Loading
Loading articles
By Kubernetes Team
AI summary
The Kubernetes Security Response Committee is updating several historical CVE records to accurately reflect that they remain unfixed due to inherent architectural design trade-offs. By removing incorrect 'fixed version' fields, the project aims to improve the fidelity of vulnerability scanners and ensure administrators correctly identify and mitigate these risks. These changes formalize the status of vulnerabilities like CVE-2020-8561 and CVE-2021-25740 as permanent architectural considerations.
Key points