{"api_version":"v1","generated_at":"2026-10-09T13:45:00+00:00","product":{"cve_count":6,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-fluxcd-flux2-ea47562a5d85","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/flux","name":"flux2","next_cursor":null,"observations":[{"affected":"< 0.35.0","affected_versions_present":true,"cve_id":"CVE-2022-39272","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-39272","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T16:45:22.608Z","patch_url":"https://github.com/kubernetes/apimachinery/issues/131","primary_source":"","published":"2022-10-21T00:00:00.000Z"},{"affected":">= 0.0.4, < 0.23.0; >= 0.0.17, < 0.32.0","affected_versions_present":true,"cve_id":"CVE-2022-36049","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-36049","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T17:14:00.853Z","patch_url":"","primary_source":"","published":"2022-09-07T20:15:13.000Z"},{"affected":"< 0.32.0, >= 0.21.0","affected_versions_present":true,"cve_id":"CVE-2022-36035","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-36035","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T17:47:18.679Z","patch_url":"https://github.com/fluxcd/flux2/security/advisories/GHSA-xwf3-6rgv-939r","primary_source":"","published":"2022-08-31T14:55:09.000Z"},{"affected":"flux2 < v0.28.5, >= v0.19.0; kustomize < v0.29.0, >= v0.16.0","affected_versions_present":true,"cve_id":"CVE-2022-24878","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24878","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T18:29:31.214Z","patch_url":"","primary_source":"","published":"2022-05-06T01:35:08.000Z"},{"affected":"flux2 < v0.29.0; kustomize-controller < v0.24.0","affected_versions_present":true,"cve_id":"CVE-2022-24877","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24877","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T18:29:38.832Z","patch_url":"","primary_source":"","published":"2022-05-06T01:10:09.000Z"},{"affected":"flux2 < v0.29.0 >= v0.1.0; helm-controller < v0.23.0 >= v0.1.0; kustomize-controller < v0.19.0 >= v0.2.0","affected_versions_present":true,"cve_id":"CVE-2022-24817","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24817","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:29:46.822Z","patch_url":"https://github.com/fluxcd/flux2/security/advisories/GHSA-vvmq-fwmg-2gjc","primary_source":"","published":"2022-05-06T00:00:14.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"fluxcd"}}
