Overview
About vulnerability
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.Details
- Affected product:
- argocd , argoproj/gitops-engine , kubernetes/kubernetes
- Affected packages:
- k8s.io/kubernetes @ 1.32.2 (+2 more)