Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Grype's >= Medium CVEs for container image #159

Open
endersonmaia opened this issue Sep 13, 2024 · 0 comments
Open

Grype's >= Medium CVEs for container image #159

endersonmaia opened this issue Sep 13, 2024 · 0 comments

Comments

@endersonmaia
Copy link
Contributor

endersonmaia commented Sep 13, 2024

These are from the container image generated by cartesi build.

I think we should create an individual issue for each CVE to tackle them as a sub-issue for this issue.

NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
busybox-static 1:1.36.1-6ubuntu3.1 deb CVE-2023-42366 Medium
busybox-static 1:1.36.1-6ubuntu3.1 deb CVE-2023-39810 Medium
libgcrypt20 1.10.3-2build1 deb CVE-2024-2236 Medium
libssl3t64 3.0.13-0ubuntu3.4 deb CVE-2024-41996 Medium
openssl 3.0.13-0ubuntu3.4 deb CVE-2024-41996 Medium

Severity from grype's output, it may be different depending on the source

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant