fluent/fluentd-docker-image

fluend:v1.14.4-1.0 has Security Vulnerebilities

Suman-ag07 opened this issue · 1 comments

Hi Team,

Fluentd: v1.14.4-1.0 is Vulnereble to below security Vulnerebilities:

CVE ID Severity Package Current version
CVE-2018-25032 high zlib 1.2.11-r3 fixed in 1.2.12-r0
CVE-2022-28739 high ruby-webrick,ruby-irb,ruby-etc,ruby-libs,ruby 2.7.5-r0 fixed in 2.7.6-r0
CVE-2022-28391 critical ssl_client,busybox 1.32.1-r7 fixed in 1.32.1-r8
CVE-2022-30065 high ssl_client,busybox 1.32.1-r7 fixed in 1.32.1-r9
CVE-2022-0778 high libssl1.1,libcrypto1.1 1.1.1l-r0 fixed in 1.1.1n-r0
CVE-2022-2097 high libssl1.1,libcrypto1.1 1.1.1l-r0 fixed in 1.1.1q-r0
CVE-2022-29458 high ncurses-libs,ncurses-terminfo-base 6.2_p20210109-r0 fixed in 6.2_p20210109-r1
CVE-2022-24795 high yajl-ruby 1.4.1

Please release a version to fix the issue.

ashie commented

fluent/fluentd:v1.14.4-1.0 isn't latest.
Please use latest image.