Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities on this image #64

Closed
jribmartins opened this issue Oct 10, 2023 · 1 comment
Closed

Vulnerabilities on this image #64

jribmartins opened this issue Oct 10, 2023 · 1 comment

Comments

@jribmartins
Copy link

This image has some high vulnerabilities:

  • CVE-2023-38039 (alpine version should be update)
    The library github.com/docker/docker version 23.0.1+incompatible was detected in Golang binary located at /usr/bin/helm and is vulnerable to CVE-2023-28840, which exists in versions >= 23.0.0, < 23.0.3.
  • CVE-2023-28840 (helm version should be updated)
    The package curl version 8.2.1-r0 was detected in APK package manager on a container image running Alpine 3.18.3 is vulnerable to CVE-2023-38039, which exists in versions < 8.3.0-r0.
ozbillwang pushed a commit that referenced this issue Oct 10, 2023
@ozbillwang
Copy link
Collaborator

ozbillwang commented Oct 10, 2023

I guess you run the test on current latest versions, right?

1.28.2 1.27.6 1.26.9 1.25.14

I run with trivy scan, but get different result

image

Ref logs: https://app.circleci.com/pipelines/github/alpine-docker/k8s/610/workflows/58236c5c-e300-4034-946b-f79a980ca6ff/jobs/616

ozbillwang pushed a commit that referenced this issue Oct 10, 2023
ozbillwang pushed a commit that referenced this issue Oct 10, 2023
ozbillwang pushed a commit that referenced this issue Oct 10, 2023
ozbillwang pushed a commit that referenced this issue Oct 10, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants