Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities reported by trivy #2058

Closed
martinelli-francesco opened this issue Mar 21, 2023 · 4 comments
Closed

Vulnerabilities reported by trivy #2058

martinelli-francesco opened this issue Mar 21, 2023 · 4 comments
Labels

Comments

@martinelli-francesco
Copy link

Trivy reports many vulnerabilities (even HIGH) on the current stable image. I think most of them are related to the openssl version installed in the base image, so probably just updating the image will fix the problem:

Repository: oauth2-proxy/oauth2-proxy
Tag: v7.4.0
Critical: 0
High: 8
Medium: 3
Low: 0

vulnerabilityID severity resource installedVersion fixedVersion
CVE-2022-4450 HIGH libcrypto1.1 1.1.1q-r0 1.1.1t-r0
CVE-2023-0215 HIGH libcrypto1.1 1.1.1q-r0 1.1.1t-r0
CVE-2023-0286 HIGH libcrypto1.1 1.1.1q-r0 1.1.1t-r0
CVE-2022-4304 MEDIUM libcrypto1.1 1.1.1q-r0 1.1.1t-r0
CVE-2022-4450 HIGH libssl1.1 1.1.1q-r0 1.1.1t-r0
CVE-2023-0215 HIGH libssl1.1 1.1.1q-r0 1.1.1t-r0
CVE-2023-0286 HIGH libssl1.1 1.1.1q-r0 1.1.1t-r0
CVE-2022-4304 MEDIUM libssl1.1 1.1.1q-r0 1.1.1t-r0
CVE-2022-41721 HIGH golang.org/x/net v0.1.0 0.1.1-0.20221104162952-702349b0e862
CVE-2022-41723 HIGH golang.org/x/net v0.1.0 0.7.0
CVE-2022-41717 MEDIUM golang.org/x/net v0.1.0 0.4.0
GHSA-vvpx-j8f3-3w6h UNKNOWN golang.org/x/net v0.1.0 0.7.0

Expected Behavior

At least the high vulnerabilities solved.

@tolleiv
Copy link

tolleiv commented Mar 27, 2023

See also #2013 and #2051

@github-actions
Copy link
Contributor

This issue has been inactive for 60 days. If the issue is still relevant please comment to re-activate the issue. If no action is taken within 7 days, the issue will be marked closed.

@github-actions github-actions bot added the Stale label May 27, 2023
@marcindulak
Copy link

👀

@github-actions github-actions bot removed the Stale label May 28, 2023
@github-actions
Copy link
Contributor

This issue has been inactive for 60 days. If the issue is still relevant please comment to re-activate the issue. If no action is taken within 7 days, the issue will be marked closed.

@github-actions github-actions bot added the Stale label Jul 28, 2023
@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Aug 4, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants