Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-65662

Update the dependency "go-jose/go-jose" to fix CVE-2025-27144

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • None
    • 4.17.z
    • oc
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Low
    • None
    • None
    • None
    • In Progress
    • Release Note Not Required
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Hello, this is a request to fix the `github.com/go-jose/go-jose` dependency in the oc binary.
      
      The scanner reports the CVE [1] due to the dependency.
      The fixed version should be v4/4.0.5 or newer, v3/3.0.4 or newer. [2]
      
      [1] - https://access.redhat.com/security/cve/cve-2025-27144
      [2] - https://github.com/go-jose/go-jose/security/advisories/GHSA-c6gw-w398-hv78 

      Version-Release number of selected component (if applicable):

      OpenShift Container Platform 4.16

              aguclu@redhat.com Arda Guclu
              rhn-support-vwalek Vladislav Walek
              None
              None
              Ying Zhou Ying Zhou
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: