aws / aws-lambda-base-images

Apache License 2.0
648 stars 107 forks source link

Critical CVE's on Python:3.9 #53

Closed glmourad closed 1 year ago

glmourad commented 1 year ago

Hi,

The current public.ecr.aws/lambda/python:3.9 presents 3 Critical CVE's:

CVE-2022-22824 - expat CVE-2022-22823 - expat CVE-2022-22822 - expat

Any estimate when these issues can be addressed?

carlzogh commented 1 year ago

Thank you for reporting this - a fresh set of images is now available with patches for the above-mentioned CVEs.