Backport candidate: CVE-2025-13888 fix not present on v1.13 branch
メンテナーはふだん 2 日以内に返信
まだ誰も着手していません。
評価
調査の方向性
まず、v1.13 ブランチがまだサポートされているか確認してください。サポートされている場合は、v1.13 の controllers/argocd_metrics_controller.go を調査し、PR #897 のコミット bc6ac3e0 と比較してください。完了の条件は、namespace-isolation fix が v1.13 に存在すること、または同等のバックポートが提供されていることです。ブランチが EOL の場合は、代わりにそのステータスを記録してください。
索引モデルが issue の本文から書いたものです。
説明
Hi maintainers,
While auditing supported branches for CVE backports, I noticed that the fix for CVE-2025-13888 (PR #897, commit bc6ac3e0, "fix CVE namespace-isolation break") does not appear to be present on the v1.13 branch.
What I checked
- The
v1.13branch HEAD does not contain the new symbols introduced by the fix:userDefinedMonitoringLabelconstant — not present incontrollers/argocd_metrics_controller.goonv1.13openshift.io/user-monitoringlabel literal — not presentstrings.HasPrefix(namespace.Name, "openshift-")guard — not present
- The pre-fix code path (
namespace.Labels[clusterMonitoringLabel] = "true"unconditional) is still present. git compare v1.13...bc6ac3e0reports the branch is 16 commits behind the fix commit and the fix is not in the merged set.
Why this matters
Without the openshift- prefix guard, the operator may add the cluster-monitoring label to namespaces it shouldn't, which is the namespace-isolation issue described in the advisory. If v1.13 is still a supported maintenance branch, a cherry-pick of bc6ac3e0 (or an equivalent fix) would close that gap.
If v1.13 is no longer supported / EOL, please feel free to close — happy to know either way.
Thanks for your work on this project.
— @vulgraph
- 主要言語
- Go
- スター
- 188
- フォーク
- 362
- 平均マージ
- 5日 4時間
- マージ済み PR(30日)
- 27
環境構築
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
redhat-developer/gitops-operator のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
redhat-developer/gitops-operator#1350 ·
メンテナーはふだん 2 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 86/100
redhat-developer/gitops-operator#1287 ·
メンテナーはふだん 2 日以内に返信
-
Secret-looking text in log output, ci logs redacted対応中かも @olivergondza が 5 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 45/100
redhat-developer/gitops-operator#1311 ·
メンテナーはふだん 2 日以内に返信
-
Harden OpenShift manual-install SCC troubleshooting guidance対応中かも @olivergondza が 25 日前に担当しました。 オープン
redhat-developer/gitops-operator#1295 · 担当者 1 名 ·
メンテナーはふだん 2 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
redhat-developer/gitops-operator#634 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
redhat-developer/gitops-operator の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
prime-radiant-inc/evener#4223 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
open-telemetry/opentelemetry-go-compile-instrumentation#1467 ·
メンテナーはふだん 3 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
yetone/magpie#1490 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
modelcontextprotocol/go-sdk#1367 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信