Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multiple Critical Security vulnerabilities in Docker image (highest CVSS: 9.8) #448

Open
jimscard opened this issue Feb 16, 2023 · 1 comment

Comments

@jimscard
Copy link

Scanned the maildev/maildev:latest Docker image with the Trivy extension for Docker Desktop.
It identified 15 security vulnerabilities, for which fixes were available. The highest CVSS score is 9.8/10.

2 Critical: CVE-2022-2421 in socket.io-parser, and CVE-2022-37434 in zlib
4 High: CVE-2022-25881 in http-cache-semantics, CVE-2023-0286 in llibcrypto1.1, CVE-2023-0286 in libssl1.1, and CVE-2022-29244 in npm.

Additionally, there were another 9 Medium CVEs identified -- they were in libcrypto1.1, libssl1.1 and engine.io.

@dancer1325
Copy link

Hi @jimscard

And is there some planned new release to address those vulnerabilities?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants