Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerabilities with version 3.5.5 #75

Closed
ravisharda opened this issue Aug 21, 2019 · 3 comments
Closed

Security vulnerabilities with version 3.5.5 #75

ravisharda opened this issue Aug 21, 2019 · 3 comments

Comments

@ravisharda
Copy link

ravisharda commented Aug 21, 2019

Expected behavior

Vulnerability scans of container image should not report critical/high severity security vulnerabilities.

Actual behavior

  1. Image scans using Blackduck reported several critical and high severity security vulnerabilities for version 3.5.5 of the image.

    Please let me know how to share the report with you. I can generate a csv file, and send it to an email if that'd work. Alternatively, I can share the report here.

  2. The scan report (https://hub.docker.com/_/zookeeper/scans/library/zookeeper/3.5.5) available in Docker hub for the image, also shows several critical/high severity vulnerabilities. (Note: the user must be logged in to Docker Hub to be able to see the report).

Steps to reproduce the behavior

Not applicable.

System configuration

Not applicable.

@31z4
Copy link
Owner

31z4 commented Aug 21, 2019

Unfortunately 9 out of 10 vulnerable components come from openjdk:8-jre-slim base image: https://hub.docker.com/_/openjdk/scans/library/openjdk/8-jre-slim. And another one is jackson-databind 2.9.8 which is a part of apache-zookeeper-3.5.5-bin distribution.

I can only suggest to report these issues upstream.

@ravisharda
Copy link
Author

Thanks for your prompt response!

An issue was reported for upstream docker-library/openjdk#349, as suggested.

I'm closing this issue.

@Prabhaker24
Copy link

I have reported the issues to openjdk:8-jre-slim and they came back and said that they have fixed some issues and some are a false positive. Does 31z4/zookeeper-docker uses the latest image, I have given the link to the git hub issue link of openjdk:8-jre-slim that I raised you can go through it.

docker-library/openjdk#349

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants
@31z4 @ravisharda @Prabhaker24 and others