Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in libexpat < 2.4.9 CVE-2022-40674 #52

Closed
gvdmarck opened this issue Oct 3, 2022 · 2 comments · Fixed by #53
Closed

Vulnerability in libexpat < 2.4.9 CVE-2022-40674 #52

gvdmarck opened this issue Oct 3, 2022 · 2 comments · Fixed by #53

Comments

@gvdmarck
Copy link

gvdmarck commented Oct 3, 2022

Latest image contains libexpat 2.4.8 which has a critical vulnerability CVE-2022-40674 (pulled as a git dependency).

Would it be possible to re build an image with libexpaxt 2.4.9 ?

ozbillwang pushed a commit that referenced this issue Oct 4, 2022
ozbillwang added a commit that referenced this issue Oct 4, 2022
Co-authored-by: Bill Wang <bill.wang>
@ozbillwang
Copy link
Contributor

ozbillwang commented Oct 4, 2022

thanks to report the issue, I have re-built the image, seems it got latest libexpat. Please confirm.

I also added feature to run trivy scan on the image and generate the report

image

if compare with the old image

image

@gvdmarck
Copy link
Author

gvdmarck commented Oct 5, 2022

Hello Bill,

We just did a rebuild and everything is fine, snyk is happy.

Thank you for the swift reaction!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging a pull request may close this issue.

2 participants