Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVEs on 2.0.1 docker image #22235

Closed
tooptoop4 opened this issue Nov 28, 2022 · 2 comments · Fixed by #22489
Closed

CVEs on 2.0.1 docker image #22235

tooptoop4 opened this issue Nov 28, 2022 · 2 comments · Fixed by #22489
Assignees
Labels
#bug Bug report v2.0.1

Comments

@tooptoop4
Copy link
Contributor

i pulled docker image for 2.0.1rc4

findings:
upgrade Pillow to 9.3.0 to resolve CVE-2022-30595, CVE-2022-45198, CVE-2022-45199
upgrade Flask-Caching to 1.11.0 to resolve CVE-2021-33026
upgrade Werkzeug to 2.1.1 to resolve CVE-2022-29361
upgrade aiohttp to 3.8.3 to resolve CVE-2022-33124
curl is also affected by CVE-2022-42916 , can it be removed from the image?

@tooptoop4 tooptoop4 added the #bug Bug report label Nov 28, 2022
@rusackas
Copy link
Member

rusackas commented Nov 29, 2022

Thank you for pointing out these issues. 2.0.1 is close to fully baked, and resolves a number of issues already. I think these additional fixes will have to wait for a fast-follow 2.0.2 release and/or 2.1.0.

@rusackas
Copy link
Member

We'll add these to the security roadmap, and have it on the agenda to tackle and discuss at the next Security working group meeting. Let me know if you have any interest in attending. Thanks again!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
#bug Bug report v2.0.1
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants