Fix snyk vuln in golang.org/x/net/http2#2271
Fix snyk vuln in golang.org/x/net/http2#2271openshift-merge-bot[bot] merged 1 commit intoopenshift:mce-2.4from
Conversation
✗ High severity vulnerability found in golang.org/x/net/http2 Description: Allocation of Resources Without Limits or Throttling Info: https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXNETHTTP2-6531285 Introduced through: k8s.io/apimachinery/pkg/util/net@0.29.2, k8s.io/client-go/rest@0.29.1, k8s.io/client-go/tools/cache@0.29.1, k8s.io/apimachinery/pkg/watch@0.29.2, github.com/openshift/generic-admission-server/pkg/cmd@#8dcc3c9b298f, k8s.io/client-go/discovery/cached/disk@0.29.1, k8s.io/client-go/plugin/pkg/client/auth/gcp@0.29.1, k8s.io/client-go/discovery@0.29.1, k8s.io/client-go/dynamic@0.29.1, k8s.io/kube-aggregator/pkg/client/clientset_generated/clientset/typed/apiregistration/v1@0.29.1, k8s.io/client-go/tools/record@0.29.1, k8s.io/client-go/tools/leaderelection/resourcelock@0.29.1, k8s.io/client-go/tools/clientcmd@0.29.1, google.golang.org/api/cloudresourcemanager/v1@0.167.0, google.golang.org/api/compute/v1@0.167.0, google.golang.org/api/dns/v1@0.167.0, google.golang.org/api/serviceusage/v1@0.167.0, k8s.io/client-go/informers@0.29.1, k8s.io/client-go/listers/core/v1@0.29.1, k8s.io/client-go/tools/watch@0.29.1, k8s.io/apimachinery/pkg/apis/meta/v1@0.29.2, k8s.io/cli-runtime/pkg/printers@0.29.2, google.golang.org/api/option@0.167.0, k8s.io/cli-runtime/pkg/genericclioptions@0.29.2, k8s.io/client-go/restmapper@0.29.1, k8s.io/kubectl/pkg/util/openapi@0.29.1, k8s.io/client-go/tools/leaderelection@0.29.1, sigs.k8s.io/controller-runtime/pkg/client/config@0.17.2, github.com/openshift/installer/pkg/asset/machines/gcp@#304af6735c65, github.com/openshift/installer/pkg/destroy/gcp@#304af6735c65, github.com/heptio/velero/pkg/apis/velero/v1@1.0.0, k8s.io/api/rbac/v1@0.29.2, github.com/openshift/api/authorization/v1@#ce10821dc999, github.com/openshift/api/image/v1@#ce10821dc999, github.com/openshift/api/machine/v1alpha1@#ce10821dc999, github.com/openshift/cluster-control-plane-machine-set-operator/pkg/machineproviders/providers/openshift/machine/v1beta1/providerconfig@#d141fa11b2e9, k8s.io/api/admission/v1beta1@0.29.2, k8s.io/apimachinery/pkg/apis/meta/v1/unstructured@0.29.2, k8s.io/api/admissionregistration/v1@0.29.2, k8s.io/api/batch/v1@0.29.2, k8s.io/api/certificates/v1@0.29.2, github.com/openshift/hive/apis/hivecontracts/v1alpha1@0.0.0, github.com/openshift/hive/apis/hiveinternal/v1alpha1@0.0.0, github.com/openshift/installer/pkg/asset/machines/ibmcloud@#304af6735c65, github.com/openshift/installer/pkg/asset/machines/ovirt@#304af6735c65, k8s.io/cluster-registry/pkg/apis/clusterregistry/v1alpha1@0.0.6, github.com/openshift/api/apps/v1@#ce10821dc999, github.com/openshift/api/route/v1@#ce10821dc999, k8s.io/api/apps/v1@0.29.2, github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring/v1@0.50.0, k8s.io/api/core/v1@0.29.2, k8s.io/apimachinery/pkg/api/meta@0.29.2, github.com/openshift/custom-resource-status/conditions/v1@#f2fdb4999d87, github.com/openshift/hive/apis/hive/v1/metricsconfig@0.0.0, github.com/openshift/installer/pkg/types@#304af6735c65, github.com/openshift/library-go/pkg/controller@#126b47137408, k8s.io/apimachinery/pkg/api/errors@0.29.2, k8s.io/apimachinery/pkg/apis/meta/v1/validation@0.29.2, k8s.io/apimachinery/pkg/api/equality@0.29.2, k8s.io/cli-runtime/pkg/resource@0.29.2, sigs.k8s.io/controller-runtime/pkg/client/apiutil@0.17.2, k8s.io/kubectl/pkg/polymorphichelpers@0.29.1, sigs.k8s.io/controller-runtime/pkg/metrics@0.17.2, github.com/openshift/hive/apis/hive/v1@0.0.0, github.com/openshift/cluster-api-provider-ovirt/pkg/apis/ovirtprovider/v1beta1@#e3f2850dd519, github.com/openshift/cluster-autoscaler-operator/pkg/apis/autoscaling/v1@#fe524080b551, github.com/openshift/cluster-autoscaler-operator/pkg/apis/autoscaling/v1beta1@#fe524080b551, sigs.k8s.io/controller-runtime/pkg/webhook/admission@0.17.2, github.com/openshift/library-go/pkg/operator/resource/resourcemerge@#126b47137408, github.com/openshift/library-go/pkg/verify@#126b47137408, github.com/openshift/hive/apis@0.0.0, github.com/openshift/library-go/pkg/operator/resource/resourceread@#126b47137408, k8s.io/kube-aggregator/pkg/apis/apiregistration/v1@0.29.1, github.com/openshift/api/config/v1@#ce10821dc999, github.com/openshift/hive/apis/hive/v1/aws@0.0.0, github.com/openshift/hive/apis/hive/v1/azure@0.0.0, github.com/openshift/hive/apis/hive/v1/gcp@0.0.0, github.com/openshift/hive/apis/hive/v1/ibmcloud@0.0.0, github.com/openshift/hive/apis/hive/v1/openstack@0.0.0, github.com/openshift/hive/apis/hive/v1/ovirt@0.0.0, github.com/openshift/hive/apis/hive/v1/vsphere@0.0.0, github.com/openshift/api/machine/v1beta1@#ce10821dc999, github.com/openshift/installer/pkg/destroy/azure@#304af6735c65, github.com/openshift/installer/pkg/destroy/vsphere@#304af6735c65, github.com/openshift/installer/pkg/destroy/providers@#304af6735c65, github.com/openshift/installer/pkg/destroy/ovirt@#304af6735c65, k8s.io/client-go/util/retry@0.29.1, k8s.io/apimachinery/pkg/api/validation@0.29.2, k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1@0.29.2, sigs.k8s.io/controller-runtime/pkg/client@0.17.2, sigs.k8s.io/controller-runtime/pkg/cache@0.17.2, sigs.k8s.io/controller-runtime/pkg/controller/controllerutil@0.17.2, k8s.io/kubectl/pkg/cmd/apply@0.29.1, k8s.io/kubectl/pkg/cmd/util@0.29.1, sigs.k8s.io/controller-runtime/pkg/metrics/server@0.17.2, github.com/openshift/cluster-api-provider-ovirt/pkg/apis@#e3f2850dd519, sigs.k8s.io/controller-runtime/pkg/config@0.17.2, k8s.io/apimachinery/pkg/runtime/serializer@0.29.2, github.com/openshift/api/operator/v1@#ce10821dc999, github.com/openshift/installer/pkg/types/aws@#304af6735c65, github.com/openshift/installer/pkg/types/ibmcloud@#304af6735c65, github.com/openshift/installer/pkg/types/openstack@#304af6735c65, github.com/openshift/installer/pkg/types/ovirt@#304af6735c65, github.com/openshift/installer/pkg/types/vsphere@#304af6735c65, github.com/openshift/installer/pkg/destroy/aws@#304af6735c65, github.com/openshift/installer/pkg/destroy/ibmcloud@#304af6735c65, k8s.io/kubectl/pkg/cmd/delete@0.29.1, github.com/openshift/installer/pkg/asset/machines/aws@#304af6735c65, github.com/openshift/installer/pkg/asset/machines/azure@#304af6735c65, github.com/openshift/installer/pkg/asset/machines/openstack@#304af6735c65, sigs.k8s.io/controller-runtime/pkg/client/fake@0.17.2, k8s.io/kubectl/pkg/cmd/patch@0.29.1, sigs.k8s.io/controller-runtime/pkg/reconcile@0.17.2, sigs.k8s.io/controller-runtime/pkg/event@0.17.2, github.com/openshift/machine-api-operator/pkg/controller/vsphere@#2cc7fcf262f3, k8s.io/client-go/kubernetes@0.29.1, sigs.k8s.io/controller-runtime/pkg/webhook@0.17.2, github.com/openshift/installer/pkg/asset/machines/vsphere@#304af6735c65, github.com/openshift/installer/pkg/asset/installconfig/aws@#304af6735c65, github.com/openshift/installer/pkg/destroy/openstack@#304af6735c65, sigs.k8s.io/controller-runtime/pkg/predicate@0.17.2, github.com/openshift/machine-api-provider-gcp/pkg/apis/gcpprovider/v1beta1@#6096cc86f3ba, sigs.k8s.io/controller-runtime/pkg/handler@0.17.2, sigs.k8s.io/controller-runtime/pkg/manager@0.17.2, github.com/openshift/library-go/pkg/manifest@#126b47137408, github.com/openshift/library-go/pkg/verify/store/sigstore@#126b47137408, sigs.k8s.io/controller-runtime/pkg/controller@0.17.2, sigs.k8s.io/controller-runtime/pkg/source@0.17.2 From: k8s.io/apimachinery/pkg/util/net@0.29.2 > golang.org/x/net/http2@0.22.0 From: k8s.io/client-go/rest@0.29.1 > golang.org/x/net/http2@0.22.0 From: k8s.io/client-go/tools/cache@0.29.1 > k8s.io/apimachinery/pkg/util/net@0.29.2 > golang.org/x/net/http2@0.22.0 and 211 more... Fixed in: 0.23.0
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: 2uasimojo, suhanime The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
@2uasimojo: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## mce-2.4 #2271 +/- ##
========================================
Coverage 57.58% 57.58%
========================================
Files 187 187
Lines 25837 25837
========================================
Hits 14878 14878
Misses 9711 9711
Partials 1248 1248 |
✗ High severity vulnerability found in golang.org/x/net/http2
Description: Allocation of Resources Without Limits or Throttling
Info: https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXNETHTTP2-6531285
Introduced through: k8s.io/apimachinery/pkg/util/net@0.29.2, k8s.io/client-go/rest@0.29.1, k8s.io/client-go/tools/cache@0.29.1, k8s.io/apimachinery/pkg/watch@0.29.2, github.com/openshift/generic-admission-server/pkg/cmd@#8dcc3c9b298f, k8s.io/client-go/discovery/cached/disk@0.29.1, k8s.io/client-go/plugin/pkg/client/auth/gcp@0.29.1, k8s.io/client-go/discovery@0.29.1, k8s.io/client-go/dynamic@0.29.1, k8s.io/kube-aggregator/pkg/client/clientset_generated/clientset/typed/apiregistration/v1@0.29.1, k8s.io/client-go/tools/record@0.29.1, k8s.io/client-go/tools/leaderelection/resourcelock@0.29.1, k8s.io/client-go/tools/clientcmd@0.29.1, google.golang.org/api/cloudresourcemanager/v1@0.167.0, google.golang.org/api/compute/v1@0.167.0, google.golang.org/api/dns/v1@0.167.0, google.golang.org/api/serviceusage/v1@0.167.0, k8s.io/client-go/informers@0.29.1, k8s.io/client-go/listers/core/v1@0.29.1, k8s.io/client-go/tools/watch@0.29.1, k8s.io/apimachinery/pkg/apis/meta/v1@0.29.2, k8s.io/cli-runtime/pkg/printers@0.29.2, google.golang.org/api/option@0.167.0, k8s.io/cli-runtime/pkg/genericclioptions@0.29.2, k8s.io/client-go/restmapper@0.29.1, k8s.io/kubectl/pkg/util/openapi@0.29.1, k8s.io/client-go/tools/leaderelection@0.29.1, sigs.k8s.io/controller-runtime/pkg/client/config@0.17.2, github.com/openshift/installer/pkg/asset/machines/gcp@#304af6735c65, github.com/openshift/installer/pkg/destroy/gcp@#304af6735c65, github.com/heptio/velero/pkg/apis/velero/v1@1.0.0, k8s.io/api/rbac/v1@0.29.2, github.com/openshift/api/authorization/v1@#ce10821dc999, github.com/openshift/api/image/v1@#ce10821dc999, github.com/openshift/api/machine/v1alpha1@#ce10821dc999, github.com/openshift/cluster-control-plane-machine-set-operator/pkg/machineproviders/providers/openshift/machine/v1beta1/providerconfig@#d141fa11b2e9, k8s.io/api/admission/v1beta1@0.29.2, k8s.io/apimachinery/pkg/apis/meta/v1/unstructured@0.29.2, k8s.io/api/admissionregistration/v1@0.29.2, k8s.io/api/batch/v1@0.29.2, k8s.io/api/certificates/v1@0.29.2, github.com/openshift/hive/apis/hivecontracts/v1alpha1@0.0.0, github.com/openshift/hive/apis/hiveinternal/v1alpha1@0.0.0, github.com/openshift/installer/pkg/asset/machines/ibmcloud@#304af6735c65, github.com/openshift/installer/pkg/asset/machines/ovirt@#304af6735c65, k8s.io/cluster-registry/pkg/apis/clusterregistry/v1alpha1@0.0.6, github.com/openshift/api/apps/v1@#ce10821dc999, github.com/openshift/api/route/v1@#ce10821dc999, k8s.io/api/apps/v1@0.29.2, github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring/v1@0.50.0, k8s.io/api/core/v1@0.29.2, k8s.io/apimachinery/pkg/api/meta@0.29.2, github.com/openshift/custom-resource-status/conditions/v1@#f2fdb4999d87, github.com/openshift/hive/apis/hive/v1/metricsconfig@0.0.0, github.com/openshift/installer/pkg/types@#304af6735c65, github.com/openshift/library-go/pkg/controller@#126b47137408, k8s.io/apimachinery/pkg/api/errors@0.29.2, k8s.io/apimachinery/pkg/apis/meta/v1/validation@0.29.2, k8s.io/apimachinery/pkg/api/equality@0.29.2, k8s.io/cli-runtime/pkg/resource@0.29.2, sigs.k8s.io/controller-runtime/pkg/client/apiutil@0.17.2, k8s.io/kubectl/pkg/polymorphichelpers@0.29.1, sigs.k8s.io/controller-runtime/pkg/metrics@0.17.2, github.com/openshift/hive/apis/hive/v1@0.0.0, github.com/openshift/cluster-api-provider-ovirt/pkg/apis/ovirtprovider/v1beta1@#e3f2850dd519, github.com/openshift/cluster-autoscaler-operator/pkg/apis/autoscaling/v1@#fe524080b551, github.com/openshift/cluster-autoscaler-operator/pkg/apis/autoscaling/v1beta1@#fe524080b551, sigs.k8s.io/controller-runtime/pkg/webhook/admission@0.17.2, github.com/openshift/library-go/pkg/operator/resource/resourcemerge@#126b47137408, github.com/openshift/library-go/pkg/verify@#126b47137408, github.com/openshift/hive/apis@0.0.0, github.com/openshift/library-go/pkg/operator/resource/resourceread@#126b47137408, k8s.io/kube-aggregator/pkg/apis/apiregistration/v1@0.29.1, github.com/openshift/api/config/v1@#ce10821dc999, github.com/openshift/hive/apis/hive/v1/aws@0.0.0, github.com/openshift/hive/apis/hive/v1/azure@0.0.0, github.com/openshift/hive/apis/hive/v1/gcp@0.0.0, github.com/openshift/hive/apis/hive/v1/ibmcloud@0.0.0, github.com/openshift/hive/apis/hive/v1/openstack@0.0.0, github.com/openshift/hive/apis/hive/v1/ovirt@0.0.0, github.com/openshift/hive/apis/hive/v1/vsphere@0.0.0, github.com/openshift/api/machine/v1beta1@#ce10821dc999, github.com/openshift/installer/pkg/destroy/azure@#304af6735c65, github.com/openshift/installer/pkg/destroy/vsphere@#304af6735c65, github.com/openshift/installer/pkg/destroy/providers@#304af6735c65, github.com/openshift/installer/pkg/destroy/ovirt@#304af6735c65, k8s.io/client-go/util/retry@0.29.1, k8s.io/apimachinery/pkg/api/validation@0.29.2, k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1@0.29.2, sigs.k8s.io/controller-runtime/pkg/client@0.17.2, sigs.k8s.io/controller-runtime/pkg/cache@0.17.2, sigs.k8s.io/controller-runtime/pkg/controller/controllerutil@0.17.2, k8s.io/kubectl/pkg/cmd/apply@0.29.1, k8s.io/kubectl/pkg/cmd/util@0.29.1, sigs.k8s.io/controller-runtime/pkg/metrics/server@0.17.2, github.com/openshift/cluster-api-provider-ovirt/pkg/apis@#e3f2850dd519, sigs.k8s.io/controller-runtime/pkg/config@0.17.2, k8s.io/apimachinery/pkg/runtime/serializer@0.29.2, github.com/openshift/api/operator/v1@#ce10821dc999, github.com/openshift/installer/pkg/types/aws@#304af6735c65, github.com/openshift/installer/pkg/types/ibmcloud@#304af6735c65, github.com/openshift/installer/pkg/types/openstack@#304af6735c65, github.com/openshift/installer/pkg/types/ovirt@#304af6735c65, github.com/openshift/installer/pkg/types/vsphere@#304af6735c65, github.com/openshift/installer/pkg/destroy/aws@#304af6735c65, github.com/openshift/installer/pkg/destroy/ibmcloud@#304af6735c65, k8s.io/kubectl/pkg/cmd/delete@0.29.1, github.com/openshift/installer/pkg/asset/machines/aws@#304af6735c65, github.com/openshift/installer/pkg/asset/machines/azure@#304af6735c65, github.com/openshift/installer/pkg/asset/machines/openstack@#304af6735c65, sigs.k8s.io/controller-runtime/pkg/client/fake@0.17.2, k8s.io/kubectl/pkg/cmd/patch@0.29.1, sigs.k8s.io/controller-runtime/pkg/reconcile@0.17.2, sigs.k8s.io/controller-runtime/pkg/event@0.17.2, github.com/openshift/machine-api-operator/pkg/controller/vsphere@#2cc7fcf262f3, k8s.io/client-go/kubernetes@0.29.1, sigs.k8s.io/controller-runtime/pkg/webhook@0.17.2, github.com/openshift/installer/pkg/asset/machines/vsphere@#304af6735c65, github.com/openshift/installer/pkg/asset/installconfig/aws@#304af6735c65, github.com/openshift/installer/pkg/destroy/openstack@#304af6735c65, sigs.k8s.io/controller-runtime/pkg/predicate@0.17.2, github.com/openshift/machine-api-provider-gcp/pkg/apis/gcpprovider/v1beta1@#6096cc86f3ba, sigs.k8s.io/controller-runtime/pkg/handler@0.17.2, sigs.k8s.io/controller-runtime/pkg/manager@0.17.2, github.com/openshift/library-go/pkg/manifest@#126b47137408, github.com/openshift/library-go/pkg/verify/store/sigstore@#126b47137408, sigs.k8s.io/controller-runtime/pkg/controller@0.17.2, sigs.k8s.io/controller-runtime/pkg/source@0.17.2
From: k8s.io/apimachinery/pkg/util/net@0.29.2 > golang.org/x/net/http2@0.22.0
From: k8s.io/client-go/rest@0.29.1 > golang.org/x/net/http2@0.22.0
From: k8s.io/client-go/tools/cache@0.29.1 > k8s.io/apimachinery/pkg/util/net@0.29.2 > golang.org/x/net/http2@0.22.0
and 211 more...
Fixed in: 0.23.0