Skip to content
This repository has been archived by the owner on Nov 1, 2022. It is now read-only.

Flux 1.18 container vulnerable to CVE-2020-6750 #2883

Closed
willholley opened this issue Feb 27, 2020 · 2 comments · Fixed by #2922
Closed

Flux 1.18 container vulnerable to CVE-2020-6750 #2883

willholley opened this issue Feb 27, 2020 · 2 comments · Fixed by #2922
Labels
blocked-needs-validation Issue is waiting to be validated before we can proceed bug

Comments

@willholley
Copy link
Contributor

The Flux 1.18.0 container reports as vulnerable to CVE-2020-6750 when scanned by the IBM Cloud container registry.

Vulnerable Packages Found
=========================

Vulnerability ID   Policy Status   Affected Packages   How to Resolve
CVE-2020-6750      Active          glib                Upgrade glib to >= 2.62.5-r0

Would it be possible to get the container rebuilt with the updated package?

@willholley willholley added blocked-needs-validation Issue is waiting to be validated before we can proceed bug labels Feb 27, 2020
@hiddeco
Copy link
Member

hiddeco commented Feb 27, 2020

There has been a discussion about CVEs before in #2143

@hiddeco
Copy link
Member

hiddeco commented Feb 27, 2020

Errr #1964

Quoting from https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6750

The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection.

You have to place CVEs into context, and given this I would not rate this a severe issue to a Flux user nor the cluster it is running in.

Our current release process isn’t designed to provide patch builds for CVEs and it would require a complete new patch release. This is simply not worth the effort.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
blocked-needs-validation Issue is waiting to be validated before we can proceed bug
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants