-
Bug
-
Resolution: Unresolved
-
Major
-
None
-
4.16.z
-
Quality / Stability / Reliability
-
False
-
-
None
-
Important
-
None
-
None
-
None
-
None
-
In Progress
-
Release Note Not Required
-
None
-
None
-
None
-
None
-
None
Description of problem:
Hello, this is a request to fix the `github.com/go-jose/go-jose` dependency in the oc binary. The scanner reports the CVE [1] due to the dependency. The fixed version should be v4/4.0.5 or newer, v3/3.0.4 or newer. [2] [1] - https://access.redhat.com/security/cve/cve-2025-27144 [2] - https://github.com/go-jose/go-jose/security/advisories/GHSA-c6gw-w398-hv78
Version-Release number of selected component (if applicable):
OpenShift Container Platform 4.16
- depends on
-
OCPBUGS-65662 Update the dependency "go-jose/go-jose" to fix CVE-2025-27144
-
- Closed
-
- is cloned by
-
OCPBUGS-65662 Update the dependency "go-jose/go-jose" to fix CVE-2025-27144
-
- Closed
-
- links to