-
Notifications
You must be signed in to change notification settings - Fork 476
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
vulnerability in 8-jdk-alpine image #213
Comments
See docker-library/postgres#286 (comment) #161, #112, docker-library/postgres#286, docker-library/drupal#84, docker-library/official-images#2740, docker-library/ruby#117, docker-library/ruby#94, docker-library/python#152, docker-library/php#242, docker-library/buildpack-deps#46, #185. A CVE doesn't imply having an actual vulnerability, and often is even a false positive (given how most distributions handle versioning/security updates in stable releases). If there are actionable items we can resolve, we're happy to do so (and do so actively). We update all Debian based images to include any updates in apt packages at least monthly (we regenerate the base images and then rebuild all dependent images). |
Looking at the Alpine bugtracker (https://bugs.alpinelinux.org/projects/alpine/search?q=CVE-2018-6942), it does appear to have been fixed in Alpine 3.8, 3.7, 3.6, and 3.5, so we should pick up the change shortly (especially given the recently-merged #210). |
@tianon I have pulled the latest image and the scan returned the same results. |
It seems to be fine. In a freshly pulled image, it contains the package release revision that has the fix (pkgver=2.9, pkgrel=1 alpinelinux/aports@7a7493c). $ docker pull openjdk:8-jdk-alpine
8-jdk-alpine: Pulling from library/openjdk
8e3ba11ec2a2: Pull complete
311ad0da4533: Pull complete
df312c74ce16: Pull complete
Digest: sha256:1fd5a77d82536c88486e526da26ae79b6cd8a14006eb3da3a25eb8d2d682ccd6
Status: Downloaded newer image for openjdk:8-jdk-alpine
$ docker run -it --rm openjdk:8-jdk-alpine sh
/ # apk info freetype
WARNING: Ignoring APKINDEX.adfa7ceb.tar.gz: No such file or directory
WARNING: Ignoring APKINDEX.efaa1f73.tar.gz: No such file or directory
freetype-2.9.1-r1 description:
TrueType font rendering library
freetype-2.9.1-r1 webpage:
https://www.freetype.org/
freetype-2.9.1-r1 installed size:
745472
|
Hi,
We find a vulnerability in the
8-jdk-alpine
image:Is it a known issue? does it has a fix?
Thanks
The text was updated successfully, but these errors were encountered: