zalando / spilo

Highly available elephant herd: HA PostgreSQL cluster using Docker
Apache License 2.0
1.5k stars 369 forks source link

Security Vulnerabilities: Both 15 and 16 Images have critical and high Vulnerabilities #982

Open gowthamvetriselvan opened 4 months ago

gowthamvetriselvan commented 4 months ago

Hi Team

Recent docker image of Spilo having critical and high Vulnerabilities

Do we know when it can be addressed or provide any workaorund on overcoming this Vulnerabilities. since with this Vulnerabilities looks like easy to break the postgres DB

Jan-M commented 3 months ago

How do you reach the conclusion that from any of those CVEs it is easy to break the Postgres database cluster run via Spilo container?

gowthamvetriselvan commented 1 week ago

@Jan-M Apologize for mentioning easily breakable (a Generic Statement). But, To provide the ground situation on this issue.. we have software security policies that prohibit us from using 3rd party software with CVEs of severity "High" or greater. These CVEs limit their audience.