Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Image vulnerabilities on fluentd-kubernetes-daemonset:v1.16.3-debian-opensearch-2.1 #1488

Open
iamro opened this issue Mar 27, 2024 · 1 comment

Comments

@iamro
Copy link

iamro commented Mar 27, 2024

Describe the bug

Hello,

the released images have a lot of vulnerabilities (including critical and high ones):

total - 18, critical - 0, high - 1, medium - 1, low - 16
Vulnerability threshold check results: PASS

Compliance Issues
+----------+------------------------------------------------------------------------+
| SEVERITY | DESCRIPTION |
+----------+------------------------------------------------------------------------+
| high | (CIS_Docker_v1.5.0 - 4.1) Image should be created with a non-root user |
+----------+------------------------------------------------------------------------+
| high | Private keys stored in image |
+----------+------------------------------------------------------------------------+

I suppose that most of them are present in the base image that you are using. Can you update it to include all the security fixes?

To Reproduce

total - 18, critical - 0, high - 1, medium - 1, low - 16
Vulnerability threshold check results: PASS

Compliance Issues
+----------+------------------------------------------------------------------------+
| SEVERITY | DESCRIPTION |
+----------+------------------------------------------------------------------------+
| high | (CIS_Docker_v1.5.0 - 4.1) Image should be created with a non-root user |
+----------+------------------------------------------------------------------------+
| high | Private keys stored in image |
+----------+------------------------------------------------------------------------+

Expected behavior

Expecting the image to have no CVSS suspecting any security concerns

Your Environment

- Tag of using fluentd-kubernetes-daemonset: 
v1.16.3-debian-opensearch-2.1

Your Configuration

Ubuntu

Your Error Log

total - 18, critical - 0, high - 1, medium - 1, low - 16
Vulnerability threshold check results: PASS

Compliance Issues
+----------+------------------------------------------------------------------------+
| SEVERITY |                              DESCRIPTION                               |
+----------+------------------------------------------------------------------------+
| high     | (CIS_Docker_v1.5.0 - 4.1) Image should be created with a non-root user |
+----------+------------------------------------------------------------------------+
| high     | Private keys stored in image                                           |
+----------+------------------------------------------------------------------------+

Additional context

No response

Copy link

This issue has been automatically marked as stale because it has been open 90 days with no activity. Remove stale label or comment or this issue will be closed in 30 days

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants