aiogram / telegram-bot-api

Docker image of Telegram Bot API Server
https://hub.docker.com/r/aiogram/telegram-bot-api
153 stars 50 forks source link

Zlib vulnerability CVE-2022-37434 #8

Closed mercuree closed 1 year ago

mercuree commented 1 year ago

When using latest telegram-bot-api docker image, I get vulnerability notification. To fix this, you should update alpine version up to 3.13.12 (at least) Here you can find list of known vulnerabilities in alpine https://dso.docker.com/images/alpine image

JrooTJunior commented 1 year ago

Fixed in https://github.com/aiogram/telegram-bot-api/commit/70a98c31f56bb187a79e02bc7d7ec21c0b33d052