Skip to content

Critical CVEs found when scanning latest image #7541

@MalteHei

Description

@MalteHei

When scanning the latest version of the code-server image, our scanner found two critical CVEs:

  • Image: ghcr.io/coder/code-server:4.105.1 (digest: sha256:2d48970bd2084aa34a522d772b6a437981ea80407465b3bf7958553985c570e1)
  • Scanner: Trivy v0.58.2
  • Critical CVEs:
    • CVE-2023-45853 in version 1:1.2.13.dfsg-1 of package zlib1g
    • CVE-2024-24790 in version v1.20.7 of package stdlib (fixed in versions 1.21.11, 1.22.4)

CVE-2024-24790 seems to be contained in every image flavour, not just debian

Due to our security policy, these CVEs block us from deploying code-server in our environment.
Is there any chance of updating these dependencies? (Or are they false-positives?)

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingenhancementSome improvement that isn't a featureneeds-investigationThis issue needs to be further investigatedsecuritySecurity related

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions