adoptium / containers

Repo containing the dockerfiles and scripts to produce the official eclipse-temurin containers.
https://hub.docker.com/_/eclipse-temurin/
Apache License 2.0
216 stars 93 forks source link

eclipse-temurin:11-jre-alpine has vulnerability "CVE-2023-48795" #474

Closed ManhingChan closed 8 months ago

ManhingChan commented 8 months ago

Hi support,

We are using "eclipse-temurin:11-jre-alpine" as our base linux docker image, but it fail to pass the vulnerability scan in our container host, details as following:

CVE-2023-48795

We checked that CVE-2023-48795 is created at 2023/11/23, and we checked on the latest release of "eclipse-temurin:11-jre-alpine", and the latest version is 2 month before, may we know when will the new update of "eclipse-temurin:11-jre-alpine" which fixed the issue, and is there any workaround for us?

Yours, Manhing

karianna commented 8 months ago

Base layers are updated by Docker Inc. up at Docker Hub. I recommend filing a request there.