docker
docker copied to clipboard
GNU Bash Privilege Escalation Vulnerability for Debian
Scanning the matomo:latest container with azure security detects 'GNU Bash Privilege Escalation Vulnerability for Debian' CVE-2019-18276

GNU Bash. Bash is the GNU Project's shell. An attacker with command execution in the shell can use "enable -f" for runtime loading of a new builtin, which can be a shared object that calls setuid() and therefore regains privileges.
QID Detection Logic (Authenticated) This checks for vulnerable version of Bash shell in Debian 9 and 10.
Can Matomo be rebuilt to patch this security CVE
This is not even fixed by Debian itself: https://security-tracker.debian.org/tracker/CVE-2019-18276
https://github.com/docker-library/faq#why-does-my-security-scanner-show-that-an-image-has-cves