Backport candidate: CVE-2025-13888 fix not present on v1.13 branch
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 3/5
- Geschätzter Aufwand
- 1-2 Tage
- Anfängerfreundlichkeit
- 52/100
Rechercherichtung
Prüfe zuerst, ob der v1.13-Branch noch unterstützt wird. Falls ja, untersuche controllers/argocd_metrics_controller.go in v1.13 und vergleiche ihn mit Commit bc6ac3e0 aus PR #897; abgeschlossen bedeutet, dass der namespace-isolation-Fix in v1.13 vorhanden ist oder ein gleichwertiger Backport bereitgestellt wird. Falls der Branch EOL ist, dokumentiere stattdessen diesen Status.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Hi maintainers,
While auditing supported branches for CVE backports, I noticed that the fix for CVE-2025-13888 (PR #897, commit bc6ac3e0, "fix CVE namespace-isolation break") does not appear to be present on the v1.13 branch.
What I checked
- The
v1.13branch HEAD does not contain the new symbols introduced by the fix:userDefinedMonitoringLabelconstant — not present incontrollers/argocd_metrics_controller.goonv1.13openshift.io/user-monitoringlabel literal — not presentstrings.HasPrefix(namespace.Name, "openshift-")guard — not present
- The pre-fix code path (
namespace.Labels[clusterMonitoringLabel] = "true"unconditional) is still present. git compare v1.13...bc6ac3e0reports the branch is 16 commits behind the fix commit and the fix is not in the merged set.
Why this matters
Without the openshift- prefix guard, the operator may add the cluster-monitoring label to namespaces it shouldn't, which is the namespace-isolation issue described in the advisory. If v1.13 is still a supported maintenance branch, a cherry-pick of bc6ac3e0 (or an equivalent fix) would close that gap.
If v1.13 is no longer supported / EOL, please feel free to close — happy to know either way.
Thanks for your work on this project.
— @vulgraph
- Vorherrschende Sprache
- Go
- Sterne
- 188
- Forks
- 359
- Ø Merge
- 4 T. 6 Std.
- Gemergte PRs (30 T.)
- 27
Entwicklungsumgebung
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus redhat-developer/gitops-operator
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 86/100
redhat-developer/gitops-operator#1287 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 45/100
redhat-developer/gitops-operator#1311 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Harden OpenShift manual-install SCC troubleshooting guidanceEvtl. vergeben @olivergondza hat das vor 15 Tagen übernommen. Offen
redhat-developer/gitops-operator#1295 · 1 zugewiesene Person ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 35/100
redhat-developer/gitops-operator#634 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
triage:required
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 48/100
redhat-developer/gitops-operator#572 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in redhat-developer/gitops-operator
Ähnliche Issues
-
[Docs] - Document minimum Terraform/OpenTofu version (>= 1.11) required by write-only argumentsOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 92/100
MagaluCloud/terraform-provider-mgc#323 ·
Maintainer antworten meist innerhalb von 11 Tagen
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
rossoctl/context-guru#366 ·
Maintainer antworten meist innerhalb von 1 Tag
-
stage-fail
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
siyuan-note/bazaar#2293 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
piraeusdatastore/piraeus-operator#1070 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
Maintainer antworten meist innerhalb von 1 Tag