Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-3154 found with latest version #1834

Open
nvuillam opened this issue Apr 27, 2024 · 2 comments
Open

CVE-2024-3154 found with latest version #1834

nvuillam opened this issue Apr 27, 2024 · 2 comments
Labels
bug Something isn't working

Comments

@nvuillam
Copy link

What happened:

CVE found by trivy

┌────────────────────────────────┬───────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────┐
│            Library             │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │                         Title                         │
├────────────────────────────────┼───────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────────┤
│ github.com/opencontainers/runc │ CVE-2024-3154 │ HIGH     │ fixed  │ v1.1.12           │ 1.2.0-rc.1    │ cri-o: Arbitrary command injection via pod annotation │
│                                │               │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2024-3154             │
└────────────────────────────────┴───────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────────┘

What you expected to happen:

No CVE found :)

How to reproduce it (as minimally and precisely as possible):

See MegaLinter build job: https://github.com/oxsecurity/megalinter/actions/runs/8862893746/job/24336363970?pr=3518

Dockerfile uses the following: RUN curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin

Anything else we need to know?:

Environment:

  • Output of grype version: latest
  • OS (e.g: cat /etc/os-release or similar): alpine linux
@nvuillam nvuillam added the bug Something isn't working label Apr 27, 2024
@kzantow
Copy link
Contributor

kzantow commented Apr 29, 2024

Note: Grype also finds this CVE :) We'll definitely get this updated once the new version is released.

@nvuillam
Copy link
Author

@kzantow many thanks for your reactivity :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
Status: Ready
Development

No branches or pull requests

2 participants