robusta icon indicating copy to clipboard operation
robusta copied to clipboard

Fix CVEs in the base image

Open gsr25 opened this issue 7 months ago • 3 comments

🔴 Critical Vulnerability Integer Overflow or Wraparound CWE-190: Details CVE-2023-45853: CVE Link CVSS Score: 9.8 (Critical)

🟡 Medium Vulnerabilities

And almost 70+ Low Vulnerability detected by snyk

gsr25 avatar May 16 '25 09:05 gsr25

Hi 👋, thanks for opening an issue! Please note, it may take some time for us to respond, but we'll get back to you as soon as we can!

  • 💬 Slack Community: Join Robusta team and other contributors on Slack here.
  • 📖 Docs: Find our documentation here.
  • 🎥 YouTube Channel: Watch our videos here.

github-actions[bot] avatar May 16 '25 09:05 github-actions[bot]

Hi @gsr25 The critical vulnerability is irrelevant (CVE-2023-45853), you can read more here: https://github.com/madler/zlib/issues/868#issuecomment-2655313719

I will take a look on other vulnerabilities as well. Thanks.

moshemorad avatar May 18 '25 08:05 moshemorad

Hi @gsr25 The critical vulnerability is irrelevant (CVE-2023-45853), you can read more here: madler/zlib#868 (comment)

I will take a look on other vulnerabilities as well. Thanks.

Thank you @moshemorad , please do let me know if you need a full snyk report

gsr25 avatar May 18 '25 12:05 gsr25