You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It appears that mitigating the recent http2 vulnerabilities (see
CVE-2023-44487 and CVE-2023-39325) requires [more than just a library
update to golang.org/x/net][1]. Until better mitigations have been
developed, disable http2 in both the metrics and webhooks servers.
[1]: kubernetes/kubernetes#121197
Signed-off-by: Andy Sadler <[email protected]>
0 commit comments