solo-io / gloo

The Feature-rich, Kubernetes-native, Next-Generation API Gateway Built on Envoy
https://docs.solo.io/
Apache License 2.0
4.07k stars 435 forks source link

Vulnerabilities found in Gloo version 1.16.16 #9764

Open DreyfussDaena opened 2 months ago

DreyfussDaena commented 2 months ago

Gloo Edge Product

Enterprise

Gloo Edge Version

gloo-ee 1.16.11-alpine (gloo 1.16.16)

Kubernetes Version

v1.28.6

Describe the bug

Expected Behavior

These vulnerabilities should be resolved asap as they are high and could cause potential security issues.

Steps to reproduce the bug

These vulnerabilities came up on a BlackDuck scan while scanning the gloo images.

Additional Environment Detail

No response

Additional Context

No response

nfuden commented 1 month ago

All Glibc vulnerabilites are unfixable on 1.16-alpine variants as alpine's musl to glibc linker doesnt support newer glibc.

The other one vulnerabilites should be handled in our upcoming 1.16.12 enterprise release