LDAPAccountManager / docker

Docker images for LAM
GNU General Public License v3.0
19 stars 3 forks source link

Docker lam 8.6 : apache Vulnerability #3

Closed Nibeck1309 closed 4 months ago

Nibeck1309 commented 10 months ago

On lam 8.6 latest stable docker release Tenable report apache version is vulnerable:

Synopsis

The remote web server is affected by multiple vulnerabilities. Description

The version of Apache httpd installed on the remote host is prior to 2.4.58. It is, therefore, affected by multiple vulnerabilities as referenced in the 2.4.58 advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number. Steps to Remediate

Upgrade to Apache version 2.4.58 or later.

Risk Information

CVSS v2 Severity: High

In the docker container, when I check the apache version : image

gruberroland commented 10 months ago

Thank you very much for your report. This is very much appreciated.

The Debian security team classified the issues as low prio and the LAM Docker image is not using the two modules affected. Therefore, the issues will be fixed once Debian publishes a security fix for its distribution.

gruberroland commented 4 months ago

Fixed with latest Docker image