Skip to content

Address major CVE with openstorage/stork image #1185

@ameer2rock

Description

@ameer2rock

Is this a BUG REPORT or FEATURE REQUEST?:
Security Vulnerabilities
What happened:
openstorage/stork image found major and moderate security vulnerabilities
What you expected to happen:
Image to not have vulnerabilities
How to reproduce it (as minimally and precisely as possible):
Scanned image openstorage/stork:2.9.0 with aquasec security scanner and found vulnerabilities for:
CVE-2022-1292 (major, OpenSSL)
CVE-2022-27772 (moderate, curl)

Anything else we need to know?:
The most current version of stork (2.11.3) has the same software installed and gets flagged by image scanner.
OpenSSL version 1.1.1k
Curl version: 7.61.1

Environment:

  • Kubernetes version (use kubectl version): 1.22.7
  • Cloud provider or hardware configuration: internally hosted
  • OS (e.g. from /etc/os-release): Ubuntu 20.04
  • Kernel (e.g. uname -a): 5.4.0.104-generic
  • Install tools: na
  • Others:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions