[Question] CVE vulnerabilities present in v1.33.2
- Dominant language
- TypeScript
- Stars
- 2.1k
- Forks
- 395
- Avg merge
- 2d 22h
- Merged PRs (30d)
- 13
Description
**Describe scenario**
We have an AKS cluster running v1.33.2
We're running a few managed add-ons / extensions:
- Flux
- app-routing
- cilium
**Question**
Microsoft Defender reports a few CVE vulnerabilities in containers that are related to the managed add-ons / extensions, is this normal?
Examples:
/subscriptions/* * * /securityentitydata/namespace-kube-system-pod-cilium-*-container-cilium-agent (CVE-2024-45337)
/subscriptions/* * * /securityentitydata/namespace-flux-system-pod-fluxconfig-agent-*-*-container-fluent-bit (CVE-2025-53547)
/subscriptions/* * * /securityentitydata/namespace-flux-system-pod-fluxconfig-controller-*-*-container-manager (CVE-2025-53547)
/subscriptions/* * * /securityentitydata/namespace-flux-system-pod-fluxconfig-agent-*-*-container-fluxconfig-agent (CVE-2025-53547)
/subscriptions/* * * /securityentitydata/namespace-app-routing-system-pod-external-dns-*-*-container-controller (CVE-2024-45337)
Is this normal / expected ?
Contributor guide
Assessment
This issue has not been assessed yet.