1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["14666"],{951200:function(e,t,i){i.r(t),i.d(t,{frontMatter:()=>d,toc:()=>a,default:()=>o,metadata:()=>s,assets:()=>c,contentTitle:()=>l});var s=JSON.parse('{"id":"security-bulletins/reports/va-ghsa-74fp-r6jw-h4mp","title":"GHSA-74FP-R6JW-H4MP","description":"Lifecycle of GHSA-74FP-R6JW-H4MP","source":"@site/docs/docs-content/security-bulletins/reports/va-ghsa-74fp-r6jw-h4mp.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/va-ghsa-74fp-r6jw-h4mp","permalink":"/security-bulletins/reports/va-ghsa-74fp-r6jw-h4mp","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/va-ghsa-74fp-r6jw-h4mp.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"GHSA-74FP-R6JW-H4MP","title":"GHSA-74FP-R6JW-H4MP","description":"Lifecycle of GHSA-74FP-R6JW-H4MP","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2026-2781","permalink":"/security-bulletins/reports/va-cve-2026-2781"},"next":{"title":"GHSA-M425-MQ94-257G","permalink":"/security-bulletins/reports/va-ghsa-m425-mq94-257g"}}'),r=i(474848),n=i(884429);let d={sidebar_label:"GHSA-74FP-R6JW-H4MP",title:"GHSA-74FP-R6JW-H4MP",description:"Lifecycle of GHSA-74FP-R6JW-H4MP",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},l,c={},a=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function h(e){let t={a:"a",h2:"h2",p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,n.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(t.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,r.jsxs)(t.p,{children:["Visit the official vulnerability details page for ",(0,r.jsx)(t.a,{href:"https://github.com/advisories/ghsa-74fp-r6jw-h4mp",children:"GHSA-74FP-R6JW-H4MP"})," to learn more."]}),"\n",(0,r.jsx)(t.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,r.jsx)(t.p,{children:"10/25/2024"}),"\n",(0,r.jsx)(t.h2,{id:"last-update",children:"Last Update"}),"\n",(0,r.jsx)(t.p,{children:"09/02/2025"}),"\n",(0,r.jsx)(t.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,r.jsx)(t.p,{children:"k8s.io/apimachinery"}),"\n",(0,r.jsx)(t.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,r.jsx)(t.p,{children:"Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing"}),"\n",(0,r.jsx)(t.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,r.jsx)(t.p,{children:(0,r.jsx)(t.a,{href:"https://github.com/advisories/ghsa-74fp-r6jw-h4mp",children:"7.5"})}),"\n",(0,r.jsx)(t.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,r.jsxs)(t.p,{children:["This vulnerability is reported by govulncheck because of the presence of go library, k8s.io/apimachinery (Affected versions: < 0.0.0-20190927203648-9ce6eca90e73). This is a false positive, because it does not affect latest kubernetes versions as indicated here (",(0,r.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/CVE-2019-11253",children:"https://nvd.nist.gov/vuln/detail/CVE-2019-11253"}),"). Current K8s version used: 1.28.11"]}),"\n",(0,r.jsx)(t.h2,{id:"status",children:"Status"}),"\n",(0,r.jsx)(t.p,{children:"Ongoing"}),"\n",(0,r.jsx)(t.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,r.jsxs)(t.table,{children:[(0,r.jsx)(t.thead,{children:(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.th,{children:"Version"}),(0,r.jsx)(t.th,{children:"Palette Enterprise"}),(0,r.jsx)(t.th,{children:"Palette Enterprise Airgap"}),(0,r.jsx)(t.th,{children:"VerteX"}),(0,r.jsx)(t.th,{children:"VerteX Airgap"})]})}),(0,r.jsxs)(t.tbody,{children:[(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.7.16"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u2705 No Impact"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.6.41"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.5.22"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.4.20"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]})]})]}),"\n",(0,r.jsx)(t.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,r.jsxs)(t.table,{children:[(0,r.jsx)(t.thead,{children:(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.th,{children:"Date"}),(0,r.jsx)(t.th,{children:"Revision"})]})}),(0,r.jsxs)(t.tbody,{children:[(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"04/15/2025"}
1),(0,r.jsx)(t.td,{children:"Advisory severity revised to HIGH from"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"04/15/2025"}),(0,r.jsx)(t.td,{children:"Advisory severity revised to from HIGH"})]})]})]})]})}function o(e={}){let{wrapper:t}={...(0,n.R)(),...e.components};return t?(0,r.jsx)(t,{...e,children:(0,r.jsx)(h,{...e})}):h(e)}},884429:function(e,t,i){i.d(t,{R:()=>d,x:()=>l});var s=i(296540);let r={},n=s.createContext(r);function d(e){let t=s.useContext(n);return s.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function l(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:d(e.components),s.createElement(n.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.