fix(plugin-keychain-vault): fix CVE-2024-0553 in vault server image #3065
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
because it seems to not have the same vulnerabilities as the lastest
stable Debian image does, so the change itself is to move to Ubuntu 24.04
LTS.
a couple of small code changes that are also added in this commit.
The original security report from Trivy that we've discoverd on the CI:
┌─────────────┬───────────────┬──────────┬───────────────────┐
│ Library │ Vulnerability │ Severity │ Installed Version │
├─────────────┼───────────────┼──────────┼───────────────────┤
│ libgnutls30 │ CVE-2024-0553 │ HIGH │ 3.6.7-4+deb10u11 │
│ │ │ │ │
└─────────────┴───────────────┴──────────┴───────────────────┘
...
┬──────────────────┬───────────────────────────────────────────┐
│ Fixed Version │ Title │
┼──────────────────┼───────────────────────────────────────────┤
│ 3.6.7-4+deb10u12 │ gnutls: incomplete fix for CVE-2023-5981 │
│ │ https://avd.aquasec.com/nvd/cve-2024-0553 │
┴──────────────────┴───────────────────────────────────────────┘
Signed-off-by: Peter Somogyvari [email protected]
Pull Request Requirements
upstream/main
branch and squashed into single commit to help maintainers review it more efficient and to avoid spaghetti git commit graphs that obfuscate which commit did exactly what change, when and, why.-s
flag when usinggit commit
command. You may refer to this link for more information.Character Limit
A Must Read for Beginners
For rebasing and squashing, here's a must read guide for beginners.