Azure / azure-functions-docker

This repo contains the base Docker images for working with azure functions
MIT License
267 stars 118 forks source link

Vulnerabilities identified in dotnet-isolated base image #613

Open esimkowitz opened 2 years ago

esimkowitz commented 2 years ago

My team's component governance tracker has identified the following vulnerabilities in the mcr.microsoft.com/azure-functions/dotnet-isolated:4 base image: https://security-tracker.debian.org/tracker/CVE-2021-3995, https://security-tracker.debian.org/tracker/CVE-2021-3996

The affected package is Debian:11:util-linux 2.36.1-8

The recommended action is: This vulnerability has been resolved in the latest version of this release (bullseye), update your release or upgrade util-linux from 2.36.1-8 to 2.36.1-8+deb11u1 to fix the vulnerability.

esimkowitz commented 2 years ago

This has resurfaced on our component governance scans, can someone please Ack?

esimkowitz commented 2 years ago

cc @kshyju @CooperLink