PhiTux / DailyTxT

Encrypted Diary Web-App
https://hub.docker.com/r/phitux/dailytxt/
MIT License
213 stars 14 forks source link

Vulnerabilities in Docker image #50

Open ngosang opened 4 days ago

ngosang commented 4 days ago

You can test with: grype phitux/dailytxt:1.0.15 | grep -i -E '(High|Critical)'

Docker image: phitux/dailytxt:1.0.15
flask-cors     3.0.10      4.0.2       python  GHSA-hxwh-jpp2-84pm  High      
libcrypto3     3.3.1-r0    3.3.1-r1    apk     CVE-2024-5535        Critical  
libcrypto3     3.3.1-r0    3.3.2-r0    apk     CVE-2024-6119        High      
libexpat       2.6.2-r0    2.6.3-r0    apk     CVE-2024-45492       Critical  
libexpat       2.6.2-r0    2.6.3-r0    apk     CVE-2024-45491       Critical  
libexpat       2.6.2-r0    2.6.3-r0    apk     CVE-2024-45490       Critical  
libssl3        3.3.1-r0    3.3.1-r1    apk     CVE-2024-5535        Critical  
libssl3        3.3.1-r0    3.3.2-r0    apk     CVE-2024-6119        High      
werkzeug       2.3.8       3.0.3       python  GHSA-2g68-c3qc-8985  High
PhiTux commented 4 days ago

Thanks for the info! I'm not sure, when I've time to update the packages...