Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

backman:1.22.0 vulnerabilities #37

Open
rhysmeister opened this issue Jan 4, 2021 · 3 comments
Open

backman:1.22.0 vulnerabilities #37

rhysmeister opened this issue Jan 4, 2021 · 3 comments

Comments

@rhysmeister
Copy link

Hello,

I use the latest version of backman in the Swisscom iAPC. I've received a notification about the following vulnerabilities in the image. Can these be easily resolved?

CVE-2018-20839, CVE-2020-14039, CVE-2020-14040, CVE-2020-15366, CVE-2020-16845, CVE-2020-24553, CVE-2020-26160, CVE-2020-28366, CVE-2020-28367, CVE-2020-7754, CVE-2020-9794

Cheers,

R

@akovov
Copy link

akovov commented May 2, 2021

Today got letter with new list of vulnerabilities backman v1.28.0
1 high (CVE-2020-28472), 6 medium (CVE-2018-20839, CVE-2020-26160, CVE-2020-28852, CVE-2020-29652, CVE-2020-9794, CVE-2021-23336)

@padyx
Copy link

padyx commented May 2, 2021

I had analyzed some of them before I opened PR #47:

  1. CVE-2020-28472 (high): Due to embedded component elasticdump, which depends on a vulnerable version of aws-sdk.
    However it could be a false positive, since elasticdump itself does not really use the vulnerable features (yet).
    I had raised an issue with them, but they closed it without comment: Elasticsearch-dump#783
  2. CVE-2020-28852, CVE-2020-29652: Looks like "go" vulnerabilities from the mongodb-tools which still contain the old version of the golang mongodb-driver (1.4.2). But there seems to be now newer version where the driver is updated according to the changelog.
  3. CVE-2020-26160: Concerns dgrijalva/jwt-go. There seems only a preview of a new version. etcd even switched to a completly different library
  4. CVE-2020-9794: sqlite3. Not fixed upstream in Ubuntu yet, as it's unclear if they're even affected.
  5. CVE-2021-2333: Python (3.8.5-1~20.04.2). Remediate by upgrading to newer python version.

So only the last one is "easily" fixable by building a new version and making sure that the python packages are updated.

@akovov
Copy link

akovov commented Nov 2, 2021

list of current vulnerabilities in 1.28.0:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants