Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

busybox v1.34.1: CVE-2022-28391 #2986

Open
cbl315 opened this issue Jul 6, 2022 · 7 comments
Open

busybox v1.34.1: CVE-2022-28391 #2986

cbl315 opened this issue Jul 6, 2022 · 7 comments

Comments

@cbl315
Copy link

cbl315 commented Jul 6, 2022

What did you do?
Scan image and find CVE:
CVE-2022-28391

What did you expect to see?
Upgrade busybox to v1.35

  • Alertmanager version:
    image: quay.io/prometheus/alertmanager:v0.24.0
@tooptoop4
Copy link

i am facing same issue (Installed Resource: busybox 1.34.1), do u have workaround?

@simonpasquier
Copy link
Member

Alertmanager doesn't use the netstat program so the CVE doesn't really apply. However the next release of Alertmanager will use a patched busybox image.

@liam-verta
Copy link

@simonpasquier When will the next release be? 0.24.0 was quite a few months ago.

@simonpasquier
Copy link
Member

the first release candidate of v0.25.0 is in the works: #3176

@liam-verta
Copy link

Where is it patching busybox?

@simonpasquier
Copy link
Member

sorry I replied too fast, this isn't fixed in the official busybox image and not even in busybox: docker-library/busybox#133

@liam-verta
Copy link

It is fixed in the Alpine build of busybox.
https://security.alpinelinux.org/vuln/CVE-2022-28391

I've got a PR open to create a base image the uses Alpine's busybox, but it has been dragging.

prometheus/busybox#51

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants