Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical vulnerability in ploigos-base image #113

Open
dlystra opened this issue Mar 29, 2023 · 2 comments
Open

Critical vulnerability in ploigos-base image #113

dlystra opened this issue Mar 29, 2023 · 2 comments

Comments

@dlystra
Copy link

dlystra commented Mar 29, 2023

CVE: pyup.io-52322 (CVE-2022-24439)
Severity: Critical
Package: gitpython
Version: 3.1.18
Layer:

RUN |7 PLOIGOS_USER_NAME=ploigos PLOIGOS_USER_UID=1001 PLOIGOS_USER_GID=0 PLOIGOS_HOME_DIR=/home/ploigos PLOIGOS_SOURCE=ploigos-step-runner==1.0.0 YQ_VERSION=3.4.1 SOPS_RPM=https://github.com/mozilla/sops/releases/download/v3.6.1/sops-3.6.1-1.x86_64.rpm /bin/sh -c python -m pip install --no-cache-dir --upgrade ${PLOIGOS_SOURCE} # buildkit


@itewk
Copy link
Contributor

itewk commented Mar 29, 2023

@dlystra which version of the image is this an issue in? have you checked the nightly builds to see if they have the issue? if the issue is fixed in the nightly builds, then we can just tag head of main and new released versions will publish. if not fixed in the nightly builds then need to fix the issue, then tag head of main.

@dlystra
Copy link
Author

dlystra commented Mar 29, 2023

I think it's on all of them.
https://quay.io/repository/ploigos/ploigos-base?tab=tags

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants