Skip to content

Latest image 'mcr.microsoft.com/dotnet/aspnet:8.0' still has the HIGH vulnerability CVE-2023-50387 #5357

Answered by mthalman
klingu asked this question in Q&A
Discussion options

You must be logged in to vote

.NET relies on the Linux distro maintainers to update their packages. The fixed package version is not yet available for Bookworm, as indicated in CVE-2023-50387:

We can make no recommendation of other solutions. As I mentioned, we rely on the distro maintainers here as they have a process to ensure correctness and compatibility when integrating new package versions into each distro version.

You may want to explore other distros we provide like Alpine or our Ubuntu Chiseled images which have a lower attack surface due to their smaller set of packages installed.

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
2 replies
@klingu
Comment options

@richlander
Comment options

Answer selected by klingu
Comment options

You must be logged in to vote
2 replies
@klingu
Comment options

@richlander
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants