kubernetes-client
with fixes on the reported dependency.kubernetes-client/pom.xml
Line 94 in 32b3473
Fabric8 Kubernetes Client version
SNAPSHOT
Steps to reproduce
Have the
kubernetes-client
dependency and run a SBOM vulnerability scan.Expected behavior
Depend on a
com.squareup.okhttp3:logging-interceptor
version with the vulnerability fixed.Runtime
Kubernetes (vanilla)
Kubernetes API Server version
1.25.3@latest
Environment
Linux
Fabric8 Kubernetes Client Logs
No response
Additional context
No response
The text was updated successfully, but these errors were encountered: