cli icon indicating copy to clipboard operation
cli copied to clipboard

[Snyk] Security upgrade ubuntu from trusty to trusty-20190515

Open snyk-bot opened this issue 4 years ago • 2 comments

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Changes included in this PR

  • vendor/golang.org/x/net/http2/Dockerfile

We recommend upgrading to ubuntu:trusty-20190515, as this image has only 135 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Some of the most important vulnerabilities in your base image include:

Severity Priority Score / 1000 Issue Exploit Maturity
high severity 714 NULL Pointer Dereference
SNYK-UBUNTU1404-OPENSSL-1049144
No Known Exploit
high severity 886 Off-by-one Error
SNYK-UBUNTU1404-SUDO-1065770
Mature
medium severity 514 Arbitrary Command Injection
SNYK-UBUNTU1404-SUDO-406981
No Known Exploit
medium severity 686 Improper Handling of Exceptional Conditions
SNYK-UBUNTU1404-SUDO-473059
Mature
low severity 536 Out-of-bounds Write
SNYK-UBUNTU1404-SUDO-546522
Mature

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

snyk-bot avatar May 16 '21 04:05 snyk-bot

CLA Not Signed

We have created an issue in Pivotal Tracker to manage this:

https://www.pivotaltracker.com/story/show/178169871

The labels on this github issue will be updated when the story is started.

cf-gitbot avatar May 16 '21 04:05 cf-gitbot