Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical CVEs in registry container #170

Open
wkbrd opened this issue Jul 10, 2024 · 6 comments
Open

Critical CVEs in registry container #170

wkbrd opened this issue Jul 10, 2024 · 6 comments

Comments

@wkbrd
Copy link

wkbrd commented Jul 10, 2024

The latest registry:2 container has critical CVEs.

NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
libcrypto3 3.1.5-r0 3.1.6-r0 apk CVE-2024-5535 Critical
libcrypto3 3.1.5-r0 3.1.6-r0 apk CVE-2024-4741 Unknown
libssl3 3.1.5-r0 3.1.6-r0 apk CVE-2024-5535 Critical
libssl3 3.1.5-r0 3.1.6-r0 apk CVE-2024-4741 Unknown

This was scanned using Grype.

Can these be fixed?

@milosgajdos
Copy link
Member

Please use v3 images. v2 is in a state that's not been touched for a long time.

@wkbrd
Copy link
Author

wkbrd commented Jul 10, 2024

The only 3.x version appears to be 3.0.0-alpha.1 per https://hub.docker.com/_/registry/tags.
It also has critical CVEs.

Am I pulling from the correct docker location?

@milosgajdos
Copy link
Member

They just merged docker-library/official-images#17151

Not sure how long it takes to build it 🤷‍♂️ In the meantime you can grab the latest release from:

@wkbrd
Copy link
Author

wkbrd commented Jul 10, 2024

I just pulled down distribution/distribution:3.0.0-beta.1 and it still has two fixable Critical CVEs:
libcrypto3 3.3.1-r0 3.3.1-r1 apk CVE-2024-5535 Critical
libssl3 3.3.1-r0 3.3.1-r1 apk CVE-2024-5535 Critical

Can this be fixed in the container image?

@milosgajdos
Copy link
Member

milosgajdos commented Jul 10, 2024

Unfortunately, the latest alpine image we build off has those vulns so there is nothing we can do about that until that basee image is fixed. https://hub.docker.com/_/alpine/tags

Grab a binary and build your own is the best I can recommend to you at the moment.

@wkbrd
Copy link
Author

wkbrd commented Jul 10, 2024

Thanks for the quick reply.

Adding this link as a reference: alpinelinux/docker-alpine#405.

Let's leave this ticket open as we wait for the container base image to be patched.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants