Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trivy vulnerability analysis and fixes to docker images at the library level #152

Merged
merged 5 commits into from
Jan 7, 2022

Conversation

groldan
Copy link
Member

@groldan groldan commented Jan 6, 2022

Update library dependencies to reduce trivy reported vulnerabilities in Docker images.

Summary:

  • geoservercloud/geoserver-cloud-admin-server:
    1.0-RC5: Total: 14 (UNKNOWN: 0, LOW: 1, MEDIUM: 8, HIGH: 0, CRITICAL: 5)
    1.0-SNAPSHOT: Total: 2 (UNKNOWN: 0, LOW: 1, MEDIUM: 1, HIGH: 0, CRITICAL: 0)
  • geoservercloud/geoserver-cloud-catalog:
    1.0-RC5: Total: 54 (UNKNOWN: 1, LOW: 1, MEDIUM: 14, HIGH: 27, CRITICAL: 11)
    1.0-SNAPSHOT: Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 0, CRITICAL: 0)
  • geoservercloud/geoserver-cloud-config:
    1.0-RC5: Total: 42 (UNKNOWN: 0, LOW: 1, MEDIUM: 9, HIGH: 23, CRITICAL: 9)
    1.0-SNAPSHOT: Total: 2 (UNKNOWN: 0, LOW: 1, MEDIUM: 1, HIGH: 0, CRITICAL: 0)
  • geoservercloud/geoserver-cloud-discovery:
    1.0-RC5: Total: 42 (UNKNOWN: 0, LOW: 1, MEDIUM: 9, HIGH: 23, CRITICAL: 9)
    1.0-SNAPSHOT: Total: 2 (UNKNOWN: 0, LOW: 1, MEDIUM: 1, HIGH: 0, CRITICAL: 0)
  • geoservercloud/geoserver-cloud-gateway:
    1.0-RC5: Total: 43 (UNKNOWN: 0, LOW: 1, MEDIUM: 11, HIGH: 22, CRITICAL: 9)
    1.0-SNAPSHOT: Total: 2 (UNKNOWN: 0, LOW: 1, MEDIUM: 1, HIGH: 0, CRITICAL: 0)
  • geoservercloud/geoserver-cloud-rest:
    1.0-RC5: Total: 59 (UNKNOWN: 1, LOW: 1, MEDIUM: 17, HIGH: 29, CRITICAL: 11)
    1.0-SNAPSHOT: Total: 2 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 0, CRITICAL: 1)
  • geoservercloud/geoserver-cloud-wcs:
    1.0-RC5: Total: 57 (UNKNOWN: 1, LOW: 1, MEDIUM: 16, HIGH: 29, CRITICAL: 10)
    1.0-SNAPSHOT: Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 0, CRITICAL: 0)
  • geoservercloud/geoserver-cloud-webui:
    1.0-RC5: Total: 63 (UNKNOWN: 2, LOW: 2, MEDIUM: 17, HIGH: 30, CRITICAL: 12)
    1.0-SNAPSHOT: Total: 5 (UNKNOWN: 1, LOW: 1, MEDIUM: 1, HIGH: 0, CRITICAL: 2)
  • geoservercloud/geoserver-cloud-wfs:
    1.0-RC5: Total: 63 (UNKNOWN: 2, LOW: 2, MEDIUM: 16, HIGH: 31, CRITICAL: 12)
    1.0-SNAPSHOT: Total: 4 (UNKNOWN: 1, LOW: 1, MEDIUM: 1, HIGH: 0, CRITICAL: 1)
  • geoservercloud/geoserver-cloud-wms:
    1.0-RC5: Total: 61 (UNKNOWN: 2, LOW: 2, MEDIUM: 16, HIGH: 30, CRITICAL: 11)
    1.0-SNAPSHOT: Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 0, CRITICAL: 0)
  • geoservercloud/geoserver-cloud-wps:
    1.0-RC5: Total: 60 (UNKNOWN: 2, LOW: 2, MEDIUM: 16, HIGH: 29, CRITICAL: 11)
    1.0-SNAPSHOT: Total: 4 (UNKNOWN: 1, LOW: 1, MEDIUM: 1, HIGH: 0, CRITICAL: 1)
    1.0-SNAPSHOT library vulnerabilities

geoservercloud/geoserver-cloud-rest:

Java (jar)
==========
Total: 1 (HIGH: 0, CRITICAL: 1)

+----------------------------------+------------------+----------+-------------------+---------------+-----------------------------------------+
|             LIBRARY              | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION |                  TITLE                  |
+----------------------------------+------------------+----------+-------------------+---------------+-----------------------------------------+
| org.codehaus.plexus:plexus-utils | CVE-2017-1000487 | CRITICAL | 1.5.6             | 3.0.16        | plexus-utils: Mishandled                |
|                                  |                  |          |                   |               | strings in Commandline class            |
|                                  |                  |          |                   |               | allow for command injection             |
|                                  |                  |          |                   |               | -->avd.aquasec.com/nvd/cve-2017-1000487 |
+----------------------------------+------------------+----------+-------------------+---------------+-----------------------------------------+

geoservercloud/geoserver-cloud-wcs:

Java (jar)
==========
Total: 2 (HIGH: 0, CRITICAL: 2)

+----------------------------------+------------------+----------+-------------------+---------------+-----------------------------------------+
|             LIBRARY              | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION |                  TITLE                  |
+----------------------------------+------------------+----------+-------------------+---------------+-----------------------------------------+
| log4j:log4j                      | CVE-2019-17571   | CRITICAL | 1.2.17-norce      |               | log4j: deserialization of               |
|                                  |                  |          |                   |               | untrusted data in SocketServer          |
|                                  |                  |          |                   |               | -->avd.aquasec.com/nvd/cve-2019-17571   |
+----------------------------------+------------------+          +-------------------+---------------+-----------------------------------------+
| org.codehaus.plexus:plexus-utils | CVE-2017-1000487 |          | 1.5.6             | 3.0.16        | plexus-utils: Mishandled                |
|                                  |                  |          |                   |               | strings in Commandline class            |
|                                  |                  |          |                   |               | allow for command injection             |
|                                  |                  |          |                   |               | -->avd.aquasec.com/nvd/cve-2017-1000487 |
+----------------------------------+------------------+----------+-------------------+---------------+-----------------------------------------+

geoservercloud/geoserver-cloud-wfs:

Java (jar)
==========
Total: 1 (HIGH: 0, CRITICAL: 1)

+-------------+------------------+----------+-------------------+---------------+---------------------------------------+
|   LIBRARY   | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION |                 TITLE                 |
+-------------+------------------+----------+-------------------+---------------+---------------------------------------+
| log4j:log4j | CVE-2019-17571   | CRITICAL | 1.2.17-norce      |               | log4j: deserialization of             |
|             |                  |          |                   |               | untrusted data in SocketServer        |
|             |                  |          |                   |               | -->avd.aquasec.com/nvd/cve-2019-17571 |
+-------------+------------------+----------+-------------------+---------------+---------------------------------------+

@groldan groldan added dependencies dependency management docker Issues related to docker images or docker composition labels Jan 6, 2022
@groldan groldan force-pushed the trivy_library_dependency_analysis branch from ba6d4ee to 68d9e7a Compare January 7, 2022 00:10
@groldan groldan force-pushed the trivy_library_dependency_analysis branch from 37306cd to 659b278 Compare January 7, 2022 02:45
@groldan groldan merged commit 1fc6892 into geoserver:main Jan 7, 2022
@groldan groldan deleted the trivy_library_dependency_analysis branch January 7, 2022 02:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies dependency management docker Issues related to docker images or docker composition
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant