-
Notifications
You must be signed in to change notification settings - Fork 386
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Node-red image has security vulnerabilities #431
Comments
They come from the alpine base container, not something we have any influence over. |
I've kicked off a respin of the 3.1.9 containers, they will pick up the latest NodeJS Alpine base contianers. |
@hardillb thanks for the response. |
The builds have been respun |
Unlikely, that looks like a problem with permissions on a volume mounted on |
@hardillb probably some temp issue, works well now. Thanks a lot! |
Hello,
We pull the Node-red image in our project, the Aqua security scan has reported a few vulnerabilities which could be release blocker for us:
[CVE-2024-32465] [git] [2.43.0-r0]
https://nvd.nist.gov/vuln/detail/CVE-2024-32465
Fix Version : 2.43.4-r0
[CVE-2024-32004] [git] [2.43.0-r0]
https://nvd.nist.gov/vuln/detail/CVE-2024-32004
Fix Version : 2.43.4-r0
[CVE-2024-32002] [git] [2.43.0-r0]
https://nvd.nist.gov/vuln/detail/CVE-2024-32002
Fix Version : 2.43.4-r0
The Node-red version we use - v3.1.9-18-minimal
Could you please upgrade this dependency version?
Thanks
The text was updated successfully, but these errors were encountered: