SeleniumHQ / docker-selenium

Provides a simple way to run Selenium Grid with Chrome, Firefox, and Edge using Docker, making it easier to perform browser automation
http://www.selenium.dev/docker-selenium/
Other
7.86k stars 2.51k forks source link

[🐛 Bug]: security vulnerabilities on selenium/standalone-chrome:4.22.0-20240621 #2304

Closed Lunar-Edward closed 1 month ago

Lunar-Edward commented 1 month ago

What happened?

There are some security vulnerabilities on selenium/standalone-chrome:4.22.0-20240621 CVE-2023-36632 CVE-2021-28861 CVE-2023-27043

Command used to start Selenium Grid with Docker (or Kubernetes)

Currenty using selenium/standalone-chrome:4.22.0-20240621 with docker

Relevant log output

none

Operating System

Centos

Docker Selenium version (image tag)

standalone-chrome:4.22.0-20240621

Selenium Grid chart version (chart version)

No response

github-actions[bot] commented 1 month ago

@Lunar-Edward, thank you for creating this issue. We will troubleshoot it as soon as we can.


Info for maintainers

Triage this issue by using labels.

If information is missing, add a helpful comment and then I-issue-template label.

If the issue is a question, add the I-question label.

If the issue is valid but there is no time to troubleshoot it, consider adding the help wanted label.

If the issue requires changes or fixes from an external project (e.g., ChromeDriver, GeckoDriver, MSEdgeDriver, W3C), add the applicable G-* label, and it will provide the correct link and auto-close the issue.

After troubleshooting the issue, please add the R-awaiting answer label.

Thank you!

VietND96 commented 1 month ago

@Lunar-Edward, Can you please have a scan on image tag selenium/standalone-chrome:nightly and confirm CVEs are resolved? That would be the upcoming release for this month.

Lunar-Edward commented 1 month ago

@Lunar-Edward, Can you please have a scan on image tag selenium/standalone-chrome:nightly and confirm CVEs are resolved? That would be the upcoming release for this month.

Thank you very much! CVEs are resolved in image tag selenium/standalone-chrome:nightly.

VietND96 commented 1 month ago

Please verify the latest image tag released 4.23.0-20240727

github-actions[bot] commented 1 week ago

This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.