-
Bug
-
Resolution: Unresolved
-
Normal
-
None
-
4.17.0
-
None
-
Quality / Stability / Reliability
-
False
-
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
Critical CVE in the base image for the Addon catalog: Fixable CVE-2024-41110 (CVSS 9.9) (severity Critical) found in component 'github.com/docker/docker' (version v24.0.7+incompatible) in container 'registry-server', resolved by version 25.0.6 Example image catalog: quay.io/osd-addons/acs-fleetshard-index@sha256:e271ff1c9434ef32d291cdbb7f2fbf0ecabc67784491ed0dd98703d32486a450
Version-Release number of selected component (if applicable):
How reproducible:
Use managed bundles https://gitlab.cee.redhat.com/service/managed-tenants-bundles
Steps to Reproduce:
1. Use managed bundles (Addon flow) on the cluster 2. It will install the catalog for the addon 3. The catalog container will have CVE
Actual results:
The managed bundles deploys a container with CVE
Expected results:
No CVE from managed bundles infra containers
Additional info: