-
Notifications
You must be signed in to change notification settings - Fork 2.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
busybox v1.34.1: CVE-2022-28391 #2986
Comments
i am facing same issue (Installed Resource: busybox 1.34.1), do u have workaround? |
Alertmanager doesn't use the netstat program so the CVE doesn't really apply. However the next release of Alertmanager will use a patched busybox image. |
@simonpasquier When will the next release be? 0.24.0 was quite a few months ago. |
the first release candidate of v0.25.0 is in the works: #3176 |
Where is it patching busybox? |
sorry I replied too fast, this isn't fixed in the official busybox image and not even in busybox: docker-library/busybox#133 |
It is fixed in the Alpine build of busybox. I've got a PR open to create a base image the uses Alpine's busybox, but it has been dragging. |
What did you do?
Scan image and find CVE:
CVE-2022-28391
What did you expect to see?
Upgrade busybox to v1.35
image: quay.io/prometheus/alertmanager:v0.24.0
The text was updated successfully, but these errors were encountered: