Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Docker Container Image Vulnerability - CVE-2023-44487 #484

Closed
rlindner5 opened this issue Mar 5, 2024 · 3 comments
Closed

Docker Container Image Vulnerability - CVE-2023-44487 #484

rlindner5 opened this issue Mar 5, 2024 · 3 comments

Comments

@rlindner5
Copy link

rlindner5 commented Mar 5, 2024

Is this a BUG REPORT or FEATURE REQUEST?

Choose one: BUG REPORT

What happened: Docker container is showing a high vulnerability using Cisco Vulnerability Management scanning tool. This is NOT a duplicate of #380 as this vulnerability is not included in that bug report, which is now almost 3 years old.

CVE Library Version Severity Fixed By Path


CVE-2023-44487 golang.org/x/net v0.7.0 High v0.17.0 /usr/local/bin/chaos-operator

CVE-2023-44487

What you expected to happen: Scanning jobs for production level containers should not have high vulnerabilities when using the latest image.

How to reproduce it (as minimally and precisely as possible): Used the Cisco Vulnerability Management scanning tool https://www.cisco.com/site/us/en/products/security/vulnerability-management/index.html

@Nageshbansal
Copy link
Contributor

Thanks @rlindner5 for reporting the issue. We're already working on it

@neelanjan00
Copy link
Member

@Nageshbansal please feel free to take it up. I have assigned it to you. Do let me know if you have any questions.

@rlindner5
Copy link
Author

This vulnerability is no longer showing up in scans as of the 3.5.0 image. Thanks for addressing this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants