Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fluent/fluentd:v1.11-2 security vulnerabilities #238

Open
g3kr opened this issue Nov 3, 2020 · 5 comments
Open

fluent/fluentd:v1.11-2 security vulnerabilities #238

g3kr opened this issue Nov 3, 2020 · 5 comments

Comments

@g3kr
Copy link

g3kr commented Nov 3, 2020

We are using this image and we have the following vulnerability

due to package ruby and webrick. Is there a way to fix this?

Or can you recommend an image with no vulnerability issues.

@nvtkaszpir
Copy link

Quick fix - build your own docker image with ruby 2.7.2.
Long fix, update all docker images/templates in this repo.

@g3kr
Copy link
Author

g3kr commented Nov 4, 2020

@nvtkaszpir Is there a sample you can provide for building custom image with ruby 2.7.2. I tried to use this Dockerfile and pull from ruby 2.7.2 (fluentd-docker-image/v1.11/debian/Dockerfile) it seems to cause more vulnerabilities.

@nvtkaszpir
Copy link

not really.
welcome to security, I hope you sleep well ;)

@g3kr
Copy link
Author

g3kr commented Nov 4, 2020

@edsiper do you have some thoughts on this?

@baygaillardclasspass
Copy link

Any idea when you plan to update your images for the busybox vuln? It should be as simple as updating to the latest alpine by now, though of course it's docker so who knows what could go wrong lol

kenhys added a commit to kenhys/fluentd-docker-image that referenced this issue Apr 20, 2021
Close: fluent#238

It fixes CVE-2020-25613 (webrick), too.

Signed-off-by: Kentaro Hayashi <kenhys@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants