Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Alpine Linux image #479

Closed
fernap3 opened this issue Oct 19, 2023 · 3 comments
Closed

Upgrade Alpine Linux image #479

fernap3 opened this issue Oct 19, 2023 · 3 comments

Comments

@fernap3
Copy link

fernap3 commented Oct 19, 2023

A security scan of the pgHero Docker image turned up CVE-2022-48174 in the version of Alpine Linux being sourced in the latest (v3.4.4) pgHero Docker image. According to this page, that vulnerability is resolved in a more recent version? Admittedly that page is a bit confusing and mentions the vulnerability is both resolved, and unresolved, and also mentions multiple versions of Alpine Linux so I'm not exactly sure what to make of that, lol.

If it's a low effort fix, could you update the pgHero Docker image to pull the latest Alpine Linux image? I'd be happy to make the contribution myself but don't see any dockerfile in the repo to edit.

@ankane
Copy link
Owner

ankane commented Oct 23, 2023

Hi @fernap3, can you share more details about the scan? Are you seeing the same with the latest tag?

@hiddevdm
Copy link

hiddevdm commented Nov 3, 2023

I've also found another vulnerability in a scan: CVE-2023-36617. This seems to be the case for both v3.3.4 and the current latest

NVD CVSSv3 5.3

Installed Resource
uri 0.12.1

Full Path To Resource
/usr/local/lib/ruby/gems/3.1.0/specifications/default/uri-0.12.1.gemspec

Fixed Version
0.12.2

Recommendations
Upgrade package uri to version 0.12.2 or above.

@ankane
Copy link
Owner

ankane commented Nov 28, 2023

Updated the Docker image and uri gem in pghero/pghero@0382b81 (the uri gem may still show up on the scan since that version is bundled with Ruby, but it's not being used).

@ankane ankane closed this as completed Nov 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants