Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Please fix security vulnerabilities for v0.47.2 #3461

Closed
demian711 opened this issue Jan 25, 2024 · 1 comment
Closed

Please fix security vulnerabilities for v0.47.2 #3461

demian711 opened this issue Jan 25, 2024 · 1 comment

Comments

@demian711
Copy link

Please, upgrade following packages / libraries to fix high vulnerabilities found for image version v0.47.2

Severity Name Library Name Fixed version Remediation description
High CVE-2022-41723 golang.org/x/net 0.7.0 go get -u golang.org/x/net The library golang.org/x/net version 0.4.0 was detected in Golang binary located at /usr/bin/cadvisor and is vulnerable to CVE-2022-41723, which exists in versions <0.7. .The vulnerability was found in the The Go Vulnerability Database with vendor severity: High (NVD severity: High).
High CVE-2023-2253 github.com/docker/distribution 2.8.2-beta.1 go get -u github.com/docker/distribution "The library github.com/docker/distribution version 2.8.1+incompatible was detected in Golang binary located at /usr/bin/cadvisor and is vulnerable to CVE-2023-2253, which exists in versions < 2.8.2-beta.1. The vulnerability was found in the Github Security Advisory with vendor severity: High (NVD severity: Medium)
High CVE-2023-27561 github.com/opencontainers/runc 1.1.5 go get -u github.com/opencontainers/runc "The library github.com/opencontainers/runc version 1.1.4 was detected in Golang binary located at /usr/bin/cadvisor and is vulnerable to CVE-2023-27561, which exists in versions >= 1.0.0-rc95, < 1.1.5. The vulnerability was found in the [Github Security Advisory](https://github.com/advisories/GHSA-vpvm-3wq2-2wvm) with vendor severity: High([NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-27561) severity:High`). This vulnerability has a known exploit available. Source: Github.
High CVE-2023-28840 github.com/docker/docker 20.10.24 go get -u github.com/docker/docker "The library github.com/docker/docker version 20.10.21+incompatible was detected in Golang binary located at /usr/bin/cadvisor and is vulnerable to CVE-2023-28840, which exists in versions >= 1.12.0, < 20.10.24. The vulnerability was found in the Github Security Advisory with vendor severity: High (NVD severity: High). This vulnerability has a known exploit available. Source: Github
High CVE-2023-39325 golang.org/x/net 0.17.0 go get -u golang.org/x/net "The library google.golang.org/grpc version 1.51.0 was detected in Golang binary located at /usr/bin/cadvisor and is vulnerable to GHSA-m425-mq94-257g, which exists in versions < 1.56.3. The vulnerability was found in the Github Security Advisory with vendor severity: High
High GHSA-m425-mq94-257g google.golang.org/grpc 1.56.3 go get -u google.golang.org/grpc "The library golang.org/x/net version 0.4.0 was detected in Golang binary located at /usr/bin/cadvisor and is vulnerable to CVE-2023-44487, which exists in versions < 0.17.0. The vulnerability was found in the Github Security Advisory with vendor severity: Medium (NVD severity: High). This vulnerability has a known exploit available. Sources: CISA Known Exploited Vulnerabilities Catalog, Github
@bobbypage
Copy link
Collaborator

Please use the latest release v0.49.1 - https://github.com/google/cadvisor/releases/tag/v0.49.1 which has updated the dependencies.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants