Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Image vulnerabilities on fluentd-kubernetes-daemonset:v1.16.3-debian-opensearch-2.1 #1488

Open
iamro opened this issue Mar 27, 2024 · 0 comments

Comments

@iamro
Copy link

iamro commented Mar 27, 2024

Describe the bug

Hello,

the released images have a lot of vulnerabilities (including critical and high ones):

total - 18, critical - 0, high - 1, medium - 1, low - 16
Vulnerability threshold check results: PASS

Compliance Issues
+----------+------------------------------------------------------------------------+
| SEVERITY | DESCRIPTION |
+----------+------------------------------------------------------------------------+
| high | (CIS_Docker_v1.5.0 - 4.1) Image should be created with a non-root user |
+----------+------------------------------------------------------------------------+
| high | Private keys stored in image |
+----------+------------------------------------------------------------------------+

I suppose that most of them are present in the base image that you are using. Can you update it to include all the security fixes?

To Reproduce

total - 18, critical - 0, high - 1, medium - 1, low - 16
Vulnerability threshold check results: PASS

Compliance Issues
+----------+------------------------------------------------------------------------+
| SEVERITY | DESCRIPTION |
+----------+------------------------------------------------------------------------+
| high | (CIS_Docker_v1.5.0 - 4.1) Image should be created with a non-root user |
+----------+------------------------------------------------------------------------+
| high | Private keys stored in image |
+----------+------------------------------------------------------------------------+

Expected behavior

Expecting the image to have no CVSS suspecting any security concerns

Your Environment

- Tag of using fluentd-kubernetes-daemonset: 
v1.16.3-debian-opensearch-2.1

Your Configuration

Ubuntu

Your Error Log

total - 18, critical - 0, high - 1, medium - 1, low - 16
Vulnerability threshold check results: PASS

Compliance Issues
+----------+------------------------------------------------------------------------+
| SEVERITY |                              DESCRIPTION                               |
+----------+------------------------------------------------------------------------+
| high     | (CIS_Docker_v1.5.0 - 4.1) Image should be created with a non-root user |
+----------+------------------------------------------------------------------------+
| high     | Private keys stored in image                                           |
+----------+------------------------------------------------------------------------+

Additional context

No response

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant