What the vendor says is affected
- azl3 azcopy 10.25.1-4 on Azure Linux 3.0
- azl3 cert-manager 1.12.15-3 on Azure Linux 3.0
- azl3 prometheus 2.45.4-12 on Azure Linux 3.0
- azl3 influxdb 2.7.5-5 on Azure Linux 3.0
- azl3 packer 1.9.5-9 on Azure Linux 3.0
- azl3 containerized-data-importer 1.57.0-14 on Azure Linux 3.0
- cbl2 vitess 17.0.7-8 on CBL Mariner 2.0
- cbl2 azcopy 10.25.1-5 on CBL Mariner 2.0
- cbl2 blobfuse2 2.1.2-8 on CBL Mariner 2.0
- cbl2 coredns 1.11.1-18 on CBL Mariner 2.0
- cbl2 kubernetes 1.28.4-18 on CBL Mariner 2.0
- cbl2 cert-manager 1.11.2-22 on CBL-Mariner 2.0
- cbl2 node-problem-detector 0.8.17-6 on CBL-Mariner 2.0
- cbl2 packer 1.9.5-13 on CBL-Mariner 2.0
- cbl2 azcopy 10.25.1-5 on CBL-Mariner 2.0
- cbl2 coredns 1.11.1-18 on CBL-Mariner 2.0
- cbl2 kubernetes 1.28.4-18 on CBL-Mariner 2.0
- cbl2 telegraf 1.29.4-16 on CBL-Mariner 2.0
- cbl2 telegraf 1.29.4-11 on CBL Mariner 2.0
- cbl2 kubernetes 1.28.4-15 on CBL Mariner 2.0
- cbl2 coredns 1.11.1-14 on CBL Mariner 2.0
- cbl2 moby-engine 24.0.9-15 on CBL Mariner 2.0
- cbl2 azcopy 10.25.1-3 on CBL Mariner 2.0
- cbl2 vitess 17.0.7-5 on CBL Mariner 2.0
Versions the vendor lists as fixed
- 10.25.1-2
- 1.12.15-2
- 2.45.4-8
- 2.7.5-2
- 1.9.5-6
- 1.57.0-13
- 17.0.7-5
- 10.25.1-3
- 2.1.2-8
- 1.11.1-14
- 1.28.4-15
- 1.11.2-20
- 0.8.17-6
- 1.9.5-10
- 1.29.4-11
- 24.0.9-15
- 1.31.0-5
- 1.11.4-3
- 25.0.3-11
- 2.14.1-3
- 19.0.4-5
- 0.8.20-2
- 1.30.10-2
What the vendor recommends
CBL-Mariner Releases
Review the complete instructions on the vendor's siteWhen this advisory changed
- Published by Microsoft Security Response Center
The publication date reported by the vendor.
- Updated by Microsoft Security Response Center
The vendor changed the advisory after it was first published.
- Added to SecurityAlert
We collected the advisory from the official source.
- Confirmed at the source
Our collector saw this advisory during a later source check.