You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@mgattozzi - influxdb:latest currently refers to 2.7.11. Neither gosu or dasel are part of the 1.11 or Enterprise images.
The gosu shipped in influxdb:latest was compiled with go1.18.2 (eg, go version ./usr/local/bin/gosu) while dasel was compiled with go1.21.3. While it's true that these are compiled with older golangs that have since gotten CVE fixes, these are tools for parsing config files and dropping to the non-root user within the docker environment. The aforementioned CVEs deal with processing HTTP requests which neither of these tools do. As such, they don't affect influxdb.
finding Vulnerability found in non-os package type (go) - /usr/local/bin/gosu (fixed in: 1.21.9, 1.22.2)(GHSA-4v7x-pqxf-cx7m - https://nvd.nist.gov/vuln/detail/CVE-2023-45288) in influxdb Docker image.
The text was updated successfully, but these errors were encountered: