Security Vulnerabilities #167
macmillernz
started this conversation in
General
Replies: 2 comments 4 replies
-
You mean the docker base image or the Zoraxy project itself? |
Beta Was this translation helpful? Give feedback.
0 replies
-
According to Docker Scout, Zoraxy (and/or it's dependencies) introduced these CVEs: As far as whats recorded for these, they introduce DOS attack vectors. While obviously not desirable, aren't exactly major vulnerability concerns. There are some more introduced by the Alpine base image but those can be resolved by updating package versions in the image. @macmillernz What did you use to discover these vulnerabilities? |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
The docker image is full of high severity vulnerabilities. I like Zoraxy and where it's headed but it IS NOT safe for the internet.
Is there any plan to fix this?
Beta Was this translation helpful? Give feedback.
All reactions