You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We are using the latest Postgres image in our environment in both dev and prod environments. We are seeing the following vulnerability popped up in our environment for this image.
summary:
Nick Wellnhofer discovered that the xsltApplyTemplates function in libxslt, an XSLT processing runtime library, is prone to a use-after-free flaw, resulting in a denial of service, or potentially the execution of arbitrary code if a specially crafted file is processed.
Issue:
postgres:latest-CVE-2021-30560
libxslt1.1 has vulnerabilities
Action:
Upgrade libxslt1.1 to >= 1.1.34-4+deb11u1
Request you to kindly update the libxslt to the latest version and push the new image.
The text was updated successfully, but these errors were encountered:
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
A CVE doesn't imply having an actual vulnerability, and often is even a false positive (given how most distributions handle versioning/security updates in stable releases). If there are actionable items we can resolve, we're happy to do so (and do so actively). We update all Debian based images to include any updates in apt packages at least monthly (we regenerate the base images and then rebuild all dependent images).
Hi Team,
We are using the latest Postgres image in our environment in both dev and prod environments. We are seeing the following vulnerability popped up in our environment for this image.
summary:
Nick Wellnhofer discovered that the xsltApplyTemplates function in libxslt, an XSLT processing runtime library, is prone to a use-after-free flaw, resulting in a denial of service, or potentially the execution of arbitrary code if a specially crafted file is processed.
Issue:
postgres:latest-CVE-2021-30560
libxslt1.1 has vulnerabilities
Action:
Upgrade libxslt1.1 to >= 1.1.34-4+deb11u1
Request you to kindly update the libxslt to the latest version and push the new image.
The text was updated successfully, but these errors were encountered: