Search:
Image | Release | Binary/Package | Dependency | Vulnerability ID (CVE) | Severity | Status | Justification (for status not affected) | Type (language or OS) |
---|---|---|---|---|---|---|---|---|
rancher/k3s:v1.30.14-k3s1 | K3s v1.30.14 | bin/k3s | go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.45.0 | CVE-2023-47108 | HIGH | affected | gobinary | |
rancher/klipper-helm:v0.9.7-build20250616 | K3s v1.30.14 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | helm.sh/helm/v3@v3.18.3 | CVE-2025-53547 | HIGH | affected | gobinary | |
rancher/k3s:v1.30.14-k3s1 | K3s v1.30.14 | bin/containerd-shim-runc-v2 | golang.org/x/net@v0.33.0 | CVE-2025-22870 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/k3s:v1.30.14-k3s1 | K3s v1.30.14 | bin/containerd-shim-runc-v2 | golang.org/x/net@v0.33.0 | CVE-2025-22872 | none | not affected | vulnerable code not present | gobinary |
rancher/k3s:v1.30.14-k3s1 | K3s v1.30.14 | bin/k3s | github.com/pion/interceptor@v0.1.37 | CVE-2025-49140 | none | not affected | vulnerable code not present | gobinary |
rancher/k3s:v1.30.14-k3s1 | K3s v1.30.14 | bin/k3s | golang.org/x/crypto@v0.17.0 | CVE-2024-45337 | none | not affected | vulnerable code not present | gobinary |
rancher/k3s:v1.30.14-k3s1 | K3s v1.30.14 | bin/k3s | golang.org/x/crypto@v0.17.0 | CVE-2025-22869 | none | not affected | vulnerable code not present | gobinary |
rancher/k3s:v1.30.14-k3s1 | K3s v1.30.14 | bin/k3s | gopkg.in/square/go-jose.v2@v2.6.0 | CVE-2024-28180 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/klipper-helm:v0.9.7-build20250616 | K3s v1.30.14 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | helm.sh/helm/v3@v3.18.3 | CVE-2025-53547 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/local-path-provisioner:v0.0.31 | K3s v1.30.14 | libcrypto3 | libcrypto3@3.3.2-r4 | CVE-2024-12797 | none | not affected | vulnerable code cannot be controlled by adversary | alpine |
rancher/local-path-provisioner:v0.0.31 | K3s v1.30.14 | libssl3 | libssl3@3.3.2-r4 | CVE-2024-12797 | none | not affected | vulnerable code cannot be controlled by adversary | alpine |
rancher/local-path-provisioner:v0.0.31 | K3s v1.30.14 | usr/bin/local-path-provisioner | golang.org/x/net@v0.34.0 | CVE-2025-22870 | none | not affected | vulnerable code not present | gobinary |
rancher/local-path-provisioner:v0.0.31 | K3s v1.30.14 | usr/bin/local-path-provisioner | golang.org/x/net@v0.34.0 | CVE-2025-22872 | none | not affected | vulnerable code not present | gobinary |
rancher/local-path-provisioner:v0.0.31 | K3s v1.30.14 | usr/bin/local-path-provisioner | golang.org/x/oauth2@v0.25.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |