spring-cloud / spring-cloud-skipper

A package manager that installs, upgrades, and rolls back Spring Boot applications on multiple Cloud Platforms.
http://cloud.spring.io/spring-cloud-skipper/
Apache License 2.0
111 stars 78 forks source link

vulnerabilities in docker image #1033

Closed Craig2524 closed 1 year ago

Craig2524 commented 2 years ago

When trying to bring the docker image for springcloud/spring-cloud-skipper-server:2.8.2 into our firm a scan is performed.

It detected the following vulnerabilities in the image.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23221 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21724 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23463 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42392 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37714

Spring_cloud_skipper_SCAN.txt

corneil commented 1 year ago

Fixed in 2.9.3