-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Node official images vulnerabilities #2740
Comments
Usually most vulnerabilities listed on the Docker Hub are unable to be fixed since there is not an updated package available via the package manager. Let's go down a few of the list of vulnerabilities in
Layers in
I would guess that most of the other vulnerabilities in the Layers of node:7.7.2
|
Thank you for the extensive explanation! As far as the node:7.7.2 layer vulnerability, maybe the scanner is looking at the library version which doesn't reflect the patch as mentioned here: nodejs/node#11728 As stated above,
However, as you can see here, it's marked as Critical. Is this discrepancy due to a different source of severity information? |
Yeah, the "Critical" is based purely on the CVSS score of 9.8. Minor is what the Debian Security team have classified it for their security release process in order to allocate resources effectively in porting security fixes across all packages. |
As seen here, an overwhelming majority of the official node images contain vulnerabilities. Can these please get addressed?
The text was updated successfully, but these errors were encountered: