Nexenta / nexentastor-csi-driver-block

Apache License 2.0
1 stars 1 forks source link

ES-746 docker image vulnerabilities #37

Closed Qeas closed 1 year ago

Qeas commented 1 year ago

trivy image nexentastor-csi-driver-block:master

2023-03-30T05:58:49.553-0700 INFO Detected OS: alpine 2023-03-30T05:58:49.553-0700 WARN This OS version is not on the EOL list: alpine 3.17 2023-03-30T05:58:49.553-0700 INFO Detecting Alpine vulnerabilities... 2023-03-30T05:58:49.560-0700 INFO Number of language-specific files: 1 2023-03-30T05:58:49.560-0700 INFO Detecting gobinary vulnerabilities... 2023-03-30T05:58:49.562-0700 WARN This OS version is no longer supported by the distribution: alpine 3.17.2 2023-03-30T05:58:49.562-0700 WARN The vulnerability detection may be insufficient because security updates are not provided

nexentastor-csi-driver-block:master (alpine 3.17.2)

Total: 0 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

nexentastor-csi-driver-block/nexentastor-csi-driver-block (gobinary)

Total: 3 (UNKNOWN: 0, LOW: 1, MEDIUM: 2, HIGH: 0, CRITICAL: 0)

+-------------------+------------------+----------+-------------------+---------------+---------------------------------------+ | LIBRARY | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION | TITLE | +-------------------+------------------+----------+-------------------+---------------+---------------------------------------+ | k8s.io/kubernetes | CVE-2020-8554 | MEDIUM | v1.20.11 | | kubernetes: MITM using | | | | | | | LoadBalancer or ExternalIPs | | | | | | | -->avd.aquasec.com/nvd/cve-2020-8554 |

These 3 vulnerabilities still do not have a fix.