Open
Conversation
✗ Medium severity vulnerability found in e2fsprogs/libcom_err Description: Out-of-bounds Write Info: https://snyk.io/vuln/SNYK-ALPINE37-E2FSPROGS-493456 Introduced through: e2fsprogs/libcom_err@1.43.7-r0, krb5-conf/krb5-conf@1.0-r1 From: e2fsprogs/libcom_err@1.43.7-r0 From: krb5-conf/krb5-conf@1.0-r1 > krb5/krb5-libs@1.15.4-r0 > e2fsprogs/libcom_err@1.43.7-r0 Image layer: Introduced by your base image (python:3.6.8-alpine3.7) Fixed in: 1.43.7-r1 ✗ High severity vulnerability found in expat/expat Description: XML External Entity (XXE) Injection Info: https://snyk.io/vuln/SNYK-ALPINE37-EXPAT-453374 Introduced through: expat/expat@2.2.5-r0, .python-rundeps@0, python2/python2@2.7.15-r2, python3/python3@3.6.9-r1 From: expat/expat@2.2.5-r0 From: .python-rundeps@0 > expat/expat@2.2.5-r0 From: python2/python2@2.7.15-r2 > expat/expat@2.2.5-r0 and 1 more... Image layer: Introduced by your base image (python:3.6.8-alpine3.7) Fixed in: 2.2.7-r0 ✗ High severity vulnerability found in expat/expat Description: Out-of-bounds Read Info: https://snyk.io/vuln/SNYK-ALPINE37-EXPAT-489399 Introduced through: expat/expat@2.2.5-r0, .python-rundeps@0, python2/python2@2.7.15-r2, python3/python3@3.6.9-r1 From: expat/expat@2.2.5-r0 From: .python-rundeps@0 > expat/expat@2.2.5-r0 From: python2/python2@2.7.15-r2 > expat/expat@2.2.5-r0 and 1 more... Image layer: Introduced by your base image (python:3.6.8-alpine3.7) Fixed in: 2.2.7-r1 ✗ Critical severity vulnerability found in sqlite/sqlite-libs Description: Out-of-bounds Read Info: https://snyk.io/vuln/SNYK-ALPINE37-SQLITE-458200 Introduced through: sqlite/sqlite-libs@3.25.3-r0, .python-rundeps@0, python2/python2@2.7.15-r2, python3/python3@3.6.9-r1 From: sqlite/sqlite-libs@3.25.3-r0 From: .python-rundeps@0 > sqlite/sqlite-libs@3.25.3-r0 From: python2/python2@2.7.15-r2 > sqlite/sqlite-libs@3.25.3-r0 and 1 more... Image layer: Introduced by your base image (python:3.6.8-alpine3.7) Fixed in: 3.25.3-r1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Instructions
Please try and perform pull requests against the
developbranch.Merging against the master branch causes a new release to be deployed, and I'd like to avoid that on every PR.
PR Details
Fix CVE 2018 20843 by upgrading expat and dependencies
Description
Fix following scenned vulerabilities:
✗ Medium severity vulnerability found in e2fsprogs/libcom_err
Description: Out-of-bounds Write
Info: https://snyk.io/vuln/SNYK-ALPINE37-E2FSPROGS-493456
Introduced through: e2fsprogs/libcom_err@1.43.7-r0, krb5-conf/krb5-conf@1.0-r1
From: e2fsprogs/libcom_err@1.43.7-r0
From: krb5-conf/krb5-conf@1.0-r1 > krb5/krb5-libs@1.15.4-r0 > e2fsprogs/libcom_err@1.43.7-r0
Image layer: Introduced by your base image (python:3.6.8-alpine3.7)
Fixed in: 1.43.7-r1
✗ High severity vulnerability found in expat/expat
Description: XML External Entity (XXE) Injection
Info: https://snyk.io/vuln/SNYK-ALPINE37-EXPAT-453374
Introduced through: expat/expat@2.2.5-r0, .python-rundeps@0, python2/python2@2.7.15-r2, python3/python3@3.6.9-r1
From: expat/expat@2.2.5-r0
From: .python-rundeps@0 > expat/expat@2.2.5-r0
From: python2/python2@2.7.15-r2 > expat/expat@2.2.5-r0
and 1 more...
Image layer: Introduced by your base image (python:3.6.8-alpine3.7)
Fixed in: 2.2.7-r0
✗ High severity vulnerability found in expat/expat
Description: Out-of-bounds Read
Info: https://snyk.io/vuln/SNYK-ALPINE37-EXPAT-489399
Introduced through: expat/expat@2.2.5-r0, .python-rundeps@0, python2/python2@2.7.15-r2, python3/python3@3.6.9-r1
From: expat/expat@2.2.5-r0
From: .python-rundeps@0 > expat/expat@2.2.5-r0
From: python2/python2@2.7.15-r2 > expat/expat@2.2.5-r0
and 1 more...
Image layer: Introduced by your base image (python:3.6.8-alpine3.7)
Fixed in: 2.2.7-r1
✗ Critical severity vulnerability found in sqlite/sqlite-libs
Description: Out-of-bounds Read
Info: https://snyk.io/vuln/SNYK-ALPINE37-SQLITE-458200
Introduced through: sqlite/sqlite-libs@3.25.3-r0, .python-rundeps@0, python2/python2@2.7.15-r2, python3/python3@3.6.9-r1
From: sqlite/sqlite-libs@3.25.3-r0
From: .python-rundeps@0 > sqlite/sqlite-libs@3.25.3-r0
From: python2/python2@2.7.15-r2 > sqlite/sqlite-libs@3.25.3-r0
and 1 more...
Image layer: Introduced by your base image (python:3.6.8-alpine3.7)
Fixed in: 3.25.3-r1
Related Issue
CVE-2018-20843