-
Notifications
You must be signed in to change notification settings - Fork 6.3k
Open
Labels
bugSomething isn't workingSomething isn't workingenhancementSome improvement that isn't a featureSome improvement that isn't a featureneeds-investigationThis issue needs to be further investigatedThis issue needs to be further investigatedsecuritySecurity relatedSecurity related
Description
When scanning the latest version of the code-server image, our scanner found two critical CVEs:
- Image:
ghcr.io/coder/code-server:4.105.1(digest:sha256:2d48970bd2084aa34a522d772b6a437981ea80407465b3bf7958553985c570e1) - Scanner: Trivy v0.58.2
- Critical CVEs:
- CVE-2023-45853 in version
1:1.2.13.dfsg-1of packagezlib1g - CVE-2024-24790 in version
v1.20.7of packagestdlib(fixed in versions1.21.11,1.22.4)
- CVE-2023-45853 in version
CVE-2024-24790seems to be contained in every image flavour, not just debian
Due to our security policy, these CVEs block us from deploying code-server in our environment.
Is there any chance of updating these dependencies? (Or are they false-positives?)
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workingenhancementSome improvement that isn't a featureSome improvement that isn't a featureneeds-investigationThis issue needs to be further investigatedThis issue needs to be further investigatedsecuritySecurity relatedSecurity related