Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-27780, CVE-2022-27781, CVE-2022-27782, CVE-2022-27779, CVE-2022-30115 #679

Closed
achifal opened this issue Jun 26, 2022 · 4 comments
Closed

Comments

@achifal
Copy link

achifal commented Jun 26, 2022

Name Resource Severity Score Fix Version
CVE-2022-27780 curl high 7.5 7.83.1
CVE-2022-27781 curl high 7.5 7.83.1
CVE-2022-27782 curl high 7.5 7.83.1
CVE-2022-27779 curl medium 5.3 7.83.1
CVE-2022-30115 curl medium 4.3 7.83.1
@achifal
Copy link
Author

achifal commented Jun 27, 2022

To fix this we are using:
RUN apk add --update --no-cache 'curl>=7.83.1-r1' --repository='http://dl-cdn.alpinelinux.org/alpine/edge/main

@yosifkit
Copy link
Contributor

As for the Debian based images, they are not affected by some of these CVEs (Vulnerable code introduced later) and the rest do not have updates available in Debian's package repos.

This was referenced Jul 19, 2022
@thresheek
Copy link
Collaborator

All those CVEs are now fixed in Alpine-based images.

@thresheek thresheek added this to the Move to Debian 12 Bookworm milestone Jul 19, 2022
@thresheek thresheek removed this from the Move to Debian 12 Bookworm milestone Sep 7, 2022
@thresheek
Copy link
Collaborator

All those CVEs are now fixed in Debian-based images.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants