Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVEs in openjdk:8-jre-slim #185

Closed
subsahu123 opened this issue Apr 12, 2018 · 1 comment
Closed

CVEs in openjdk:8-jre-slim #185

subsahu123 opened this issue Apr 12, 2018 · 1 comment

Comments

@subsahu123
Copy link

Hi,
We are trying to use solr:7.2-slim image for our project and upon running clair-scanner we found the below High and Medium CVEs against the base openjdk:8-jre-slim image. Any idea if these have already been mitigated or there are updates packages we need to pull.

Regards
Subhankar

High CVE-2017-16997
High CVE-2017-1000408
High CVE-2018-6485
High CVE-2017-14062
High CVE-2018-6551
High CVE-2017-8804
High CVE-2016-2779
High CVE-2017-12424
High CVE-2018-1000001
High CVE-2017-15400
High CVE-2018-6954
Medium CVE-2018-1049
Medium CVE-2018-5729
Medium CVE-2018-7169
Medium CVE-2017-12132
Medium CVE-2017-3738
Medium CVE-2018-5730
Medium CVE-2011-3389
Medium CVE-2018-8740
Medium CVE-2018-5710
Medium CVE-2018-5709
Medium CVE-2016-10228
Medium CVE-2017-1000409
Medium CVE-2018-1000035

#docker-solr/docker-solr#171

@tianon
Copy link
Member

tianon commented Apr 12, 2018

Since we're based on Debian in the tag you've referenced (and even getting OpenJDK from Debian's package), the appropriate place to get more information about whether these issues are meaningful or will receive a fix would be the following URLs: (which Clair should've also provided for you)

https://security-tracker.debian.org/tracker/CVE-2017-16997
https://security-tracker.debian.org/tracker/CVE-2017-1000408
https://security-tracker.debian.org/tracker/CVE-2018-6485
https://security-tracker.debian.org/tracker/CVE-2017-14062
https://security-tracker.debian.org/tracker/CVE-2018-6551
https://security-tracker.debian.org/tracker/CVE-2017-8804
https://security-tracker.debian.org/tracker/CVE-2016-2779
https://security-tracker.debian.org/tracker/CVE-2017-12424
https://security-tracker.debian.org/tracker/CVE-2018-1000001
https://security-tracker.debian.org/tracker/CVE-2017-15400
https://security-tracker.debian.org/tracker/CVE-2018-6954
https://security-tracker.debian.org/tracker/CVE-2018-1049
https://security-tracker.debian.org/tracker/CVE-2018-5729
https://security-tracker.debian.org/tracker/CVE-2018-7169
https://security-tracker.debian.org/tracker/CVE-2017-12132
https://security-tracker.debian.org/tracker/CVE-2017-3738
https://security-tracker.debian.org/tracker/CVE-2018-5730
https://security-tracker.debian.org/tracker/CVE-2011-3389
https://security-tracker.debian.org/tracker/CVE-2018-8740
https://security-tracker.debian.org/tracker/CVE-2018-5710
https://security-tracker.debian.org/tracker/CVE-2018-5709
https://security-tracker.debian.org/tracker/CVE-2016-10228
https://security-tracker.debian.org/tracker/CVE-2017-1000409
https://security-tracker.debian.org/tracker/CVE-2018-1000035

See also #161, #112, docker-library/postgres#286, docker-library/drupal#84, docker-library/official-images#2740, docker-library/ruby#117, docker-library/ruby#94, docker-library/python#152, docker-library/php#242, docker-library/buildpack-deps#46.

@tianon tianon closed this as completed Apr 12, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants