Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multiple vulnerabilities found in Alpine Docker image (2.7.11) by Trivy #26048

Open
tukez opened this issue Feb 21, 2025 · 0 comments
Open

Multiple vulnerabilities found in Alpine Docker image (2.7.11) by Trivy #26048

tukez opened this issue Feb 21, 2025 · 0 comments

Comments

@tukez
Copy link

tukez commented Feb 21, 2025

I scanned the latest Alpine image (2.7.11-alpine) using Trivy and found multiple critical and high severity vulnerabilities:

Image

Here is the same report in PDF: influxdb-2.7.11-alpine-vulnerabilities.pdf

I found this issue (#25177) where Go was apparently updated from 1.21.10 to 1.21.12, but the Trivy says the Go version is 1.21.9?

I tried to research some of these vulnerabilities and as far as I understand the dasel vulnerabilities are not really critical or high since it is used only for configuration parsing? There are other vulnerabilities found in influx and influxd binaries though.

These same vulnerabilities are listed in the Dockerhub page: https://hub.docker.com/layers/library/influxdb/2.7.11-alpine/images/sha256-7b910c12adf77fd4494e09c07c69d94bc9027a63ee137c481820af10de30f15b

Are these actual vulnerabilities or false positives? Is there a list of false positive vulnerabilities somewhere?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant