Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address major CVE with openstorage/stork image #1185

Open
ameer2rock opened this issue Oct 12, 2022 · 1 comment
Open

Address major CVE with openstorage/stork image #1185

ameer2rock opened this issue Oct 12, 2022 · 1 comment

Comments

@ameer2rock
Copy link

Is this a BUG REPORT or FEATURE REQUEST?:
Security Vulnerabilities
What happened:
openstorage/stork image found major and moderate security vulnerabilities
What you expected to happen:
Image to not have vulnerabilities
How to reproduce it (as minimally and precisely as possible):
Scanned image openstorage/stork:2.9.0 with aquasec security scanner and found vulnerabilities for:
CVE-2022-1292 (major, OpenSSL)
CVE-2022-27772 (moderate, curl)

Anything else we need to know?:
The most current version of stork (2.11.3) has the same software installed and gets flagged by image scanner.
OpenSSL version 1.1.1k
Curl version: 7.61.1

Environment:

  • Kubernetes version (use kubectl version): 1.22.7
  • Cloud provider or hardware configuration: internally hosted
  • OS (e.g. from /etc/os-release): Ubuntu 20.04
  • Kernel (e.g. uname -a): 5.4.0.104-generic
  • Install tools: na
  • Others:
@dvasilen
Copy link

Note that the openstorage/stork image 2.11.4 is also vulnerable to

CVE-2022-40674     Active          expat               Upgrade expat to >= 2.2.5-8.el8_6.3

This is a critical security vulnerability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants